Better would be to not (try to) do anything that requires cookie notices in the first place. Might not always be your decision but at least try to push back on the notion that this kind of tracking is needed at all.
For most of my life, it's been done with tickets you buy at a booth and put in your dash, then you use the ticket to exit
If all the privacy-violating companies go out of business, there will be plenty of underserved customers for companies with more legitimate business models.
No, I don't think so. I think most people would choose to pay with info rather than cash even if they have the cash simply because they don't fully grasp the actual cost to them. People make foolish (from my perspective) economic decisions all the time. I am currently traveling in the American south where I am surrounded by shockingly vast numbers of morbidly obese people who willingly trade their health for a sugar rush. No one is holding a gun to these people's heads and forcing them to drink sugary soda and eat fried food, but they do it anyway. They do it because they like it, and because they don't think about (or don't care about) the long-term consequences. People are (again, from my perspective) stupid. But I don't think it should be the role of government to save people from their own stupidity. That is a very slippery slope.
People also chose to use Netflix or Steam (and other streaming platforms) instead of pirating. Last one would (and still is) be free. So it's not unprecedented.
Personally, I handover all my fitness information, driving habit information, spending and banking and investing information, my health information, even my location data, my STD statuses, etc to a company so I can get massive discounts on a bunch of stuff in various ways. It alters my behavior in a good way, it alters other peoples' behavior too, and I'm all the more happier about it. I much prefer this over stupid things like sin taxes, consumption taxes and laws that most people don't stick to or agree with (talk about choice and consent, huh).
Another reason for this is addiction. Addiction has people doing things that aren’t in their best interest despite them being otherwise intelligent humans.
Even the words words "privacy" and "invaded" are such loaded and ambiguous language, I don't see how smart tech people are playing along with it as if it's some sort of innate human right in the electronic sense. You have to convince us, you don't get to just skip a few steps and tell us we're all crazy plebs that don't understand the implications of this thing you decided has to be the case. Hence the comment about this attitude being privileged (elitist).
Personally, I would love to see the kind of offers companies would start to make for opt-in tracking. In a much cooler world, people would be able to sell their data, as subscriptions, to companies, with premiums placed on more 'valuable' data at whatever given time, based on advertiser interest.
Of course, no data tracking would be ideal, for me. But if someone wants to sell their personal data, they should at least be able to sell it for a market price.
Yeah, I get that. What I'm sating is: that's a stupid rule. Why should I not be able to say that, especially if it's the truth?
If you can't afford to pay $5 cash, you certainly can't afford to pay the $6 the firm that's tracking you will make from tracking you.
What's the value of a persons data if that person cannot afford any of the products which are advertised using that data? On the other hand, persons on a limited budget are sometimes most happy to spend money unwisely.
The collection, buying, and selling of your personal data isn't always about ads. The data people have on you is increasingly used to determine what you can and cannot do, what opportunities you're offered, how much you pay for things, even how long you're left on hold when you call a company.
The data companies collect about you can get you arrested, can be used against you in family court, or prevent you from getting a job.
Even ads themselves aren't always about what you buy. Ads are often used to manipulate you, change the way you see the world, even change the way you vote.
People who buy ads or buy your personal data don't do so out of the goodness of their hearts. They do so in order to make up not only the cost of buying the ad/data in the first place but extract more money out of you, one way or another.
This means it should always be cheaper to just pay for the service yourself then "pay" via ads or exploitation of your personal data, since the latter involves more middlemen that want their cut.
The fact that poor people can currently "freeload" off the system is an artifact of imperfect targeting rather than intentional generosity on the advertisers' part to subsidize the poor population, and will be quickly closed off the second there will be a way to reliably distinguish the purchasing power of a user as to deny service to those whose ad views aren't profitable enough (as they would never be able to purchase the advertised products).
This is why many governments are in general responsible to provide enough social support that turns all citizens into privileged people.
No, that's not my position. My position is: tracking as a business model is morally justified if it is done with informed consent. A business arrangement is morally justified even if it has potentially deleterious side-effects to one of the parties so long as it is entered into with informed consent.
People buy and sell tobacco and firearms and motorcycles and junk food despite the fact that these products potentially have negative impacts on people's lives that are at least as serious as tracking. One could argue (and some do) that selling Coca Cola is not morally justified, but that position is hardly the slam-dunk that you imply.
