They are more akin to the "Do not eat" warnings on silica packs... except on the internet everyone swallows.
They are more akin to the "Do not eat" warnings on silica packs... except on the internet everyone swallows.
I just check some web pages from diffrent organs of the EU:
https://commission.europa.eu/select-language?destination=/no...
https://www.consilium.europa.eu/de/european-council/
https://european-union.europa.eu/institutions-law-budget/ins...
They all have cookie banners, some of them are super prominent and annoying. So maybe they as well are doing malicious things, maybe they don't understand they own regulation, or it is just impossible to have a non-trivial web page without a cookie banner in 2023. In either case, the regulation is totally dettached from reality and has become just some ritual.
not completely wrong.
ime in the case of the cookie law, most ppl didn't actually bother to go into details and just took the word on the street and some existing 'solution' and called it a day since everybody was doing it this way and sales/executives were pleased.
fact remains: cookie banner is _not_ necessary for logins and most existing banners are outright illegal since 'no' is not an easily accessible option
Don’t track people for non-essential reasons, then you don’t need to ask for consent, which means you don’t need a cookie banner.
To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies.
Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
Document and store consent received from users.
Allow users to access your service even if they refuse to allow the use of certain cookies
Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
If you want to save a person's login to make it easier for them to log in when they come back? That's not strictly necessary - consent is needed. If you save settings to a cookie - that's not strictly necessary - consent is needed. And then there's the "using a cookie to track a session to determine page bounce rate - even if it's not Google Analytics" - consent is needed.And of course, consent is needed if you are using cookies for marketing.
The consent is implied in login functionality. Literal example from same article you cited but apparently didn't bother to read in full:
> These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookie
Essentially if cookie is effect of user action that would directly indicate it needs storing state (cart, login, stuff like switching themes on page) it is "essential" to that feature and doesn't need consent.
> Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in.
> When people complain about the privacy risks presented by cookies, they are generally speaking about third-party, persistent, marketing cookies.
Nothing is helped or solved by insisting first party "site preferences" cookies need consent. There's obviously room for interpretation in regards to what is a "strictly necessary cookie" when it comes to site preferences, account tokens etc.
Analytics and marketing tracking cookies require separate consent, that’s correct. I would prefer websites to refrain from attempting such tracking completely.
Theoretically websites could choose to do better, but the EU should absolutely have predicted this outcome.
Yes it is.
tracking pixel ? Are you sure you know what you're talking about ?
HN being an American company probably violates some section of the GDPR (not having someone labeled as the privacy officer or some other technicality) but I doubt anyone cares. If you feel your privacy is getting violated, you can try contacting your local DPA.
In terms of cookies and data processing, I don't think HN is breaking the law anywhere, unless the privacy policy is full of lies and dang is secretly selling our personal info on the site (he isn't).
It's okay, though. No DPA will go after HN.