I'm especially skeptical about legislation coming from the body responsible for making me click dozens of "Accept Cookies" buttons every day.
I'm especially skeptical about legislation coming from the body responsible for making me click dozens of "Accept Cookies" buttons every day.
If clicking 'no' is effective, it raises the question of why can't that just be done automatically for me by my browser, sparing me the obnoxious nag screens
Because it's in the website owner's best interest to make the rejecting process be as cumbersome and annoying as possible. The whole thing is a show of bad faith.
- Persisting a shopping cart. - Storing your login session. - Identifying the node that should handle your requests.
Site operators are forbidden by the law from using essential cookies for tracking purposes.
If a site operator is classifying tracking cookies as essential, or using their essential cookies for tracking then they are very likely acting in violation of the law.
Without it the user cannot know whether an app or website will track them without first visiting it. The act of loading the site can expose the entirety of your browsing activity to the site operator. Whether you would have agreed to those terms or not isn't factored.
How does the average user tell that a site that they initially found to be free from tracking hasn't started to track them since?
It's largely predictable how companies will react to legislation, and it's 100% clear afterwards, and it's very much the fault of the EU for sticking to the path of cookie popups.
GDPR brought a lot of new UI to existing sites, but I don't get the feeling that we were on a good trend from the start, nor that the sites that care about their users got a lot worse because of it.
I mean, at that time we were getting out of Flash inserts and the whole industry didn't seem to ever stop to think about what they were doing. The very notion of user consent was foreign to many agencies before GDPR.
PS: even looking at the sheer amount of "subscribe to our newsletter" splash dialogs out there make the clumsiest cookie popups look cute to me.
I know what the responses will be: "its a great law with poor enforcement". Perhaps that's true, but if so what makes us think additional EU tech regulations will be any better enforced?
I personally saw drastic improvements. I remember marketing adding or rotating trackers every 3 months as they got pitches from random companies.
Those basically vanished the day we had to keep track of which company stored their data in which region, and where in the privacy policy list we had to slot them.
User data still goes to Google or Adobe, but getting rid of all the weird scammy players is a win in my book.
And it also helped justify investing in stronger internal data management and analysis instead.
Basically adding random third party libraries suddenly had a material cost, and I don't see any other initiative that could have realistically reached that result.