A good heuristic is to look at which part of the industry is opposing it. If it's opposed by small businesses or individual developers or civil liberties organizations, that's a bad rule even (or especially) if huge tech conglomerates like it. But if it's the reverse -- like antitrust enforcement -- now you might be onto something necessary.
I don't think people will like eg Cybersecurity Act discouraging open source usage, or AI regulations mandating whatever we happened to call AI in 2023.
And the issue of lawfulness of "safe harbor" is still unresolved. US companies can just transfer data to the US where the US intelligence services can spy on it, regardless of what the laws of either country say.
On the other hand, people said that nothing would happen to the likes of Google or Facebook, as they'll just work around it. Well, that prediction aged poorly, the lawsuits have been progressing, and it takes only one DPA from one country to change things. Like how it was deemed that Facebook's ads targeting isn't a legitimate purpose, so they'll be forced to ask for consent without denying service for those that refuse.
Meta knows that GDPR spells doom for their business model, which is why they abstained from releasing Threads in EU, as a sort of warning perhaps. But it won't work, because the EU market is too big to pull from, which is why EU legislation has teeth.
And GDPR actually works, even if it takes some time for DPAs to solve existing cases. And the "cookie law" works too. People complaining about banners miss the forest from the trees: banners are mostly needed when doing spyware shit, and they serve as a great warning to visitors. There are no cookie banners on Mastodon.
A key issue is that the Ireland DPA is understaffed and overwhelmed, because that's where historically most of the global internet megacorps have registered their EU part for tax reasons, and it seems plausible that Ireland's DPA was intentionally understaffed because Ireland wants to be friendly with them, no matter how they affect German/French/etc consumers.
There seem to be motions about adjustments to the GDPR process which would allow other DPAs to take action with respect to their people's data without having to wait on the "company-local" DPA for however many years it takes. If that happens, I'd expect the situation for Google, Meta and others to change relatively rapidly (though still taking a year or more).
If next to every site does it, most people will think there's nothing unusual.
The websites needing cookie banners or GDPR consent dialogs are using personal data for serving ads or selling it to the highest bidder. It's not a sentiment, but a fact visible to anyone that cares to see it. And just because it's a widespread practice doesn't make it ok.
You're missing the point. The fact that nearly every website you visit displays the banner means that users become desensitized to it. It's just one more thing for them to click on, next to the dialog to permit notifications and whatever else. It's the same reason developers are encouraged to solve warnings, so that when a new one props up they will notice it quickly and decide if its a problem or not; if you normally get hundreds of warnings when building you quickly learn to ignore them, hiding any problems that might exist.
And it's different from the crying wolf of leaving unfixed warnings. The cookie pop-up often cannot be ignored as it requires some action to dismiss in order to view the actual content that the user was looking for in the first place.
Yes, because you're not thinking about the site asking for permission to track you (which was the original intent of the law), you're annoyed about your time being wasted. Which, I agree, is a total waste of time, but it doesn't counter my point that it desensitizes you to the signal the GDPR was meant to enhance.
>The cookie pop-up often cannot be ignored as it requires some action to dismiss in order to view the actual content that the user was looking for in the first place.
The user often cannot ignore the dialog in the sense that they cannot avoid interacting with it, but eventually they ignore it in the sense that they learn to automatically dismiss it without even thinking about it, like EULAs in software installers. Thus the dialogs become pointless.
I think there's a selection effect going on here: If tech and politicians agree that some policy is a good idea, then tech does it voluntarily, so no regulation is needed. The only cases where it becomes a matter of regulation are the cases where tech and politicians disagree.
For example: Remember the privacy discussion around COVID-19 exposure-tracking apps? If the exposure-tracking apps had been implemented in a naive way, they would have been incredibly invasive to privacy. But tech proactively figured out good solutions to the privacy questions, so it never became an issue. If some politician _had_ proposed regulation saying that exposure-tracking apps needed to protect privacy, then tech wouldn't have pushed back, because that's what they were already doing anyway. But because tech was already doing it, politicians didn't propose the regulation.
So, because an issue never becomes a matter of regulation unless tech pushes back on it, it ends up looks like "tech pushes back on all regulation".
Furthermore, in the cases where tech and politicians disagree, the politicians haven't always been right. For example, GDPR cookie banners are a joke. California's AB5 law is another example, as the original article mentioned.
So, I don't think "boy who cried wolf" is a fair analogy. Tech companies aren't always right, but it's not as if they're automatically opposed to all new policies; and when they do oppose politicians' proposed policies, it's sometimes for good reasons.
CCPA https://oag.ca.gov/privacy/ccpa in my opinion is a more straightforward law. Basically: if you want to sell someone's information you have to get consent first. It still has some of the "banner on every site" problem but at least most which are clearly for CCPA are binary ok/don't sell my data questions.
GDPR doesn't say much about cookies. What GDPR says is that you have to have a legal basis for processing user data. For example, a DPA just ruled that Facebook doesn't have a "legitimate interest" when using the user profile for ads targeting, so they'll be forced to ask for opt-in consent without the ability to deny service to those that refuse. A legitimate interest is for things the customer expects as part of the service, e.g. an address is needed for home delivery, or maybe data needed for security (IP logging).
https://thisisunpacked.substack.com/p/the-eu-war-on-behavior...
The cookie banners are needed when websites are fingerprinting users. The website may have a legitimate interest for doing analytics, but the user still needs to be informed that they are fingerprinted. NOTE: here, too, you don't need cookie banners if it's functionality that the user expects, like a session or a shopping cart cookie.
At the risk of repeating myself: websites need cookie banners or GDPR consent dialogs mostly when doing shit that violates people's privacy.
