France fines Microsoft €60M for imposing advertising cookies
rfi.fr
rfi.fr
Reading it in translation, seems they identified the following as breaches:
1. When you visited bing.com they always dropped an ad fraud detection cookie.
2. After clicking around on bing.com, without clicking yes on any of the banners, it would drop an ads cookie.
3. On their cookie banner, rejecting took two clicks while accepting took one.
On 1, Microsoft argued that detecting ad fraud was "strictly necessary" for running bing.com, but the court disagreed, saying that advertising is not a service requested by the user. (point 53 in the full decision).
On 2, Microsoft said it was an accident and had already stopped, though not before CNIL asking them about it
On 3, Microsoft argued that (a) rejecting was not actually required to be as easy as accepting and that (b) since the default was no cookies and it took a click to get cookies that rejecting was easier than accepting. The CNIL disagreed on both.
Nice of them to spell out "we don't actually care about the users, get fucked" in such a clear and succinct way.
Aside, wonder how good/bad ip+agent fingerprinting could be combined with a url that feeds a small randomly generated string with a VERY long cache expiration, with server/proxy no-cache headers (e-tag per agent/ip). Effectively similar to a cookie, without technically being a cookie.
/sarc
The regulation explicitly says so. Easy way to accept, reject and choose. A lot of companies seem to be violating the law in that one. By making it difficult for people to reject cookies.
Where do you see that in the ePrivacy Directive?
1. The ePrivacy Directive says that before setting anything in client-side storage you must have the consent of the user unless it is strictly necessary for performing an operation requested by that user.
2. The GDPR requires consent from the user before using their personal data in a bunch of different ways, and provides a lot of details on how that consent may be collected to be considered valid.
My interpretation of Microsoft's behavior here is that they were compliant with (1) and (2) individually, but the problem was the way they were collecting consent for (1) did not follow the requirements of (2).
GDPR Article 7, 3, conditions for consent.
> It shall be as easy to withdraw as to give consent.
In which case yes, it is the same as refusal in the context of the law being discussed.
Except for the cookies that they dropped on you by default (completely by accident, of course).
Good to know that they're absolutely unshamed of it though.
I've long suspected that these sites default to dropping cookies when my consent is neither asked for nor received, as MS appears to have done here.
It's good to hear that such behavior is probably illegal in the EU.
> It's good to hear that such behavior is probably illegal in the EU.
Huh? What's the problem supposed to be?
They get discussed a lot here on HN so it's easy to assume everyone's familiar with them, but if you're not then you should search up a summary on them.
That's how I read it at least, which would mean they're defaulting to cookies when no consent is reached, but I could be wrong.
But much more importantly, it is completely impossible in the context of the thread:
> [Accusation 3.] On their cookie banner, rejecting took two clicks while accepting took one.
> On 3, Microsoft argued that (a) rejecting was not actually required to be as easy as accepting and that (b) since the default was no cookies and it took a click to get cookies that rejecting was easier than accepting. The CNIL disagreed on both.
It's sometimes hard to make marketing understand why this is an issue in the first place but then we are B2B in a mostly offline industry so it doesn't matter as much.
in my experience they don't actually understand what they are required to do, they then think the easiest way to handle it is to pay for some outside expertise with of course the understanding that they would still like to get some ad money.
I can't think of a way to actually use any kind of tracking cookies, even non-ad/sales/data-harvesting related that wouldn't be annoying in EU.
Of course, if you manage your own load balancing, could definitely combine a load-balancer pinning cookie (uuid) for "all" uses as a single "essential" cookie.
See GitHub.
You can't use the data for other purposes though.
Tracking without cookies requires consent no matter how you implement it. Claiming it to be essential won't fly if, say your Marketing or sales team has access.
Once it's used for other (technically non-essential) needs as well, one needs to find another basis for processing or ask permission for that second purpose(consent basis).
Also, if the LB cookie can be non-identifying, while fullfilling the stated technical purpose, it must not allow identifying users. So for LB cookies, one must not use a unique ID per user, but an LB ID instead. Something like "node1", "node2" etc...
They tried to be clever by re-using the same cookie for multiple purpose essential and non-essential (the “essential” purpose being related to ad fraud detection) so they claimed they did not need consent to set the cookie. And since they argued that they chose to use a single cookie “to reduce the number of reads and writes”, which is bullshit, they were clearly not acting in any kind of good faith here. The regulator did not condemn them for the bad faith argument though, but because “ad fraud detection doesn't qualify as essential”, so their “smart” move of mixing essential and non-essential purposes within the same cookie wasn't even properly done:
> En outre, le rapporteur précise, en réponse à l’argumentation de la société considérant la finalité de lutte contre la fraude au sens large comme une finalité essentielle exemptée de consentement, que seule la finalité de lutte contre les attaques en déni de service pourrait être exemptée de consentement. Le rapporteur relève que les autres finalités évoquées ne relèvent pas du champ des exemptions prévues par l’article 82 de la loi Informatique et Libertés puisqu’elles n’ont pas vocation à faciliter une communication électronique et ne sont pas strictement nécessaires à la fourniture d’un service expressément demandé par l’utilisateur.
