Ugh, please don't give them any ideas
So as long as you are collecting personal information, there is no legal difference whether you do it via cookies or another different mechanism.
I'm an external auditor. The GDPR is a cash grab.
Regulations that actually incentivize organizations toward stronger privacy and protection practices are designed more like HIPAA or PCI where the MAGNITUDE OF THE BREACH is the primary factor determining the monetary fines imposed (e.g.,number of records exposed, was it PII, PHI, etc.).
Taking 4% of the company's annual revenue from the previous year, irrespective of the size of the breach, results in a regulation about as effective as clicking those cookie consent boxes. "Oh thank goodness I gave my consent, I think now we can all rest easy that our data is being handled securely and appropriately!" No, the EU included the ticky tacky consent requirement to create major global visibility about itself so that when a company doing business with the EU has a breach, they won't be surprised when they then get an additional bill from the EU for not only having the breach, but now being in violation of the GDPR too.
The GDPR is a despicable joke. And my use of 'the' gives me the right to that opinion. If anyone else out there was involved in GDPR's creation or implementation, I think you would agree:
GDPR owns the Greatest Dung Pile Record, Grandma's Dildo Paste Replenisher, the Gagging Damaged Penis Rectum and one Gigabyte of Dick Punch Radiation in addition to €2.83 billion (as of 12/2022) collected from breached companies in 1,401 cases for "violating the GDPR".
The other option would be to have fixed fines that Google et al. pay out of their small change, while it absolutly would torch their small competition.
Sure, they could also jail CEOs for this. I would also be for that.
If a fine doesn't grow with the income it is a fee. So if you want a corporation to follow your law, it needs to come with a fine that motivates those in charge enough to follow it. Money is the soft option there.
It is totally possible to run websites in compliance with GDPR. I built multiple that require no consent whatsoever, because guess what: No personal data is collected, where it is not absolutely technically required.
For me as an EU citizen the GDPR turned my data-related communications with companies from essentially begging into the void, to actually getting a response.
The GDPR doesn't mandate fines of 4% regardless of the nature of the breach. That's the maximum size of the fine.
You should go ahead and actually read the text of the GDPR. Specifically, Article 83.
Paragraph 1 states that "the imposition of administrative fines [...] in respect of infringements of this Regulation [...] shall in each individual case be effective, proportionate and dissuasive".
Paragraph 2 lists eleven factors that the SAs have to have regard to when setting fines, and top of the list is "the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them".
Many folks assumed DNT is useless. Yet here we are comenting in a thread about a court that is making it legally enforceable.
How exactly do you legally enforce "each link must not be a unique UUID generated per-user or per-page-view"? Do you mandate how "generic" a link has to be, such that a visit to that link exposes less than a certain amount of information about that visit? What about things like order-specific links on a shopping website, that will naturally identify an account if all orders share the same namespace?
Simplified it says: if you collect personal information, you need to ask for consent. If someone doesn't consent they must not receive degraded service. Now there has been a ruling that the Do Not Track info users send you shall be honored by you (duh).
This is true regardless of how you technically do it. So UUID URLs are okay, storing which IP adresses shared an UUID link with which other IP without consent is not.
I think some in the IT world need to finally stop making excuses and stop coming up with new illegal ways of tracking users on a personal level. Just use the same creative energy for finding ways of pseudonymizing and anonymizing users (where possible — depending on what you are collecting deanonymization might always be possible).
The truth is, that we had some rulings on what is considered personal data and what isn't and IP adresses, even parts of them can be regarded as such. Now you and I might think this is silly etc., but if we write software for corporations that have to pay fines as a feaction of their total revenue not knowing that can easily ruin our lives.
And I am merely reflecting the way how these laws have been interpreted and ruled on so far in the comment section for an article on, well another ruling by a court. Legal reality, like physical reality doesn't go away if you close your eyes.
Is this what you originally meant?
Nontheless I hope you can see in which way the whole thing is still deeply connected to the legal question of how one can still learn about their service without tracking single users when they don't give their consent, maybe now even via DNT header.
That is personal information.
It does not matter how you collect that personal information, so whether you use cookies, pen and paper, the digital equivalent of a rube goldberg machine or UUIDs in the URLs — totally meaningless. As soon as you process the IP and use that information for any purpose not considered legitimate interest you are on the hook (and no: if you are in doubt it is not legitimate interest).
