You are falling into the trap that Americans normally do that think that the directive have anything to do with cookies or that the cookie banner was requested by the EU.
The requirement is simply
> You may not collect personal information without consent.
If they have an obnoxious advertising and data harvesting cookie banner then that was a design decision to make you opt in.
Equally, this is incorrect:
> You may not collect personal information without consent.
There are a whole host of reasons listed in Art. 6 when you do not need consent.
I didn't feel that logs would be relevant in this case because you would log that the Do Not Track header was present.
As a distilled version of the GDPR I still feel it hits the point.
It didn't.
Companies not willing to comply with GDPR did. As they didn't want to comply with Do Not Track header and used it for fingerprinting.
A technicality on linguistics in this case as a header would still satisfy the requirement.
Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
It has been planned for a long time to replace the ePrivacy Directive with the ePrivacy Regulation (https://en.wikipedia.org/wiki/EPrivacy_Regulation) which was actually going to replace the cookie banners with browser settings, but so far the ePrivacy Regulation is kind of stuck because of successfull lobbying by ad companies.
You also need to have the right to refuse, which is a non-issue if tracking is opt-in, or only happens in a necessary context like user login, where you can inform the user that it's about to happen.
It's a more or less deliberate misunderstanding to claim that you need popup banners because of EU regulation, and it seems to be said mainly in order to mask the fact that applications are designed to be hostile to privacy in the first place.
American companies are adversarial actors who always do the least effort to continue on.
Same cookies that get set by the annoying banner when you click through their BS to the "save my preferences" button
The concept of a government sincerely passing a law that genuinely and competently protects the privacy of its individual citizens seems absurdly unlikely to many of us. Laws are not created for individuals except when a cynical politician wants votes from the gullible. Circumventing such a "stupid", "anti-business" law as the GDPR is almost an American duty.
The EU rule was to prevent someone collecting personal identifying information and then sell it on without consent.
A really simple read can be found at the ICO.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
The "cookie banner" is to work around the fact that there are 3rd parties who would have access to your information without your consent and they want it to be awkward so that you consent.
If your application is a fitness tracker then of course you are going to have a lot of personal information. You are not allowed to sell it without consent, tracking in this case is selling information to Google et al.
You tracking a logged in user, via a shopping cart as a cookie, does not violate the GDPR.
Not the GDPR, the ePrivacy Directive. More: https://www.jefftk.com/p/why-so-many-cookie-banners
Event making a TCP connection to a non-critical third-party requires consent
https://ico.org.uk/for-organisations/guide-to-data-protectio...
It's really simple.
The reason DNT failed is because the companies that benefit from tracking users also build web browsers, and can influence how the web is built. DNT directly impacts their revenue, so they have no incentive to make it a standard.
Having worked on the backends of some of these systems, I think I'm fine with being tracked, especially in the general analytics sense. The issue I have is in being targeted or getting content that is too personalized based upon the tracking.
> the companies that benefit from tracking users also build web browsers
It is generous that they still refer to it as a "User Agent" in their self serving standards. In a functioning market, things like AdBlock and Privacy Badger would be default features in any respectable web browser and the browser would actively attempt to frustrate efforts at fingerprinting.
What ever happened to Opera as a paid product? I guess I'll have to click through their cookie preferences banner to find out...
From https://oag.ca.gov/news/press-releases/attorney-general-bont...: "“Technologies like the Global Privacy Control are a game changer for consumers looking to exercise their data privacy rights. But these rights are meaningless if businesses hide how they are using their customer's data and ignore requests to opt-out of its sale,” said Attorney General Bonta. “I hope today’s settlement sends a strong message to businesses that are still failing to comply with California’s consumer privacy law. My office is watching, and we will hold you accountable."
Regulators of course should enforce the simple fact that this is also a requirement for anyone who dismisses a consent popup, has a browser setting that suppresses it, or even someone who clicks the biggest most obvious button - since all those actions (or non-actions) must result in "no consent".
So while the dark pattern approach has merits to sites that want to track you, they must also be aware this is a balance. And a percentage of users will generally prefer to go to sites that leave them alone. That is: the cookie dialogue never widens the funnel.
Those cookie banners are illegal under GDPR, btw.
Real "Legitimate Interest" does not even require consent, and you can't claim that tracking or marketing is "legitimate interest". An example of legitimate interest is keeping your address in the records after a purchase, or storing a receipt for accounting reasons.
I suppose that is a matter that strikes a chord with me.
It cannot. That's the whole point of the GDPR. It forbids tracking without informed, explicit user consent. Users cannot be informed or agree with the header setting.
Sites can, of course, not track users, or not track users who set do not track. They don't want to, that's why they try to annoy and/or mislead anyone into agreeing with their horrible banners.
(Using Cookies for site settings or even logins can be done without explicit consent and without banners)
In it's simplest form it says: if you want to collect more data than is required, you have to ask users for consent.
This applies in equal measure to sites, banks, grocery stores, shopping malls, shit processing plants, nuclear reactors etc.
But there is a need for clarification here for the most often encountered consent case: web sites.
Basically the regulation could say: you must have consent to collect data, but you must ALSO observe specific standardized method X of of blanket disallowing all consent in specific contexts. For example, "if do-not-track is used in a web browser, then the user should not be shown a consent dialog but instead provided the service as if they had rejected the consent dialog".
I realize that regulators (for good reason!) are very reluctant to specify specific technologies. It's not their home turf, and it's likely to be quickly outdated. But I'm ready to accept that this would be a time when there is a good reason to make an exception to that rule.
GDPR requires that the user is able to refuse non-essential cookies. A banner, if used, needs two buttons, "Accept" and "Refuse" or something similar. Refusing should be as easy as accepting. And you MUST not serve the cookies unless the user really clicks on "Accept". This means that by default your website must work without those cookies.
So, if you want to honor the "Do Not Track" header, all you have to do is not show the banner at all, and don't use cookies that the user should be able to refuse. Done. You're compliant.
Why companies don't do it? Because companies want to force users to accept tracking. Cookie banners are nothing but a dark pattern, period. GDPR doesn't mandate them.
Most websites that use ads or (opt-out) tracking choose to ignore the header because there's no technical or legal reason why they can't.