Do we, though? I use "I don't care about cookies": https://chrome.google.com/webstore/detail/i-dont-care-about-... to deal with the mess.
Eu mandated that the users should be clearly told what would be tracked, they should be given an easy way to accept, reject, and choose which of them they accept.
The corporations - mainly the US - chose to 'get around' these requirements in the undying US corporate tradition: Make it difficult for the user to reject cookies so they will have to give up and just accept. Most modals have only an 'accept' and 'choose' sections, and the 'choose' section includes a gigantic list of 'vendors' which you have to individually turn off one by one. So that you will give up and just click 'accept'. Some of them offer a 'reject all' button way at the bottom of of the list, after listing 30-40 vendors. So basically its the usual corporate trickery to force user to do things they don't want to.
However, this is illegal - Eu works on civil law, and civil law is a clear, well defined legal practice. If it says you have to do some specific thing, there isnt much 'interpret my way around it'. So, per that law, all the cookie modals that do not give the users an EASY way to reject cookies are in violation of that law. It absolutely does not matter zit if the user 'consents' to the terms. Mutual agreements and contract law overriding actual law is a trait of the Anglosaxon common law, not civil law. In civil law, it doesnt matter zit if the other party agreed to something illegal per law.
Therefore, not only all these pesky modals that try to force you into accepting those ~80 cookies from a random website you visit are not Eu's doing, but also most of them are actually in violation of the GDPR law.
So if the website doesn't collect any data at all, except for what is needed for running the website and preventing malicious users (so, collecting ips for a week in the logs to use fail2ban), do they need a "privacy" section?
I ask because a privacy section requires a lawyer, and that is a big cost for a simple static website with no earning goals
I dont think they do. There are such sites indeed and I havent seen any prompts in them.
> so, collecting ips for a week in the logs to use fail2ban
IP by solely itself wouldnt constitute 'Personally identifiable information' as far as I know. But Im not sure.
> I ask because a privacy section requires a lawyer
Not really. Website privacy legal templates already exist and they are pretty standard at this point.
IP is considered identifiable information if it's used for some purpose (e.g. statistics for website visits). I'm pretty sure it's considered "legit use" if it's for filtering malicious users.
Could you point to some of those standards? I had a customers reaching out and found myself without any idea how to handle that privacy section.
> IP is considered identifiable information
Not at all. IP by itself is meaningless and it just points to a computer or a proxy. Only if you have other information then it starts becoming identifiable. Even in court cases that involve IPs its not enough - the ISP gives the IP to the court, but then the court must find who was the person using that IP at that given point in time in that house, even the person using the computer.
> Could you point to some of those standards?
You can just google privacy section templates with GDPR keyword. There are a lot of templates as such. WordPress itself provides an easy way to create such templates and it already has GDPR tools built in.
I feel like people give a pass and even defend it because it had good intentions. Clearly it wasn't well thought and people should criticize it more instead. Bad execution can ruin good ideas.
Of course there are other good things on GDPR as a whole but this cookie consent thing was a disaster. I live in the EU but use a VPN routing my connections to a nearby non-eu country to have an overall better browsing experience.
Its not open to abuse. Its just that the US corporations are violating its articles.
> Clearly it wasn't well thought
It was well thought out. It mandates easy Accept / Reject for tracking. Just one click. Tell the users what you will track. And allow them to choose if they want to.
The route that the US corps. took is no different from how they go around and violate laws in their home turf. They think that they can do the same with civil law. But it doesn't work that way. Eventually one will get busted for not obliging with the articles of the law.
There’s no good idea that the EU won’t find some way to execute poorly, alas.
What you say just sounds like Daily Mirror grade smear.
The EU is great at taking credit for things it had very little to do with. Sometimes it’s obvious things that happen elsewhere without the EU (expiration dates on food), sometimes it’s the work of other organisations (like NATO). “Oh, there’s peace in Europe? Yeah, the EU did that. Oh, there’s war in Europe? Hmm, more EU should fix that.”
> What you say just sounds like Daily Mirror grade smear.
I’m a euro-federalist, so I doubt the Daily Mirror would be interested. The EU is a mixed bag and I want it to do better. Reflexively attacking people whose views you know very little about seems unconstructive.