I’m going to keep ensuring that this possibly-only-good-for-the-privileged world is realized and I think modern privacy regulation like the GDPR helps, which is why I’m supportive of it.
We're going to have to agree to disagree about that. Have you ever actually faced that choice? I haven't. Until I have, I don't think I'm in a position to make that decision on someone else's behalf.
Here's another thing to consider: we allow people to put their lives at risk in exchange for money and social prestige by joining the military. The only substantive difference I see between that and selling an organ is that the latter doesn't provide any tangible benefits to the elites who make the rules whereas the former does.
But if you assume the court decisions stands then if your business is based on tracking that means your business is based on illegal activities.
The only way out is to either change your business approach to comply with the law or go out of business. That’s no difference to many other activities that probably could earn money but are illegal.
Why? Tracking is not illegal. It's just tracking without consent that's illegal.
I don't - and I am fully informed and prepared. A month into the cookie banners avalanche and I just started clicking OK without looking. Now I have the "I don't care about cookies" extension and that's it.
I think this question is very context sensitive. The way privacy questions are usually presented ("we want to improve/personalize your experience"), I don't think most people care. But when presented with actual outcomes of loss of privacy (e.g. the Cambridge Analytica scandal) people seem to care a lot. For most people I suspect there's a gap in understanding between how people think their data is used and how it's actually used. Whenever this gap is closed by a major scandal where "how the sausage is made" is revealed, there's often a strong reaction.
But perhaps the biggest indication that people do care about privacy is that ad companies are so reluctant to allow them to opt out of tracking. If (almost) nobody cares, what's the harm in having clear consent or an opt out?
I have an alternative ideology to sell you...
we product enough to feed everyone.
That is: where you can’t track people without explicit consent, consent is as easy to not give as to give, and you can’t choose not to deliver the service or deliver a worse service to those who do not consent.
Scam: "a dishonest scheme; a fraud; a swindle"
I would argue, outside of our closest relationships, the majority of people are attempting to, or engaging in some kind of scamming behavior in at least half of their interactions.
At this point, 2023 worldwide, fear and distrust are table stakes for social interaction
But that the majority must still behave rightly paranoid that it is the majority in order to protect themselves from a really pretty small minority.
Yes well the whole point is to make things better - not just keep them the same
This relates to a piece of advice I gave my children: most people are fundamentally good and decent. A small percentage are not. The problem is that you can't tell which is which just by looking at them.
However it is unquestionable that the default mode for humans in America to operate is out of fear - and the opposite is by exception
Even in human interaction amongst your closest friends and family, they only interact with you for their own benefit - that just happens to be in pursuit of the endorphins/dopamine gained when they spend time with the people they share memories with, and it happens to be reciprocal.
Well, with exception of those which need to be shot with Hanlon's handgun[0]. There's surprisingly many of those, and not where people would suspect (e.g. I see it more often interacting with small businesses than with larger ones) - but in most interactions with others, I find it best to not reach for the handgun until it's clear it's needed.
--
[0] - "Never attribute to stupidity that which can be adequately explained by systemic incentives promoting malice." -- https://news.ycombinator.com/item?id=21691282
This is excellent advice for both metaphorical and literal handguns.
Large corporations where all human values are made illegal are quite shining examples how humans should operate in our system. This is sadly quite common in non-profits too.
I agree with this, but there are situations where because of obvious incentives you cannot make this assumption. Car salesman treating me like his best friend? I wonder why?
I think the numbers are way lower, but it is an old, archaic idea, you do good for your tribe/family - by taking from anywhere outside of the tribe. Stealing from the tribe is very bad and might get you killed. Stealing from another tribe however is not stealing, but reputable work, as long as there are no established friendly relations to that tribe. Many people indeed operate with this mindset (consciously or not)
But all in all I would rather say, that the number of people who consider all of humanity their family, is increasing.
This sentence shouldn’t be associated with anything “non-profit”
Proving yet again that, unless you structure your organization differently than every other capitalist thing (which means you won’t get funding through traditional sources) then you’re just helping capital further entrench their positions of power
You want to have some kind of impact, and you end up having to spending money to do that. You want the most impact and your funding is limited.
