I click the link and I get a full screen pop up with the sentence in my face “cookies enable core functionality”
I’m trying to read some text man. All this tech and we can’t send a frickin link that opens to some text. Cmon.
I click the link and I get a full screen pop up with the sentence in my face “cookies enable core functionality”
I’m trying to read some text man. All this tech and we can’t send a frickin link that opens to some text. Cmon.
> Receive users’ consent before you use any cookies except strictly necessary cookies.
it further explains:
> [Strictly necessary cookies] are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.
Makes me wonder why we have all these cookie consent dialogs, either it's people playing it safe or they really do not set cookies for a true purpose.
if the latter: then all that's happened with GDPR is that we've been given visibility to the problem.. and it feels like everyone (including governments apparently) will adopt some measure of dark patterns to ensure they can still track people.
> These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user
How do you explain to the user what those cookies do and why they are necessary?
Is it OK just to have an explanation on your site's terms of service page or on its legal page, or do you have to put it somewhere you are sure the user will see?
you do not need to issue a pop-up, you just need the user to be able to find the explanation if they want to.
Which would require showing this info somewhere even for essential cookies. Is a popup required for this?
https://termly.io/faq/do-i-need-a-cookie-policy-on-my-websit...
"We use essential cookies to make our site work. With your consent, we may also use non-essential cookies to improve user experience and analyse website traffic. By clicking 'Accept', you agree to our website's cookie use as described in our Cookie Policy. You can change your cookie settings at any time by clicking “Preferences”. Preferences/ Decline/ Accept"
if you're not doing that then they're telling you that you don't need a pop-up.
A bit funny that this page does show a large popup so that you can accept their use of cookies.
They don't meet the legal definition of strictly necessary.
They don't really "track you" in any meaningful way - the most interesting info in the gov.uk cookies seems to be language (English or Welsh) and if the user provides it, country (England, Wales, Scotland or NI).
Still, the data falls under GDPR, so we get consent dialogs.
what you didnt mention is that:
> We also use LUX Real User Monitoring software cookies from SpeedCurve to measure your web performance experience while visiting GOV.UK.
stuff like this is why they need the consent dialog.
if instead of embedding tracing cookies and analytics JS they processed access logs, they would learn a lot without needing the dialog. However, since everyone just throws up the dialog (and users are trained to expect it) its “not worth solving”.
Most people, whether in government or in business, can't give a flying fsck about GDPR or whatever. They just want to get their primary job done, and to them stuff like GDPR is just legal red tape that's imposed on them and that serves no value whatsoever, merely serving as roadblocks slowing them down from doing their real job. They don't want to understand the intricacies of GDPR, they just want to get it over with as quickly as possible, which means slapping a cookie banner on the site, checking the "I am now compliant" checkbox that the GDPR officer nagged them with, and calling it a day. They don't want to go through the trouble of researching a couple of weeks what the best user-friendly way is of being GDPR compliant when they can just install a cookie banner in 5 minutes.
Sounds familiar? If you're a developer in a large corporation then I'm sure you have also been annoyed by the tons of security and firewall rules, and most of you would rather work around them than trying to understand why they exist and how to best comply to them both in mechanics and in spirit. Just like you're not deliberately trying to be evil and breaking the company's security, they're not deliberately being evil and trying to violate privacy.
Most people don't give a fuck about anything that isn't related to their current task. However, there are laws, and company must give a fuck about it and do such UX so that those that don't give a fuck are not fucked on spot.