The regulator then remarked that mixing both kinds of purpose within the same cookie is explicitely forbidden anyway: (emphasis mine, on the relevant part)
> En premier lieu, s’agissant des cookies et autres traceurs multi-finalités, la formation restreinte rappelle que l’article 82 de la loi Informatique et Libertés exige un consentement aux opérations de lecture et d’écriture d’informations dans le terminal d’un utilisateur mais prévoit des cas spécifiques dans lesquels certains traceurs bénéficient d’une exemption au consentement : soit lorsque celui-ci a pour finalité exclusive de permettre ou faciliter la communication par voie électronique soit lorsqu’il est strictement nécessaire à la fourniture d’un service de communication en ligne à la demande expresse de l’utilisateur.
But yes, this all ended up being irrelevant since the court decided that they were using it for non-essential purposes before getting permission.
Because that's what was tried before GDPR, and it has proven to be a conclusive failure. https://en.wikipedia.org/wiki/Do_Not_Track
I assume this didn't happen due to industry lobbying.
I think the result would have been similar to what happened when apple did it's Facebook nerf. Within the margin of error no one wants to be tracked and the ad industry knows this despite their fake "user-benefit" Spiel.
In the end it didn't happen and I can't recall what it was called.
I hope they will go back on this and mandate DNT after all.
Run an adblocker. The Web was a total mess even before GDPR came along and not limited to Europe. If the issue of denying sites a revenue stream bothers you then perhaps make yourself a promise that you'll turn it off when ad networks stop being a vector for malware and/or stop engaging in the un-permitted collection and sale/abuse of personal data.
Personally, I run NoScript (as well as ad blockers) and so cookie popups are relatively rare on my Mac, but I still get them on iOS. I don't like them, but I see them as a warning that the site is going to try to exploit my personal data in return for serving me content.
It's also worth pointing out that there is no actual need to have a cookie banner unless you're doing something with the data that actually needs permission. For instance basecamp.com was GDPR/ePrivacy directive compliant when I was there, but never needed a banner because they decided to stop collecting and processing personal data in a way that required permission.
However, I wish the law were solely about sites working with cookies disabled. The prompt on every website is driving me crazy, to the point of installing extensions like https://www.i-dont-care-about-cookies.eu/ (though this has been acquired by Avast apparently, so I won't ever update from 3.3.2).
Ever since the first browsers, cookie preferences were customizable in them. Websites should not duplicate that functionality, but merely respect it.
EasyList Cookie is one of the first lists I enable on any adblocker that allows it.
Once that happens it will be almost as before, just with less battery usage, less network usage and less tracking.
Will it happen?
I think it will. I know see even Google - who I expect to have a small army of lawyers - have given up to certain extent and now lets me opt out directly without any extra steps.
Thank you for the recommendation!
1. Left-click Ublock Origin
2. Click the gear Icon
3. Check the box that says "EasyList Cookie"
This is not allowed either.
GDPR, unlike the previous attempt isn't a cookie law but a data law.
By law, the user experience must not be different based on whether the user has or has not given consent for tracking.
Registration implies consent to process information (identity) for the purposes for which that information was provided, namely access to the content. It does not imply consent to use that information for other purposes such as tracking, and so any attempt to track a user around a site for advertising purposes using their login details would be in breach of the GDPR, unless the user has explicitly and freely given separate consent for that to be done. For that to be possible, the request for consent to track must be completely separate from the process of creating an account or logging in - it cannot be part of the terms and conditions.
That's the Angloamerican common law's logic. In civil law, the law cannot be overridden by others 'agreeing' to override it. Its more like software engineering in that regard, instead of arbitrary interpretations.
This is factually inaccurate; contracts are one area of, but not the basis of, common law.
> In the eyes of civil law, the use of the site would need to take place per the laws and regulations present in civil law as opposed to whatever that the user may agree in terms.
In common law, contracts don't trump other law, and contracts or provisions thereof can be invalid for being contrary to public policy.
Of course it isn't the entire basis of the law. However it lies in the fundamental of the entire common law institution: Common law originated from the feudal relationship in between the liege lord and the vassal contracting each other based on certain criteria. Over time, this concept was meshed with medieval customs and started being applied to the society as a whole. Hence the awkward medieval-feeling nature of the common law with all those 'precedents', 'interpretations' and 'agreements'.