The STRUCTURE is wrong is the point.
The entire concept is built around would-be-aristocrats (Board) coercing the management and employees into allocating property (Money) based on their whim with no accountability or democratic function. It is built to exploit.
Instead they should organize as a non-stock cooperative so that is effectively impossible to exploit. That's the actual answer.
Maybe you can call it something else, but for a non-profit ROI is just answering the question "Are we spending our money wisely?
Or were you referring to the non-profit having a board?
Using concepts like ROI for non-profit operations is one of the signs how everything is made to emulate business.
If you don't care, switch on DNT and never see those banners again (assuming this ruling preveils).
Ugh, please don't give them any ideas
So as long as you are collecting personal information, there is no legal difference whether you do it via cookies or another different mechanism.
I'm an external auditor. The GDPR is a cash grab.
Regulations that actually incentivize organizations toward stronger privacy and protection practices are designed more like HIPAA or PCI where the MAGNITUDE OF THE BREACH is the primary factor determining the monetary fines imposed (e.g.,number of records exposed, was it PII, PHI, etc.).
Taking 4% of the company's annual revenue from the previous year, irrespective of the size of the breach, results in a regulation about as effective as clicking those cookie consent boxes. "Oh thank goodness I gave my consent, I think now we can all rest easy that our data is being handled securely and appropriately!" No, the EU included the ticky tacky consent requirement to create major global visibility about itself so that when a company doing business with the EU has a breach, they won't be surprised when they then get an additional bill from the EU for not only having the breach, but now being in violation of the GDPR too.
The GDPR is a despicable joke. And my use of 'the' gives me the right to that opinion. If anyone else out there was involved in GDPR's creation or implementation, I think you would agree:
GDPR owns the Greatest Dung Pile Record, Grandma's Dildo Paste Replenisher, the Gagging Damaged Penis Rectum and one Gigabyte of Dick Punch Radiation in addition to €2.83 billion (as of 12/2022) collected from breached companies in 1,401 cases for "violating the GDPR".
The other option would be to have fixed fines that Google et al. pay out of their small change, while it absolutly would torch their small competition.
Sure, they could also jail CEOs for this. I would also be for that.
If a fine doesn't grow with the income it is a fee. So if you want a corporation to follow your law, it needs to come with a fine that motivates those in charge enough to follow it. Money is the soft option there.
It is totally possible to run websites in compliance with GDPR. I built multiple that require no consent whatsoever, because guess what: No personal data is collected, where it is not absolutely technically required.
For me as an EU citizen the GDPR turned my data-related communications with companies from essentially begging into the void, to actually getting a response.
The GDPR doesn't mandate fines of 4% regardless of the nature of the breach. That's the maximum size of the fine.
You should go ahead and actually read the text of the GDPR. Specifically, Article 83.
Paragraph 1 states that "the imposition of administrative fines [...] in respect of infringements of this Regulation [...] shall in each individual case be effective, proportionate and dissuasive".
Paragraph 2 lists eleven factors that the SAs have to have regard to when setting fines, and top of the list is "the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them".
Many folks assumed DNT is useless. Yet here we are comenting in a thread about a court that is making it legally enforceable.
How exactly do you legally enforce "each link must not be a unique UUID generated per-user or per-page-view"? Do you mandate how "generic" a link has to be, such that a visit to that link exposes less than a certain amount of information about that visit? What about things like order-specific links on a shopping website, that will naturally identify an account if all orders share the same namespace?
Simplified it says: if you collect personal information, you need to ask for consent. If someone doesn't consent they must not receive degraded service. Now there has been a ruling that the Do Not Track info users send you shall be honored by you (duh).
This is true regardless of how you technically do it. So UUID URLs are okay, storing which IP adresses shared an UUID link with which other IP without consent is not.
I think some in the IT world need to finally stop making excuses and stop coming up with new illegal ways of tracking users on a personal level. Just use the same creative energy for finding ways of pseudonymizing and anonymizing users (where possible — depending on what you are collecting deanonymization might always be possible).
The truth is, that we had some rulings on what is considered personal data and what isn't and IP adresses, even parts of them can be regarded as such. Now you and I might think this is silly etc., but if we write software for corporations that have to pay fines as a feaction of their total revenue not knowing that can easily ruin our lives.
