https://ec.europa.eu/commission/presscorner/detail/en/ip_24_...
"This site uses cookies to offer you a better browsing experience."
Which of course is total crap. There's no better experience, only a worse experience with the banner.
They seems to use this https://piwik.pro/, which as far as i read seems ok (i did not audit the code personally), i think this data might be legit useful for UX (im really shit a UX, you should ask people working on it though).
If you give companies an easy copy-and-paste way to get around a single regional law then they will do the quickest dumbest thing possible to get what they want no matter who the visitor is and where they're located.
The EU laws are poorly conceived, poorly written, and now we all have to live with them. They can make privacy laws, but they need to make them better.
I truly believe that the EU ruined the web for everyone with their haphazard legislation. And now they're trying to do it again with AI but thankfully they're just getting blocked now instead of everyone trying to comply.
https://ec.europa.eu/commission/presscorner/detail/en/ip_24_...
If that site needs a cookie banner I'm guessing nearly all sites do.
Exactly. And this doesn't surprise me.
The law states: if you collect more data than is strictly required for your site[1] to function and/or send user data to third parties, you have to:
- tell the users about it
- let the users to opt out, where opt out must be as easy as opt in
- if the users opt out, the site[1] must continue working
So yes, that site does send some extra data to third-parties, and informs the user about it. And lets the user know about it. IMO it shouldn't use third-party services, but oh well.
These days it's a source of my constant amazement that 8 years after its publication the people who complain about GDPR the most have not had even the tiniest attempt to read anything about it or understand anything about it.
[1] I simplified this to sites. GDPR is General Data Protection Regulation. All this equally applies to sites, apps, offline businesses, governments etc. To cookies, local storage, offline paper documents, tape records, cloud storage etc.
8 years. The law has been around for 8 years. It has been enforced for 6. It takes about half an hour to read the most relevant parts of it (chapters 1—5). An hour if you're not too familiar with legalese. And yet... "I don't know".
What is there to know? Nearly every website on the western internet has these cookie banners including the EU's own government sites.
The practical consequences of the laws are now apparent.
So what did we all miss that was hidden in the legalese?
Rarely do you see people flaunt their willful ignorance.
> Nearly every website on the western internet has these cookie banners
Well, since you approach is "I don't know and what is there to know", it's no surprise that the industry so easily sold you the lie of "the EU's laws are at fault"
> including the EU's own government sites.
Compare the banner on the site linked above and the usual dark patterns employed by the industry.
are you saying that the explosion of opt-in cookie banners on the web is not the result of the EU's privacy laws?
With AI what I saw in the news mostly made sense and did not hinder development too much. But again I would rather they regulate the use because it will have real negative consequences for many people if they don't
A lot of EU laws have also been bad. VATMOSS (especially with the very low initial limit to register) was initially a disaster. It actually deterred people from trading within the EU! The commission's attempt at chat surveillance was thrown out by the parliament, but they will try again. The new AI regulations look problematic. The draft I saw of the AI one was far too broad (included old tech like expert systems) - not checked recently whether it has changed. There are also issues with a lack of FOSS exemptions in the other current law (forgotten what it is called) imposing greater liability for faults in some categories of software.
I think it is important to acknowledge that many regulations are not perfect and I would push for more revisions on the details (although changes in the law also have a real cost associated) that don't hit their target.
last time I caught up on it, it was a very narrow exemption that was only of use to pure hobby projects.
Where would you find a lawmaker with an ounce of foresight?
Heck, the way the cookie protocol works the server already says ‘hey, may I store this cookie?’ by sending the Set-Cookie header. The user’s browser doesn’t have to do anything if he doesn’t want it to!
It is not a question of cookies per se. You can use localStorage and other techniques to track users without using cookies. But you still have to show the warning if you are tracking.
And there a plenty of legitimate uses of cookies.
I stopped using it because if you blocked websites from setting cookies, that meant the cookie consent banner showed on every page rather than the first you viewed because the cookie consent cookie had been blocked. That made blocking cookies entirely apart from whitelisted sites impossible.
Not every one is tech-savvy and that is why we have regulations.