A large part of the world adopted such rules after the Eu implemented them. The Eu is seen as the leader and standard in these things. Eu implemented consumer protections, everyone else in OECD also did. Eu implemented EUVAT, OECD countries are also doing it. Also various US states. Eu implemented GDPR, and suddenly from Brazil to US every other country or state has their own GDPR.
Now the Eu has its digital gatekeepers law. Watch how long will it take for other OECD countries to adopt similar laws.
> Reflexively attacking people whose views you know very little
Sorry but we are on public internet. We dont have the time to sit and get to know people. If you are talking like the people from a certain group, then its normal that people respond to you as if you were from that group.
Moreover, the culture that people grow up in affects their perspective greatly. Not surprisingly, having grown in an Anglosaxon country seems to have shaped your perspective too.
We had most of these other things before EU even existed. Brazilian's Código de Defesa do Consumidor dates from 1990. Expiration dates are such a common thing worldwide its not even worth searching on there internet. A quality assurance institution named INMETRO exists since the 70s testing everything from condoms reliability to reporting small parts in children's toys. Brazil also pioneered net neutrality one year before the EU.
Talking about culture perspective you seem to admire the EU regulatory frame and that's fine but as I said before nothing is perfect and its totally ok to criticize something that is poorly conceived even if intentions were good.
Nope. Euparl does most of these regulations. The GDPR, digital gatekeepers and various other internet related laws originated from the left wing parties in Euparl - those parties grew from pirate party roots. The pirate parties that were founded in many Eu countries in mid 2000s during the copyright/filesharing battles.
That is a big factor in proliferation of such agreements, however thats not the normal mechanic. Japan has no need for copying EUVAT to trade with the Eu for example. But they are doing it. Also, various US states implemented similar schemes without any such need.
> Talking about culture perspective you seem to admire the EU regulatory frame
I explicitly do. What you are seeing with the emergence of recent regulations like GDPR, digital gatekeepers is due to the ascent of pro-people, pro open web parties that grew from pirate party roots coming to power in the Eu parliament.
> A quality assurance institution named INMETRO exists since the 70s
Eu started as a coal cooperation organization in mid 1950s and by 70s most of its institutions and practices were in place - especially in the direction of consumer, product and manufacturing regulations. It was the example even by then.
The idea of VAT dates back to the First World War, and while the EU assists European governments in coordinating its collection in Europe, it had no meaningful impact on the adoption of VAT-style taxes overseas. Neither Australia nor the United States levy VAT.
Consumer protections absolutely do not originate in the EU. It’s a claim so absurd I honestly don’t know what to say to it. English civil law has had case law and statute protecting consumers for centuries, which is in no way remarkable, seeing as even Roman law had consumer protections in cases of fraud, mistake, or duress.
The idea that the EU is some shining beacon on a hill that everyone looks up to is something one hears a lot around Europe, but I think the people who think this may have places like Moldova confused with the rest of the world. The EU is the fastest shrinking trade bloc, in relative terms, on the face of the planet. Europeans used to like saying that if they were a single country, they’d be the largest economy in the world. That ceased to be true in the last few years - the US has now overtaken the EU. Whereas the US has to manage runaway growth and speculative excess, the EU is forced to make provisions for its relative economic decline. If European countries were US states, living standards in large European economies like Germany and France would rank near the bottom. This is a huge problem. Less prosperity means less quality government services, including healthcare, social security, and education. Less growth over time means fewer nurses, fewer teachers in the future. If the EU single market is such a towering achievement, why is EU growth so sclerotic? It’s hard for Europeans to hear, but the EU is simply not a model people outside of Europe aspire to, even people who otherwise love Europe.
The European project has wonderful achievements, in my opinion, like the Schengen area, and deep scientific and educational cooperation, including Erasmus exchanges for young people. But instead of focusing on those, the EU prefers to claim credit for the sunrise. I’d rather see the EU reformed than abolished - it’s still a net good, I think - but far too many Europeans are far too myopic about the EU’s shortcomings, and far too ignorant about how the rest of the world functions to consider alternatives. (Or even just apply a reasonable degree of scepticism when the EU claims credit for things that predate it or that are already widespread elsewhere.)
> Sorry but we are on public internet. We dont have the time to sit and get to know people.
You seem to be defending bad faith assumptions as a time saving device. Seems to me like that would just set you up for a lot of unnecessarily adversarial discussions, and a generally less pleasant experience than you could be having.