Many wrongly believe GDPR is about cookies. It is not. It is about the information and the consent. So whether you change the collection mechanism doesn't make any difference if you still collect the info. It just means you now have to update your consent banner to include that new way of data collection as well ; )
Let me give you a hint: Because they are required to do so by law (at least in the biggest free market on the planet). Now maybe you can figure out how that law is called and why it is relevant in a discussion where the topic is DNT and a German court ruling it needs to be honored.
We are not discussing whether tracking is technically possible — that would be a pretty short discussion: Yes it is possible. So we are talking about something else. And if we are not talking about the law, why did you even feel a need to come up with a way of circumventing it?
To summarize: we’re talking about technical solutions to linking sessions across independent devices. What’s your “short discussion” answer to that?
So when the headline says »German court prohibits Linkedin from ignoring DNT signals« the interesting point isn't what is technically ancient history, but what that new legal reality might mean in practise for those of us who build, maintain and run the things that are affected by said legal reality.
Or what more did you have to say than hint at one very obvious and noticable way to do tracking?
So from my perspective: No. I jumped into a particular thread that seemed to imply one could "get around" that particular legal issue with a technical fix, which is just false. You sure can do that but it will not make the legal risk go away, just because you are not using cookies.
Now of course you could again go and attack the messenger instead of telling us why a technological workaround for a legal issue has nothing to do with the legal issue inside the comment section on said legal issue. Now because all of this could just be one great misunderstanding I am going to assume you don't know that much on the legal side of the issue and my comments on "your" thread came across as aggressive which raised the heat unnecessarily and was not my intention.
"No cookie or localdb or browser fingerprinting is going to tell you whether someone looked at a site once on their home computer, again on their phone while commuting, and again on a work computer to show colleagues."
My intention was to provide a mechanism for solving this problem. GDPR or even Europe in general has nothing to do with it.
If you don't care, switch on DNT and never see those banners again (assuming this ruling preveils).
Scam: "a dishonest scheme; a fraud; a swindle"
I would argue, outside of our closest relationships, the majority of people are attempting to, or engaging in some kind of scamming behavior in at least half of their interactions.
At this point, 2023 worldwide, fear and distrust are table stakes for social interaction
But that the majority must still behave rightly paranoid that it is the majority in order to protect themselves from a really pretty small minority.
Yes well the whole point is to make things better - not just keep them the same
This relates to a piece of advice I gave my children: most people are fundamentally good and decent. A small percentage are not. The problem is that you can't tell which is which just by looking at them.
However it is unquestionable that the default mode for humans in America to operate is out of fear - and the opposite is by exception
Even in human interaction amongst your closest friends and family, they only interact with you for their own benefit - that just happens to be in pursuit of the endorphins/dopamine gained when they spend time with the people they share memories with, and it happens to be reciprocal.
Well, with exception of those which need to be shot with Hanlon's handgun[0]. There's surprisingly many of those, and not where people would suspect (e.g. I see it more often interacting with small businesses than with larger ones) - but in most interactions with others, I find it best to not reach for the handgun until it's clear it's needed.
--
[0] - "Never attribute to stupidity that which can be adequately explained by systemic incentives promoting malice." -- https://news.ycombinator.com/item?id=21691282
This is excellent advice for both metaphorical and literal handguns.
Large corporations where all human values are made illegal are quite shining examples how humans should operate in our system. This is sadly quite common in non-profits too.
I agree with this, but there are situations where because of obvious incentives you cannot make this assumption. Car salesman treating me like his best friend? I wonder why?
I think the numbers are way lower, but it is an old, archaic idea, you do good for your tribe/family - by taking from anywhere outside of the tribe. Stealing from the tribe is very bad and might get you killed. Stealing from another tribe however is not stealing, but reputable work, as long as there are no established friendly relations to that tribe. Many people indeed operate with this mindset (consciously or not)
But all in all I would rather say, that the number of people who consider all of humanity their family, is increasing.
This sentence shouldn’t be associated with anything “non-profit”
Proving yet again that, unless you structure your organization differently than every other capitalist thing (which means you won’t get funding through traditional sources) then you’re just helping capital further entrench their positions of power
You want to have some kind of impact, and you end up having to spending money to do that. You want the most impact and your funding is limited.
The STRUCTURE is wrong is the point.
The entire concept is built around would-be-aristocrats (Board) coercing the management and employees into allocating property (Money) based on their whim with no accountability or democratic function. It is built to exploit.
Instead they should organize as a non-stock cooperative so that is effectively impossible to exploit. That's the actual answer.
Maybe you can call it something else, but for a non-profit ROI is just answering the question "Are we spending our money wisely?
Or were you referring to the non-profit having a board?
Using concepts like ROI for non-profit operations is one of the signs how everything is made to emulate business.