There is no EU cookie banner law
bitecode.dev
bitecode.dev
- Forbid browsers from sending the DNT header automatically. They may ask the user. - Consider the DNT header valid consent or withdrawal of consent. - Forbid websites from asking for consent if the header is set.
Other than that yes this would be the solution.
I have seen sites just banning all the EU IPs, but I don't think that would work anymore, as California & India have similar laws. I am sure a bunch of other jurisdictions have it by now, as well.
The EU doesn’t have jurisdiction over American companies, there’s no way to enforce this. If your company has a European legal presence, that legal entity may see enforcement, but if you’re an American site operating under American jurisdiction, the EU cannot compel you to do anything. America is a sovereign nation that is not subject to EU laws.
And most sites don't just use one tracking network but they use many (see some of the convoluted cookie banners where you have to turn off data sharing with several hundred "partners")
You need to heavily asterisk this because this is not true in all cases.
The only way to explain it is mass hysteria. Someone did the banner first and everyone thinks that’s what you need to do to comply and everyone copied.
I don't think so. Most sites have teams big enough to know what they are doing, and they know this is the only way to "comply" while still being able to continue business as usual.
That must be why https://gdpr.eu has a cookie banner /s
I want to know what I need to implement in my software so that should I need to respond to a gdpr request, I can action it as required. Someone else can deal with third party notifications etc, but I want to know how to create a ‘nuke this user’ function, but I don’t even know what data a user can supply for identifying purposes (their name? email address? IP?) nor what data I must destroy (name? email? Ip?)
I have had to use gdpr to get data a few times now and while it’s amazing that we can so easily do that now 30 days is never enough because i can tell that the export is being done manually then converted to pdf. Which means my data is no longer inside the system its in bits and pieces in someone's (usually non technical) downloads/desktop folder which feels way less safe to me!