> In common law, contracts don't trump other law, and contracts or provisions thereof can be invalid for being contrary to public policy.
Today. And mainly because the US combines common law and civil law in a meshed system. For the UK, its mainly because common law was basically unworkable and indefensible in the modern age after civil law became de facto standard in the entire world, setting the legal discourse. Still, the contractual concepts lies in the fundamental of the law as evidenced by the 'agreement' concept that is so extensively being utilized by US corporations.
Never dick around trying to use contract terms and narrow technicalities to bypass regulations and obligations. It won’t go well.
A site might have terms and conditions, or conditions of sale etc. but if you as an individual buy something you still have protection from consumer laws. Any conditions you agree to are only ever in addition to your statutory rights.
So, a company might state that an item has a 12 month warranty (as happened with me, a Mac computer bought from Apple), and it might break after that time (mine after something like 13 months). In my case Apple said they were not going to fix it for free because it was out of warranty and I didn't have Apple care (deliberately because I knew consumer law), but I successfully argued that (as stated in the legislation) that there was a reasonable expectation that the item should have worked for a lot longer than that, ultimately making them responsible. They did in the end accept this and fix it.
There's other examples, like if an item is not as described then the company selling it has to pay costs to have it returned, and that the company is responsible for the item while it is in transit in either direction. You are due a refund within 14 days of the /rejection/ of the item, not any other timescale, or dependent on when you return the item, etc. etc.
In summary, your "terms and conditions" are effectively irrelevant if they attempt to reduce or bypass existing legislation.
So "account-only" would be allowed, but "if you reject cookie you need account" would break it.
You still need to get user consent about any tracking and 3rd party tho.
AFAIK the only legitimate way is "Do you want to be tracked? Yes/No".
If that means less ad based business models so be it (as far as the GDPR is concerned).
Maybe it even means the return of quality content.
It's more like the minimum wage argument or something like that but you don't really need an analogy.
Advertising itself is only mildly offensive; if done with taste it can be no problem at all, but too many companies seemingly don't know when to stop - the line from Ready Player One about monetizing 70% of a person's field of view sounds exactly like what Meta and Google would do if they could get away with it.
I want legislation on this topic to create breathing space for real businesses which make things of value.
I never heard that word. Is that an euphemism for "corrupted"?
https://www.merriam-webster.com/dictionary/enthrall
Context matters. If you are talking about a child with a jigsaw then sure, the more cutesy definition applies. But talking about politicians and money, you have to bend over backwards pretty far not to see the second definition as more appropriate.
This has nothing to do with that. NYT started locking its content years before cookie regulations. Membership content existed way before. It recently exploded. That's why. Not due to cookies.
Care to elaborate why you think so?
Quick google search about the effects of the law shows various studies done so far to assess the positive impact it brought.
https://techcrunch.com/2019/08/10/most-eu-cookie-consent-not...
I think the USB-C mandate also going to result in a similar implementation by companies.
Apple already setting the trend by going to have only wireless charging for phones.
Either I misread you or this is pure nonsense.
I have read through many of these popups and there is no way 200-700 trackers are there for my benefit.
It should be absolutely trivial to reject tracking unless you actively want it.
It's misinterpretation of the letter of the law (there's no such thing as a cookie dialog/banner) and the spirit of the law (disabling tracking should be easy default choice, not the convoluted, hard choice).
But practically, when they take up a good 2/3 of the screen and are not dismissible without making a choice then they do.
Cookie law was lame af from the beginning and did nothing but annoyed end-users.
Take into consideration that these companies annoyed their users but blamed it on the politicians, which is pretty irrational behavior.
And here you are, still blaming the politicians. As a result the GDPR came into being which is far more strict, it too is being blamed as the reason why many companies have now decided to shut down service altogether as the easiest solution to comply, when obviously the alternative would be to simply stop tracking your users.
Are you saying that before the 2002 ePrivacy Directive came out most people who thought about this wouldn't have predicted that companies would put up cookie banners?
Users were way more naive at the time of cookie banners being introduced. Internet were still not a real IRL thing.
The relevant governing bodies need to crack down on companies that are violating the rulings and ensure that it's understood this is a requirement for doing business.
If you've ever been in a position to write policy, you know the adage that if you design something to be idiot-proof, they'll just design a better idiot. Same rule applies for bad actors.
Laws don't try to predict everything, that's why the spirit of the law is just as important as the letter. What the law means to accomplish is just as important as what is actually written, and persons who violate the spirit of the law while not explicitly violating the letter should not get a free pass; this is not how law works, and it's why despite the hundreds of thousands of laws on the US books, there are still courts to interpret laws and make rulings on situations.