And I am merely reflecting the way how these laws have been interpreted and ruled on so far in the comment section for an article on, well another ruling by a court. Legal reality, like physical reality doesn't go away if you close your eyes.
Is this what you originally meant?
Nontheless I hope you can see in which way the whole thing is still deeply connected to the legal question of how one can still learn about their service without tracking single users when they don't give their consent, maybe now even via DNT header.
That is personal information.
It does not matter how you collect that personal information, so whether you use cookies, pen and paper, the digital equivalent of a rube goldberg machine or UUIDs in the URLs — totally meaningless. As soon as you process the IP and use that information for any purpose not considered legitimate interest you are on the hook (and no: if you are in doubt it is not legitimate interest).
Many wrongly believe GDPR is about cookies. It is not. It is about the information and the consent. So whether you change the collection mechanism doesn't make any difference if you still collect the info. It just means you now have to update your consent banner to include that new way of data collection as well ; )
Let me give you a hint: Because they are required to do so by law (at least in the biggest free market on the planet). Now maybe you can figure out how that law is called and why it is relevant in a discussion where the topic is DNT and a German court ruling it needs to be honored.
We are not discussing whether tracking is technically possible — that would be a pretty short discussion: Yes it is possible. So we are talking about something else. And if we are not talking about the law, why did you even feel a need to come up with a way of circumventing it?
To summarize: we’re talking about technical solutions to linking sessions across independent devices. What’s your “short discussion” answer to that?
So when the headline says »German court prohibits Linkedin from ignoring DNT signals« the interesting point isn't what is technically ancient history, but what that new legal reality might mean in practise for those of us who build, maintain and run the things that are affected by said legal reality.
Or what more did you have to say than hint at one very obvious and noticable way to do tracking?
So from my perspective: No. I jumped into a particular thread that seemed to imply one could "get around" that particular legal issue with a technical fix, which is just false. You sure can do that but it will not make the legal risk go away, just because you are not using cookies.
Now of course you could again go and attack the messenger instead of telling us why a technological workaround for a legal issue has nothing to do with the legal issue inside the comment section on said legal issue. Now because all of this could just be one great misunderstanding I am going to assume you don't know that much on the legal side of the issue and my comments on "your" thread came across as aggressive which raised the heat unnecessarily and was not my intention.
"No cookie or localdb or browser fingerprinting is going to tell you whether someone looked at a site once on their home computer, again on their phone while commuting, and again on a work computer to show colleagues."
My intention was to provide a mechanism for solving this problem. GDPR or even Europe in general has nothing to do with it.
Did they learn their lesson? Because that was an incredibly foolish assumption out of the starting gate; from old-guard developers and companies' points of view, they were stomping into a sandbox they hadn't built and upsetting the status quo that was working; of course malicious compliance should have been anticipated.
Are you telling me that EU lawmakers were utterly naive to common left wing critiques of capitalism? That beggars belief.
The banners were an extremely predictable outcome of a badly-crafted law.
I think this is unlikely to happen, because most websites actually want to track you. So they will display the banner anyway, or perhaps a slightly modified version like "we noticed you have your DNT turned on, but are you willing to make an exception just for us?"
That gives them a chance users will consent anyway to get rid of the cookie banner. And they will argue that a specific consent given on their website overrides the generic non-consent represented by DNT.
Stop spouting nonsense. Enforcement is done by the DPA of the country where the company is located, hence why everyone is annoyed with how Ireland is handling Facebook but can't do anything about it.
How would you make it one-off?
In an ideal world, respecting DNT would instantly bin 95% of the cookies and data processing requests, but I'm still getting automatic (and permissionless) marketing subscriptions from companies when I make purchases, and the British ICO seems unwilling to intervene, so it seems unlikely that DNT being case law is going to have any quick effect on things.
Just put up a `Privacy` link for those actually conscious of the topic to give them details; you'd be doing both categories of users a solid tucking that info out of the way.
I use a lot of news aggregators, and never once got a link to a 451.
I think part of that is also that it's not foolproof to identify where a user is connecting from. Because I think legally, you can't use "but that user had an US IP address" as an excuse why you broke EU law against an EU citizen connecting from inside the EU.
