Consent-O-Matic: Automatic cookie management
consentomatic.au.dk
consentomatic.au.dk
You are falling into the trap that Americans normally do that think that the directive have anything to do with cookies or that the cookie banner was requested by the EU.
The requirement is simply
> You may not collect personal information without consent.
If they have an obnoxious advertising and data harvesting cookie banner then that was a design decision to make you opt in.
American companies are adversarial actors who always do the least effort to continue on.
A technicality on linguistics in this case as a header would still satisfy the requirement.
Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
It has been planned for a long time to replace the ePrivacy Directive with the ePrivacy Regulation (https://en.wikipedia.org/wiki/EPrivacy_Regulation) which was actually going to replace the cookie banners with browser settings, but so far the ePrivacy Regulation is kind of stuck because of successfull lobbying by ad companies.
You also need to have the right to refuse, which is a non-issue if tracking is opt-in, or only happens in a necessary context like user login, where you can inform the user that it's about to happen.
It's a more or less deliberate misunderstanding to claim that you need popup banners because of EU regulation, and it seems to be said mainly in order to mask the fact that applications are designed to be hostile to privacy in the first place.
Equally, this is incorrect:
> You may not collect personal information without consent.
There are a whole host of reasons listed in Art. 6 when you do not need consent.
I didn't feel that logs would be relevant in this case because you would log that the Do Not Track header was present.
As a distilled version of the GDPR I still feel it hits the point.
It didn't.
Companies not willing to comply with GDPR did. As they didn't want to comply with Do Not Track header and used it for fingerprinting.
The reason DNT failed is because the companies that benefit from tracking users also build web browsers, and can influence how the web is built. DNT directly impacts their revenue, so they have no incentive to make it a standard.
Having worked on the backends of some of these systems, I think I'm fine with being tracked, especially in the general analytics sense. The issue I have is in being targeted or getting content that is too personalized based upon the tracking.
> the companies that benefit from tracking users also build web browsers
It is generous that they still refer to it as a "User Agent" in their self serving standards. In a functioning market, things like AdBlock and Privacy Badger would be default features in any respectable web browser and the browser would actively attempt to frustrate efforts at fingerprinting.
What ever happened to Opera as a paid product? I guess I'll have to click through their cookie preferences banner to find out...
Same cookies that get set by the annoying banner when you click through their BS to the "save my preferences" button
The EU rule was to prevent someone collecting personal identifying information and then sell it on without consent.
A really simple read can be found at the ICO.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
The "cookie banner" is to work around the fact that there are 3rd parties who would have access to your information without your consent and they want it to be awkward so that you consent.
If your application is a fitness tracker then of course you are going to have a lot of personal information. You are not allowed to sell it without consent, tracking in this case is selling information to Google et al.
You tracking a logged in user, via a shopping cart as a cookie, does not violate the GDPR.
Not the GDPR, the ePrivacy Directive. More: https://www.jefftk.com/p/why-so-many-cookie-banners
Event making a TCP connection to a non-critical third-party requires consent
The concept of a government sincerely passing a law that genuinely and competently protects the privacy of its individual citizens seems absurdly unlikely to many of us. Laws are not created for individuals except when a cynical politician wants votes from the gullible. Circumventing such a "stupid", "anti-business" law as the GDPR is almost an American duty.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
It's really simple.
From https://oag.ca.gov/news/press-releases/attorney-general-bont...: "“Technologies like the Global Privacy Control are a game changer for consumers looking to exercise their data privacy rights. But these rights are meaningless if businesses hide how they are using their customer's data and ignore requests to opt-out of its sale,” said Attorney General Bonta. “I hope today’s settlement sends a strong message to businesses that are still failing to comply with California’s consumer privacy law. My office is watching, and we will hold you accountable."
Regulators of course should enforce the simple fact that this is also a requirement for anyone who dismisses a consent popup, has a browser setting that suppresses it, or even someone who clicks the biggest most obvious button - since all those actions (or non-actions) must result in "no consent".
So while the dark pattern approach has merits to sites that want to track you, they must also be aware this is a balance. And a percentage of users will generally prefer to go to sites that leave them alone. That is: the cookie dialogue never widens the funnel.
Those cookie banners are illegal under GDPR, btw.
Real "Legitimate Interest" does not even require consent, and you can't claim that tracking or marketing is "legitimate interest". An example of legitimate interest is keeping your address in the records after a purchase, or storing a receipt for accounting reasons.
I suppose that is a matter that strikes a chord with me.
Most websites that use ads or (opt-out) tracking choose to ignore the header because there's no technical or legal reason why they can't.
It cannot. That's the whole point of the GDPR. It forbids tracking without informed, explicit user consent. Users cannot be informed or agree with the header setting.
