> the cookie provision, which has resulted in an overload of consent requests for internet users, will be streamlined. The new rule will be more user-friendly as browser settings will provide an easy way to accept or refuse tracking cookies and other identifiers. The proposal also clarifies that no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.
https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r...
Given that the EU has now conceded that point, we can finally get rid of this noise and move on. Hurrah!
Now, some of you may disagree with the above analysis, but your analysis is no more valid than anyone else's. EU privacy law is deliberately vague and open to interpretation so you can't complain when someone interprets it the way given above.
The laws themselves are not any more precise. I spent way too long puzzling over the wording in the GDPR.
Benefits:
(1) Don't have to trust the site to honor your consent.
(2) Sites won't try dark UI patterns (because they're not building the UI).
(3) More standardized UI because instead of each site inventing their own, they all use the browser's UI.
(4) Less tedium for the user. Browser can let the user choose defaults for the cookie consent dialog. Or define rules to handle certain choices automatically. And, if you can standardize categories (performance cookies, advertising cookies, etc.), then you can apply defaults and rules to those too.
(5) Web developers' jobs are easier. Just maintain and serve a cookie description data file. And of course be prepared to live without certain cookies.
Yes, this is extra work for the developers of browsers themselves. But it would be worth it. And apparently they're already spending engineering resources on cookie consent anyway.
Though they might be hard to enforce.
First, because they don't actually inform you of much.
Second, because they're tricky to understand if you're not a lawyer. Most of them mean "you have no privacy", but worded in a way that leads you to think you do.
Third, because it's a bit ridiculous to expect everyone to read them. You'd spend more of your time reading those damned things than the page you want to read -- and you'd have to read them on every visit because they can change at any time without notice.
Better is if sites would just give basic, truthful warnings at the moments where you are making a privacy-impacting decision.
I suppose we could require users to take a test to prove that they read the privacy policy. That would be interesting.
> I suppose we could require users to take a test to prove that they read the privacy policy
That wouldn't really address the main issue with them, which is that they're written in a deceptive manner. I can tell you right now what 90% of them mean: "you have none". But that's not how they read. How they read is things like "we may share your data with trusted partners in order order to deliver you a great experience".
but none of the ones I've read qualify as "informed consent" because even if they're clearly understandable, they don't fully inform you. They always mention sharing data with partners, for instance, but never say who those partners are, what data is being shared with them, and what those partners are doing with that data.
Unless you know that, informed consent is impossible.
Complaining about them seems to miss the bigger picture.