I've read a lot of complaints against GDPR on HN and elsewhere and I feel that it misses the forest from the trees: those banners and dialogs expose just how widespread the practice of violating people's privacy is. And I fear that a lot of the backlash coming from Silicon Valley has been from people connected to the ads industry.
As I point out every time this comes up, under ePrivacy the burden the site has to meet is not "expects" but "strictly necessary to satisfy a user request". And the way most sites implement shopping carts, where items will still be in your cart if you close your browser and come back the next day, isn't ok:
a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours in the future to take into account the fact that the user may accidentally close his browser and could have a reasonable expectation to recover the contents of his shopping basket when he returns to the merchant's website in the following minutes. https://ec.europa.eu/justice/article-29/documentation/opinio... (2.3)
Maintaining a shopping cart across days isn't "strictly necessary" and so requires explicit consent.
I don't think the difference between hours and days is relevant, unless the law says that there's a difference. Setting user preferences, such as the language, is a matter of accessibility. I'd be hard-pressed to think of a better sample of “strictly required”.
Setting user preferences, such as a “dark mode” toggle, wouldn't be any different from setting the browser or operating system's dark mode preference, a bit that web pages can always read.
It's important to remember that ePrivacy isn't strictly about cookies, but about all client-side data that gets sent to the server. For example, in case you're doing analytics, fingerprinting via any other means except for cookies (e.g., user agent, HTTP referrer, IP, etc.) still counts under ePrivacy. As such, you can fingerprint users via “window.matchMedia('(prefers-color-scheme: dark)')”, and if you do that, then yes, you need a cookie banner. But not for doing what the user agent asked for.
For analytics, indeed, you need a cookie banner. And while it's a concern of service providers to improve their service that I understand, it's not something that the user expects. And my personal problem is that the entire web ended up using Google Analytics. Such data ends up being shared with third parties, which is why it's good that it is opt-in.
I do agree that businesses should consult lawyers (^^)b
My claim is that many things users might expect to be retained are not automatically ok to retain, and that shopping carts as typically implemented are one of these.
The fact that cookies are A) only loosely correlated with undesired behavior and B) already optional makes it absurd that every site I visit should waste 10 seconds of my time with a banner asking me to consent to their use of cookies. Especially because the only way for them to remember that preference is... to give you a cookie!
Fortunately Brave has an option to automatically skip those banners, which works on most sites.
I think you are missing another, equally massive, source of information politicians are exposed to: lobbying. We see Microsoft complaining about mergers, but politicians are exposed to non-stop lobbying.
Many of the sites actually don't require cookie notifications because strictly necessary cookies^ are GDPR compliant but they still display the notification. In theory if cookie notifications were omitted when possible then sites who track more than needed would stick out immediately.
^ Strictly necessary cookies are essential for websites to provide basic functions or to access particular features of it. Such features include the ability to sign in, add items to your cart in an online store, or purchase stuff on the internet.
And these cases are the utter majority.
> For example, GDPR cookie banners are a joke.
They are, but only for those services that want to squeeze their customers like they're data lemons. What you need to do to provide the customer with the service they desire is covered automatically, the thing where you need a GDPR consent banner is if you want to include a truckload of external services to track your users across the Internet.
By all means, this one cookie - whose use was completely voluntary - was a 'technical cookie' which I do not need consent for under the EU's cookie laws.
It took about 30 minutes after the go-live before the first madmen came around and started shouting at me that I needed a cookie banner.
The problem with that law is not only that it caused everyone to set up a cookie banner to operate as they used to, it also is that it created a class of people who are self-declared data protection vigilantes.
I do consider publishing on Gopher (or Gemini) in the future, if only to prevent zealots - who often have no technical knowledge - from accessing my services. The people I address are capable - and willing - to use other protocols.
I think it's the opposite -- tech and politicians agree on the vast majority of things, but they're considered banal so the topic never comes up. But, you could imagine an alternate universe where tech did things differently, and then politicians wanted to regulate them. Here are some examples:
* Tech companies offer most of their services for free. You could imagine a world where Google charged for searches and Facebook charged for posting, and so "poor people being excluded from the Internet" became a political issue.
* Tech companies translate their services into a variety of languages. You could imagine a world where Google and Facebook were only available in English, and so "non-English-speakers being excluded from the Internet" became a political issue.
* Tech companies don't allow anyone to view DMs, private posts, etc. except law enforcement. You could imagine a world where Google and Facebook had a culture where it was normal for employees to snoop on other peoples' DMs, and it became a political issue.
* Conversely, you could imagine a world where tech companies refused to allow law enforcement access to peoples' DMs even with a valid warrant, and it became a political issue. (This is starting to happen.)
* Tech companies allow anyone to post by default. You could imagine a world where tech companies only allowed people to post if tech companies liked their political views (similar to how newspapers' biases affect which editorials they publish) and it became a political issue. (This is starting to happen: the left is pressuring tech companies to restrict certain right-wing content, and the right is talking about regulation to force tech not to do that.)
* Tech companies sometimes kick people off the platform for arbitrary procedural reasons, but not for personal pettiness reasons (with the notable exception of Elon Musk kicking people off Twitter). You could imagine a world where it was normal for e.g. Google to delete a journalist's GMail account if the journalist published something Google didn't like, and it becoming a political issue.
* Tech companies often contribute to open-source standards and software. For example, Google is heavily involved in defining web standards; and they made Chromium open-source, allowing rivals like Microsoft to build on it. You could imagine a world where the tech ecosystem was much more fragmented and closed-source than it is today, and it becoming a political issue.
This is what I was saying about a selection effect: You can easily think of ways that politicians want to regulate tech more, because those topics are controversial and make the news. But there are actually a ton of ways that tech _could_ be much worse than it is, but those topics never come up, so it takes some imagination to think of them.
That doesn't require new regulations, though. Just need to enforce the existing law.