Sites can, of course, not track users, or not track users who set do not track. They don't want to, that's why they try to annoy and/or mislead anyone into agreeing with their horrible banners.
(Using Cookies for site settings or even logins can be done without explicit consent and without banners)
In it's simplest form it says: if you want to collect more data than is required, you have to ask users for consent.
This applies in equal measure to sites, banks, grocery stores, shopping malls, shit processing plants, nuclear reactors etc.
But there is a need for clarification here for the most often encountered consent case: web sites.
Basically the regulation could say: you must have consent to collect data, but you must ALSO observe specific standardized method X of of blanket disallowing all consent in specific contexts. For example, "if do-not-track is used in a web browser, then the user should not be shown a consent dialog but instead provided the service as if they had rejected the consent dialog".
I realize that regulators (for good reason!) are very reluctant to specify specific technologies. It's not their home turf, and it's likely to be quickly outdated. But I'm ready to accept that this would be a time when there is a good reason to make an exception to that rule.
GDPR requires that the user is able to refuse non-essential cookies. A banner, if used, needs two buttons, "Accept" and "Refuse" or something similar. Refusing should be as easy as accepting. And you MUST not serve the cookies unless the user really clicks on "Accept". This means that by default your website must work without those cookies.
So, if you want to honor the "Do Not Track" header, all you have to do is not show the banner at all, and don't use cookies that the user should be able to refuse. Done. You're compliant.
Why companies don't do it? Because companies want to force users to accept tracking. Cookie banners are nothing but a dark pattern, period. GDPR doesn't mandate them.
The banners are there not because they are required, but because websites want to badger you into agreeing to tracking. Websites don't need to show a banner if tracking is opt-in or if first-party cookies are only used for functionality not tracking!
This is why even though DNT exists, nobody respects it. The point is to make it annoying so people cave in to agreeing to allow tracking. Any standard that is not "by default allow tracking" will not get adoption from the site owners because it reduces the tracking they can do. Obviously, the whole point of the EU cookie regulation / GDPR is to not have tracking by default (which is unfair to the user), but at the same time, being a regulation, it also doesn't want to default to "no tracking until opt in" as that would then be unfair to the sites. If you can't allow by default and can't deny by default, the the only remaining option is to ask.
This is really a no-win situation.
A naiive search for "legitimate" in the repo shows 10 files [0] hard-coded into specific rules sets.
Which I interpret as: it's only available on those. Which is a real shame. I'm so damn sick of manually deselecting all of the hidden consent toggles :C
[0] https://github.com/search?q=repo%3Acavi-au%2FConsent-O-Matic...
$0.querySelectorAll('.thirdparty button.optoutToggle').forEach(({click}) => click())
Where $0 is an automatic reference to the selected parent element. The pseudocode/example string passed to querySelectorAll should be a selector (same syntax as selectors in CSS) to get each individual toggle element. Then forEach of those toggles it simulates a mouse click event.That said, whatever is on these websites isn't usually even worth all this effort and it doesn't always work.
Dark patterns are everywhere and there's seemingly no widespread boycott against them. Open source projects should have banners about them on their homepage, as they've had for other social issues.
Even worse, look at this BS: https://i.imgur.com/Q0Hlzk3.png
The button that says "Do not sell my information" means YES DO sell my information when it's "on."
I complained to them directly and said I'd pursue a complaint with the CA state's attorney, and to my surprise they actually changed it. But you still see this: https://i.imgur.com/fx0pqxA.png
But alas, Consent-O-Matic is a cool tool for the present
Notably, the popular mainstream browsers haven't implemented this and so you need an add-on for it. Irritating.
For Firefox, you can enable GPC in `about:config`. You'll want to flip `privacy.globalprivacycontrol.functionality.enabled` and `privacy.globalprivacycontrol.enabled` both to `true`
For Brave, GPC is enabled by default.
You can test your browser by going to https://globalprivacycontrol.org. It'll tell you at the top of the page if you have GPC turned on.
Almost all websites have this "necessary cookies" song and dance going on. There are no necessary cookies, I view your page and then close it and we can delete everything. It's total nonsense.
99% of websites I visit that do the cookie crap I never log in to, though. The banner could easily be kept until that point.
I actually hate that it gets distilled down to cookies in discourse.
NoScript came out in 2005.[1]
He said he's "using noscript like it's still the 90's", as in he's using NoScript as if he was still in the 1990s. Problem with that is NoScript did not exist in the 1990s.
As an aside, NoScript did not exist, "browser extensions" in general did not exist (not counting toolbars...), and ads, Shockwave Flash, and some JavaScript were already very much a thing in the 1990s.