Every single consumer protection has people show up on the side of the giant corporations. Usually a libertarian type with no clue how furious they would be if they got what they were asking for.
Isn’t quite the argument you think it is.
The Web makes it so that there is one server and lots of customers. It has to be hardened against SPAM, DDOS, etc. It pays all the costs. But also recoups them by tracking, it’s called surveillance capitalism.
Every site should have no idea how many people visited, actually. Just a bunch of static front-end content that gets passed around.
If people want to store their data, they can pay dumb pipes to store encrypted data.
Get rid of email too. Anyone who gets ahold of your email address can spam you. Instead people should pay for the dumb pipes to store messages, and you can give out capabilities for your attention. They can be transferable but if they are abused then you cut off the root of that tree. And you should charge for using them, too. Just cause someone has your public address doesn’t mean they can reach you.
In short, DNS and the Web and Email promote a certain dynamic where people invest in an upfront service and then take advantage of extreme power disparities forever, to recoup costs. And if they take on equity investors in a ponzi scheme until they IPO then they have more and more costs to recoup. There is no end to it. Wall street earnings depend on surveillance capitalism to continue.
This case revolves around (third party) tracking cookies.
The Dutch Data Protection Authority (AP) defines 2 cookies as follows:
“Cookies are small files that a website owner places on a visitor’s device. For example on a computer, laptop, smartphone or tablet. For example, the owner can collect or store information about the website visit or about (the device of) the visitor.
Bottom of form
There are 3 types of cookies:
- functional cookies;
- analytical cookies;
- tracking cookies.”
The AP says about tracking cookies 3 :
“If cookies can also be read when you visit another website, we call these tracking cookies. These cookies allow organizations to track people’s internet behavior over time.
Tracking cookies make it possible to draw up profiles of people ( profiling ) and treat them differently. Tracking cookies usually process personal data.
Personal interests can be derived from the information about visited websites. This allows organizations to, for example, show their website visitors targeted advertisements. (…) Do you process personal data of visitors to your website with tracking cookies? Then you must comply with the rules of the General Data Protection Regulation (GDPR).”
https://uitspraken-rechtspraak-nl.translate.goog/?_x_tr_sl=a...
(It's in dutch, translate at your own liberty, I'll give my own below + the stuff the authority for consumers and the market demands, which is linked from their page.)
Basically of the three cookie types, functional cookies require no consent whatsoever. A cookie to set up a user session (the page uses a shopping cart in a webshop as an example and the details mention things like saved passwords and language choices) is totally fine. The AP still recommends informing the users, but it's not required.
Analytical cookies are permissible insofar that they aren't used to profile the user. You're not required to ask for permission as long as they don't contain any uniquely identifying information. You are required to inform the visitor that you are placing these cookies though.
The final category are tracking cookies. These fall under the full scope of the GDPR; you must ask for consent before placing them, you must tell people how you are collecting their data (cookies, scripts or beacons are listed as examples) and you need to tell people what you do with them.
Pre-checking consent forms in general is expressly forbidden (on the same logic that you can't pre-check people into signing up for physical spam mail or paid subscriptions) and consent must be clearly stated, not hidden in some terms of services page or privacy statement.
Those are all requirements on top of the rights the GDPR (in Dutch called the AVG) grants consumers, although obviously most of this overlaps with the GDPR already.
Tracking is server side behavior.
3P cookies aren't a problem, per se. Using 3rd party cookies to join data with other server side data is the problem.
Who are you to speak for "most people". I do object to that kind of cookie being placed without my explicit consent. It provides at least some identifying information that might allow multiple websites working together to uniquely identify you.
The law judges intent as well as technology.
There are various techniques to place "cookies" (sometimes not technically cookies) that can be correlated by multiple websites working together, but the website has to go out of their way to proactively do that, this is not something that gets enabled by simply placing a standard non-personalized cookie.
It is arguably tracking required for the functioning of the site which is a clear exception to the ban.
GDPR threads on HN are always like this. Tons of people saying "no no it doesn't work that way it wouldn't be reasonable" and then when that thing ends up being ruled illegal, "of course it's illegal everyone knew that it's all very clear".
GDPR is written in such a way that you can't ever know what is or isn't allowed.