If the law didn't intend for users to be inundated with notification banners and consent checkboxes it sure is odd how much time they spent about writing how anything but the most basic connection cookies require said things.
I'm not entirely sure that this is true. You can implement a "shopping cart" on your site, with a session cookie without needing to have a "cookie notification", so depending on circumstance I'd argue that settings might be allowed as well. Or you can just display the cookie information along with the settings it self, it doesn't actually need to be a popup.
"Or you can just display the cookie information along with the settings it self, it doesn't actually need to be a popup." this is true, you can put the information for each cookie in every place that the UI interacts with the cookie or you can put it in a dedicated popup or however else you can figure out to do it. So long as you notify and require (informed) interaction with the associated interaction you're good.
As far as I can see, this is a resource funded by the EU, so not quite authoritative, but good enough IMO. They say:
> To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must: Receive users’ consent before you use any cookies except strictly necessary cookies. [...]
This sounds like what you're saying, but this verbiage is based on a classification of cookies further above where a distinction is made:
> Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. [...] > > Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for [...]
So "strictly necessary" really only means "the site breaks without this", e.g. a session cookie set by a login page or the shopping cart example that the quoted article explicitly calls out, too. Presentational settings like display density, font size, dark/light mode and such seem to require consent.
3.6 UI customization cookies:
"These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case."
In particular, criterion A "functioning of the site" is a lot more narrow than your interpretation. It sounds like "oh, they need this to use the site's functions" but it really describes is functionality more like "you can't use the site at all without setting this cookie because you couldn't authenticate" and criterion B "for service explicitly requested" has more limitations (like lasting beyond session).
Yeah, I had to read the first version of "the cookie law". The intend was super clear, at least in the Danish version, it was pretty easy to implement and wouldn't really bother anyone... Then came the marketing/SEO/retargting assholes who had a nice thing going tracking the everlasting crap out of everyone and they did NOT want things to change. Some of these people then came up with the "hosted cookie banner" and things went to hell from there.
You are absolutely right that this should never in a million years be viewed as compliance. It mostly didn't, and still doesn't work. What should have happened is that the law should have been amended to prevent outsourcing responsibility.
If I own a store and you walk into my store am I required to forget that you came into my store?
Monday:
Bill: "Hey Jane (store owner), do you have any X45 hammers?"
Jane: "Sorry Bill, I'm out but might have some tomorrow"
Tuesday:
Bill "Did hammer come in I mentioned yesterday?"
Jane: "What hammer? Sorry I'm not allowed to remember anything about people in my shop because that would be spying so whatever you said to me yesterday has been deleted from my memory"
PS: I hate spying too. I'm just not sure how to design a law to prevent it that doesn't have unintended consequences.
These rules aren’t for your dream small business. It’s for a mega corp that would literally not care if you lived or died or if that hammer hit you on the head.
* Using Quickbooks Online? they market/sell that data.
* using ADT for payroll? They market/sell employee salary information.
* Using Ring for security? they freely share video with LEO
* etc, etc. All these services that SMB's use already have their fingers in the pie.
Second: You can have analytics AND be GDPR compliant without a cookie banner. There are even companies built around this: https://plausible.io/
The way to do this (both in ePrivacy and in GDPR, despite the different legal mechanisms they use) looks to be to write a phrase like “legitimate interest” into the main text, give illustrative examples of what that’s supposed to mean in the recitals before that, and let the courts figure out the details.
In the case of cookies, they simply apply to computers and not people. Why? It's not about whether the two are operationally similar it's about whether the two are practically similar. Until every shopkeep meticulously tracks every detail of every customer interaction and starts efficiently sharing them with others, all manually, often enough and at a large enough scale that it becomes a similar privacy concern it's not really worth fretting the law be generic enough to cover the use cases. In such a case it probably even makes sense to just write a separate law which meets the domain's needs more succinctly.
To hammer your point home even further, there's also the key point that in the digital world you also have entities like Meta that track you everywhere you go because they have their little tracker scripts running on almost every website.
To bring this back to the previous hypothetical, it's more like a single person following you around with a camera everywhere you go, which is already covered by existing laws.
In your instance, I would have put a backordered hammer in my cart. I come back the next day to check and see if the hammer is in stock. The cookie that enables cart behavior is necessary to the functioning of an online store. No consent needed.
In the real world, this basically means that tracking and marketing cookies are what you are being asked about. They don't need to ask about much else.
The EU has a very good write-up: https://gdpr.eu/cookies/
I think it would actually be very difficult to demonstrate that this tracker is absolutely required for the online store to function.
It doesn't seem to directly require comporting with someone's limited view of how a particular app is supposed to work
All store owners and employees should get whacked in the head every day.
Don't give them ideasCommon sense and consent. Laws are not theorems or malicious genies.
No. Your head is not covered by the GDPR. It requires you to not keep a record of all your clients' personal info without a legitimate interest.
There's a Seinfeld episode where Elaine goes to buy a fancy pen at a stationery store which isn't available atm. The clerk asks for her full name and number to notify her (that's a legitimate interest) but then uses it to hit on/stalk her (that would be a GDPR violation). Presumably he also doesn't get rid of the number after their business transaction.
2.) You are allowed to save 'consent=given/rejected' cookie depending on user choice.