Honestly Manifest v3 was contentious because it essentially nerfed adblockers completely -- and for that reason I really despise it.
But it sounds like exactly what you're asking for.
What is your alternative though? Surely things like this would need to access basically every website in order to be useful, and more-so on websites you'd never visited before.
You can always use something like chrome/firefox profiles which enable different plugins for different uses if that makes you feel safer.
> Surely things like this would need to access basically every website in order to be useful, and more-so on websites you'd never visited before.
Probably some kind of blacklist instead. E.g. This extension cannot run on these websites. We already have a more basic version of this with the allow running incognito option.
Right now, consent means a contractual agreement.
In the near future, with systems becoming more sophisticated and regulated (EU, I look at you), visiting a website in this sense means two lawyers negotiating a contract you simply agree to.
From "personal homepage" featuring almost anything from silly stuff to personal disclosures to "Sign here before you can see my content!" in less than 15 years.
The current situation is purely a result of advertising companies fucking you over, not because of Europe.
P3P was an early version of this concept: a browser-native privacy control system. No websites used it, it was only ever implemented by Microsoft, and has been removed from the last remaining browsers a while back.
I think Apple, Google, Microsoft, and Mozilla coming together to set up a privacy protocol to replace cookie banners would be the right way to handle things. Until usable browser UI exists, there's no way to force the companies currently employing dark patterns to comply.
A solution which might actually improve enforcement would be to have someone filter the requests that come into Consent-O-Matic and forward them to the authorities in a monthly digest. Quality reports from a human who actually put effort into making them will get more traction than automated, low-quality reports. Make it easier to enforce the law, not harder.
Compare it to the abominations that the greedy tracking leaches from OneTrust, IAB etc. are presenting.
> In most cases, the add-on just blocks or hides cookie related pop-ups. When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do). It doesn't delete cookies.
What you can do is eg. not enable the microphone when the website asks for it, not send the GA cookie back with requests to spin the visitor counter, or make the browser pretend that you have a bog-standard screen resolution and font selection. They will not have the information, so only the lack of information can be used.
If the cookie that stores your logged-in status is used for other purposes like getting more relevant ads in front of your eyeballs, that sucks. One can only hope that they are separated by functionality, or the candidates for more dubious activities are given out by a third party.
There are obvious ways of proving whether any cookie or non-cookie mechanism is employed for a purpose you did not give permission for, namely, audits of their systems and testimonies of their employees, which has resulted in quite a few huge fines being assessed and the illegal activity stopped, and will result in more.
We simply have to not legitimize this being done as "business as normal" and have to make it clear that they are not permitted to do so - all the really big impact comes from the large megacorps who eventually have to stay above the board legally.
No ads, no third parties.
You can even show ads; ads don't require tracking, or even third parties.
You can access it through the 'about' tab in the extension.
The main issue really is that publishers and ad networks conflate tracking and ads. I'm pretty tired of sites popping up a message saying: "We need to talk about your ad blocker". I don't block ads, I block tracking, remove the tracking and we're good.
Context based ads works almost as well as those based on endless amounts of personal information. They are good enough, they worked well for decades. The problem is that they are a lot hard to sell/buy and modern online ad specialist aren't qualified to do it, they can only click around the Google AdWords or Facebook Ads.
The usual response I get to this position is "but I don't want to pay with money and I don't mind ads, and I really like the content, should you be making the decision for me that I can't participate in that transaction?" To which my answer is yes.
They don't. What they say is that businesses shouldn't assume that people's private data is theirs for the taking. People still have the choice to opt-in to pervasive tracking.
Basically: I think it would be fine for anyone to participate in market transactions with transparency. But I don’t think there can be transparency here, or that if we really tried then almost no one would accept the transaction anyway.
So I’m thinking a ban of the transactions is the lesser evil.
We already ban e.g sale of your own organs. I’m fine with that too. Now, am I the right person to decide whether people value their kidneys like their integrity? Yes.
And I know the change won’t happen. I’m aware of that. I’m just saying that alternatives are out there.
Actually, it's a bit more nuanced than that, because merely by using the #1 analytics solution, even without shady practices on your part, you already put your visitors' data at risk. Other example: embeds. I used Vimeo rather than YouTube to embed videos, using their rather honest do-not-track option, but went the extra mile and disabled localStorage for them, to ensure no data whatsoever was left. So almost all business owners need to actively want to protect their users' privacy, but this is a consequence of a few big players' explicit choices. See above.
[edit: style]
Which parts of it are user-hostile? The consenting part, or the opt-out part?
We can criticize the solution, sure. We can also criticize the end result. But the intention was a good one and it was worth doing imo because at some point something has to be done.