Corporations can kick and scream all they want while writhing through to meet the letter of the law, but that doesn't make them right, it just makes them desperate.
I can show multiple government websites where the UX is broken. There is no profit motive there. But if you live in the EU, you probably have seen it already.
It is so worse that chrome has an add-on that has 800k downloads.
https://chrome.google.com/webstore/detail/i-dont-care-about-...
GDPR isn't a cookie law.
What we see now is big companies response: they try to pretend like it is, and try to blame it on lawmakers.
But, as fines like this show: they are getting caught and punished for it.
Because the law didn't say that companies had to force users to accept cookies.
It said something along the lines of: collecting data is only allowed with users active, informed consent.
For example the news site nu.nl now requires having a free account to read many specific articles. This is a smart move on their part because logging in requires maintaining a higher amount of user information across visits and thus it brings a lot of tracking into the "technically necessary" realm so they don't have to ask permission.
Marketeers just won't play nice until they are fined big time.
So basically every cookie prompt that makes you take more than one click to reject or says "You consent to this -> Yes" is in violation of the law and they will get fined if they are reported.
GDPR requires that consent is as easy to withdraw as it is to give. [0]
That companies have dragged their feet and gone kicking and screaming with cookie banners is irrelevant to the actual law; the EU needs to start cracking down more and more on this to show what it actually means, since it's quite clear that companies are not going to willingly comply with the data consent laws.
So don't blame the politicians on this one, they never gave any requirement for such banners, and in fact specifically mentioned that it must be simple to revoke/deny consent. Companies that didn't want to comply with GDPR and other privacy laws decided to make it as painful as possible for you and I and blame it on the privacy rules.
Politicians aren't forcing websites to set more than the strictly necessary cookies, which require consent. It's marketing/advertising that does.
- cookie banners are the result of the ePrivacy directive, NOT the GDPR. This directive is implemented in France in the law « informatique et libertés » which is honestly pretty good overall
- cookie banners are NOT mandatory when you use cookies. If you use only technical cookies (session IDs, local settings, etc.), you do NOT need a cookie banner. The law simply states that you must ask consent before tracking users. Cookie banners just highlight the fact that tons of websites track their users and did it on the cover of unreadable ToS before. The fact that cookie banners are so annoying proves the law wasn’t misguided
- cookies are not the only target of ePrivacy: it’s a law about consent to tracking, not about cookies
- the law works. I personally go out of my way to click « reject non necessary » when I can. I also report websites violating the intent of the law when I see them
Theres sort of a grey area where you need them to do basic website analytics, which IS a bit annoying as a developper since all website will ever do this until the end of times
This can be done without tracking users though. Also, in the context of "no-one owes you a business model", just because being able to do something can increase your bottom line by some % doesn't mean you can do it at the expense of individuals. The web industry (which I'm very much a part of) had years during which they could have voluntarily stopped being shitty to users, and they didn't, so now we have GDPR etc.
Multiple sites of Polish government - main www.gov.pl among others - attempt to run Google's tracking code on visitors' devices without consent.
This is basically illegal in the EU but Poland's GDPR body (Urząd Ochrony Danych Osobowych) dismissed the case opened by me against the Minister of Digital Affairs (Minister Cyfryzacji) who is responsible for those sites operation as baseless.
I could only wish for the Danish authorities to be so couragious as to actually enforce the law - especially against the biggest offenders.
This means that Bing will become a good example rather than a good excuse.
alas, most of the top technical talent either has moved to the United States or works for US companies so fines it is.
So for example if you want to have cameras in your shop you have to write on the doors that you have it, who is processing that data and for what purpose.
If say you as owner wanted to give that data to police, that's within the usage and fine. If you decided to make compilation of funny people in supermarket from it, or decide to train your AI models on it, that would be illegal. There is also limitation on storage period (3 months) that can be longer only if there is some crime being investigated related to that.
More IT related example: we can log IP and stuff for security purposes but they can be used only for that; we don't need to get consent to save that for purpose of say preventing DDoS or spotting out attacks but we can't use that to do analytics without anonymizing data or consent.
There are other laws that require storing data for longer, mostly tax and money related, can't exactly use GDPR to tell bank to stop storing your financial data.
Most importantly that puts the burden of handling it on corporations; with GDPR the PII is basically "radioactive".
I think it is in pretty good compromise between "freedom to do whatever you want" and "freedom for whoever else to fuck you without consequences because they can do whatever they want" althought EU is definitely overreaching in places (like the hard-on on EVs before infrastructure is ready)