It's sometimes hard to make marketing understand why this is an issue in the first place but then we are B2B in a mostly offline industry so it doesn't matter as much.
in my experience they don't actually understand what they are required to do, they then think the easiest way to handle it is to pay for some outside expertise with of course the understanding that they would still like to get some ad money.
I can't think of a way to actually use any kind of tracking cookies, even non-ad/sales/data-harvesting related that wouldn't be annoying in EU.
Of course, if you manage your own load balancing, could definitely combine a load-balancer pinning cookie (uuid) for "all" uses as a single "essential" cookie.
See GitHub.
You can't use the data for other purposes though.
Tracking without cookies requires consent no matter how you implement it. Claiming it to be essential won't fly if, say your Marketing or sales team has access.
Once it's used for other (technically non-essential) needs as well, one needs to find another basis for processing or ask permission for that second purpose(consent basis).
Also, if the LB cookie can be non-identifying, while fullfilling the stated technical purpose, it must not allow identifying users. So for LB cookies, one must not use a unique ID per user, but an LB ID instead. Something like "node1", "node2" etc...
Because that's what was tried before GDPR, and it has proven to be a conclusive failure. https://en.wikipedia.org/wiki/Do_Not_Track
I assume this didn't happen due to industry lobbying.
I think the result would have been similar to what happened when apple did it's Facebook nerf. Within the margin of error no one wants to be tracked and the ad industry knows this despite their fake "user-benefit" Spiel.
In the end it didn't happen and I can't recall what it was called.
I hope they will go back on this and mandate DNT after all.
Run an adblocker. The Web was a total mess even before GDPR came along and not limited to Europe. If the issue of denying sites a revenue stream bothers you then perhaps make yourself a promise that you'll turn it off when ad networks stop being a vector for malware and/or stop engaging in the un-permitted collection and sale/abuse of personal data.
Personally, I run NoScript (as well as ad blockers) and so cookie popups are relatively rare on my Mac, but I still get them on iOS. I don't like them, but I see them as a warning that the site is going to try to exploit my personal data in return for serving me content.
It's also worth pointing out that there is no actual need to have a cookie banner unless you're doing something with the data that actually needs permission. For instance basecamp.com was GDPR/ePrivacy directive compliant when I was there, but never needed a banner because they decided to stop collecting and processing personal data in a way that required permission.
They tried to be clever by re-using the same cookie for multiple purpose essential and non-essential (the “essential” purpose being related to ad fraud detection) so they claimed they did not need consent to set the cookie. And since they argued that they chose to use a single cookie “to reduce the number of reads and writes”, which is bullshit, they were clearly not acting in any kind of good faith here. The regulator did not condemn them for the bad faith argument though, but because “ad fraud detection doesn't qualify as essential”, so their “smart” move of mixing essential and non-essential purposes within the same cookie wasn't even properly done:
> En outre, le rapporteur précise, en réponse à l’argumentation de la société considérant la finalité de lutte contre la fraude au sens large comme une finalité essentielle exemptée de consentement, que seule la finalité de lutte contre les attaques en déni de service pourrait être exemptée de consentement. Le rapporteur relève que les autres finalités évoquées ne relèvent pas du champ des exemptions prévues par l’article 82 de la loi Informatique et Libertés puisqu’elles n’ont pas vocation à faciliter une communication électronique et ne sont pas strictement nécessaires à la fourniture d’un service expressément demandé par l’utilisateur.
The regulator then remarked that mixing both kinds of purpose within the same cookie is explicitely forbidden anyway: (emphasis mine, on the relevant part)
> En premier lieu, s’agissant des cookies et autres traceurs multi-finalités, la formation restreinte rappelle que l’article 82 de la loi Informatique et Libertés exige un consentement aux opérations de lecture et d’écriture d’informations dans le terminal d’un utilisateur mais prévoit des cas spécifiques dans lesquels certains traceurs bénéficient d’une exemption au consentement : soit lorsque celui-ci a pour finalité exclusive de permettre ou faciliter la communication par voie électronique soit lorsqu’il est strictement nécessaire à la fourniture d’un service de communication en ligne à la demande expresse de l’utilisateur.
But yes, this all ended up being irrelevant since the court decided that they were using it for non-essential purposes before getting permission.