Understanding the data you collect, why you are collecting it, what you are using it for and what the risks are if the data is leaked is unsurprisingly a useful thing to do as a business.
Understanding the data you collect, why you are collecting it, what you are using it for and what the risks are if the data is leaked is unsurprisingly a useful thing to do as a business.
I think GDPR is generally good for individuals and the internet but if someone hates cookie banners, isn’t it fair to place the blame on GDPR?
Why can’t websites accept a special header which automatically accepts all cookies? I would enable it and handle clearing/retaining cookies myself through a browser feature/extension.
No, blame companies that set cookies for merely reading a website and then bothering users about it. They have a choice, they choose to make it obnoxious.
I could be wrong but IIRC cookie banners predate gdpr.
It did not specify cookies, and did not actually specify any technical means. The ePrivacy Directive requires that companies get consent from users before storing information or gaining access to information stored on end user devices. This includes every kind of cookie you can think of, including LocalStorage. There is an exception for cookies necessary for the service requested, which typically includes things like auth cookies or shopping cart cookies, so long as that data is not used for anything else.
The GDPR doesn’t specify the technical means, only that permission must be explicit and freely given, with the default assumption being “no permission granted”. I think these conditions are entirely reasonable, and a header that could be set by somebody other than the user, then sent by the browser on behalf of the user, does not satisfy these conditions.
Most entrepreneurs believe that visibility over how your visitors are using your website is “strictly necessary” for running a functional/secure/performant website and surviving as a business, but GDPR disagrees. Hence, cookie banners everywhere.
Not deemed “strictly necessary” > “Statistics cookies — Also known as “performance cookies,” these cookies collect information about how you use a website, like which pages you visited and which links you clicked on. None of this information can be used to identify you. It is all aggregated and, therefore, anonymized. Their sole purpose is to improve website functions.”
So much could have been simplified if the GDPR rules, instead of imposing burdens on a million websites, required the 3-4 browser vendors to have a toggle for preserving first-party cookies on sites where the user submits a form with a password field, and simply cleared all others at session end or periodically.
But by regulating browser vendors, they could have made it so that it doesn't matter what cookies they sent you. If the user hadn't consented in a browser UI, the browser would forget the cookies. Easy to verify compliance.
It's just like the ol' pathetic "Do Not Track" header. Same flaw. Asking "please don't give me a cookie that I'll have to keep and send back to you anytime you see me" instead of saying nothing, and just dropping the cookies you don't need on the ground.
This is not something that can be solved client-side other than obfuscation etc. They can track you with other means than cookies. Even worse, you might have an account on their site. Having an account and using the site (and logged in) makes it trivial to follow you, but that does not give them the right to abuse that information for other purposes. You might have an unique IP and can't reasonably expect to do anything about it.
GDPR covers all of that.
"Just delete your cookies/session" is not relevant.
So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner.
You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
> So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner.
Wrong. The ePrivacy directive has an exception for strictly necessary cookies (Article 5.3), which is applicable for user sessions.
The ePrivacy directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Search for “strictly necessary”. More details in this opinion from WP29, see section 3.2: https://ec.europa.eu/justice/article-29/documentation/opinio...
> You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
Are you able to identify someone from the fingerprint of their browser? Then the fingerprint is PII. Consent (or any other legal basis from GDPR Article 6) is therefore required if the exemption from the ePrivacy directive is not applicable.
GDPR Article 6: https://www.privacy-regulation.eu/en/6.htm
In the UK, current news cycle is about sewage being dumped on our beaches by water companies that were previously privitised.