Dear Paul Graham, there is no cookie banner law
amazingcto.com
amazingcto.com
Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the most annoying way possible, and promote the idea that the issue is not the extravagant fees, nor the fact that the companies hide them before and had to be forced by law to warn you about them, no the problem is a law that force them to tell you what you're getting into before it's too late !
That's, essentially, what's happening. And we have people complain that companies need to display their fees.
On this issue in the group that complain about the cookie law there are some people who are very wrong on purpose because it's in their interest, and some people who are very wrong because they genuinely don't understand the position they're defending, complaining about being made aware of the fee, instead of the fees themselves or the fact that the companies hide them if not forced by law.
To each their own belief about which category PG fits into.
Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.
Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as possible to make you have exactly the reaction you're having.
That being said, all the dark-pattern banners actually break the law. The problem, if anything, is lack of enforcement of the law.
The law is pretty crystal clear. In many cases the issue is that websites are outsourcing their tracking to ad companies, which in turn apply those banners indiscriminately because that's in their interest.
You think a small company should roll their own tracking software? A mom and pop website that wants to track its conversion rate on its little eCommerce site?Come on. Be realistic.
do you think the same thing about laws against murder?
about fraud?
This criminal uses murder! If you continue to interact, you consent to being murdered.
Murders you anyway
Laws are not borne in a perfect state; very much like programs, sometimes you need a few versions to see how the system actually works in practice and fix a few bugs. The fact that v1.0 has such bugs is not a good reason to just give up, nor it's an indication that the programmer is bad at programming.
All companies? Every single company with a website even if without any trackers or ads?! All companies are evil and the single law that triggered their evil behaviour is good. Sure. Ever heard of Occam's razor?
> All companies are evil
No, but many, many companies are sociopathic assholes that exist just to make a buck. Otherwise we wouldn't need these laws.
(Thanks for the site though, Paul)
it's also generally an indictment of the modern neoliberal regulatory approach in general. asking people nicely to follow train safety regulations etc isn't going to get you results. even fines/penalties largely end up just as cost-of-doing-business (even in the EU). if you really want behavior to go away, make it illegal and give people at the top Sarbanes-Oxley-style legal culpability if it happens on their watch.
again, if you want to know the right way to set incentives so that people don't do a thing, you need only look at the way rich people want their money handled. you can bet that ripping off rich people is an ultra-mega-crime and doesn't just get a 1%-of-the-takings slap on the wrist. And lo and behold SOX does actually hold important people accountable as a result, not just some fall guy at the bottom.
On your second point, that is again a choice of said companies, not a problem with the law. The GDPR has proven very well that if they cared, they can segment who is affected or not, and not just big tech lots of random local news site and the likes are doing it just fine.
So again, you're aiming at the wrong culprit.
Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.
Germany is a bit litigious w.r.t. internet or privacy, so the combination---cookie consent---is a doozy. Nearly every German website that does anything will have a consent notification, and the slightest misstep (e.g. using Google Fonts without asking permission) can be punishable.
Our US based legal team told us we needed a cookie banner if we were going to have visitors in the EU. I pushed back, but I lost, and ultimately it's not my fight.
It's a battle to get them onboard to not taking the safest possible approach, so you only want to fight that battle when it's a kingmaker of an opportunity.
you're right, I said third party, but I actually meant tracking. I actually went and checked, and our only cookie is the cookie for if you've seen the cookie banner or not...
> Consent may be required even if there are no cookies at all.
For what?
This actually makes sense - because if you didn't have the cookie banner then some fucking weirdo would come to Hacker News and make a self righteous post about how you're "tracking residents of the EU without their consent and abusing them" (even though you're not). Instant karma. Next thing you know these weirdos and their mob are reporting you to their government and you're dealing with government inquiries and more legal expenses trying to prove your cookie-less web 1.0 site doesn't "abuse people."
The banner placates them.
You may use "legitimate interest" cookies/tracking without saying so, but as soon as you show a privacy dialog you actually have to disclose everything you're doing including legitimate interest.
Basically by having a list of what youre're doing with your user's data you're giving up your right to do anything not listed.
GDPR actually doesn't specifically mention cookies at all. Tracking is what's illegal, not cookies.
Let's say you keep website logs with IPs on them, and you do analytics for non-essential purposes. You can do this under GDPR, but you must gain consent from the user before logging this PII.
It actually is completely and totally orthogonal to cookies. Some cookies are fine without consent. Some things that are not cookies are illegal without consent.
They probably won't tell you that, tho.
Managers and everyone else can have charts and graphs without retaining personal data.
The processing of personal data prior to anonymisation to turn it into aggregate data, that part needs protection. But you can do it in a variety of ways that don't require personally invasive tracking.
I live in Europe; I don't experience this "nightmare". Would you care to expand?
Now I am not saying the US doesn't have a problem. They just don't have GDPR and most website don't ask you for any permission to track you. So the experience is generally smoother (with the occasional tracking popup).
Ideally there should be a way for me to broadcast my willingness to share my data and not allow dark patterns to try to change my opinion. But the GDPR does not cover that and allows websites to drive you crazy until you click "YES, Track me"
This is not my experience. Perhaps the websites you favour are exceptionally abusive.
> a way for me to broadcast my willingness to share my data
That's the opposite of what most people want to broadcast.
> But the GDPR does not cover that and allows websites to drive you crazy
Apparently your view is that GDPR should not allow that, i.e. it isn't strict enough. I'm inclined to agree.
[0] https://community.mozilla.org/en/campaigns/firefox-cookie-ba...
The post is dated 2022. The feature became generally available in v120. Stable is v123, so it is available now. It's gated, so you still have to enable it as described in the post.
Source: Living in Europe
The reality is that I (and others who are complaining, as well as many who have resigned themselves to their fate) are happy to have a website "track me", certainly if the cost of non-tracking are having to click away an annoying popup, and think that people who compare a website wanting to know the number of their visitors to "hidden fees" are kind of being ridiculous.
The you should doubly blame the companies, because that's what do not track was for, they're the one who decided to make it not work that way and instead being ignored and not considered a valid option for the law.
> think that people who compare a website wanting to know the number of their visitors to "hidden fees" are kind of being ridiculous.
You don't need a cookie for that, and what GDPR has told us is that we're not talking of that but about dozens or hundreds on every major sites so trying to frame it that way is disingenuous.
A few of these cookie prompts during the day and they'd be able to tell everything from where your kids go to school to the kind of prn you prefer to watch on weekdays and everything in between.
This is how ad companies can sell premium views, don't show cosmetics to men, increase car related ads to people who has watched other car related ads and so on.
There's no such thing as server-side "private browsing".
It's really not. They already could do all that before cyberstalking was normalized. It's called content-based profiling, and it doesn't require any GDPR consent.
The example about "show more car ads to someone who watched other car ads"? It's not about showing car ad on a site whose content is about cars (or where the site owner decided they like that kind of thing).
It's about knowing you have wandered over to car comparison site recently so they can show you car advertisements when you look up sports news, show car-related merchandise when you're browsing some shopping site, show you insurance ads, etc.
And aside from that, I think it should be much more expensive to say sorry than ask for permission. In my world a firm like facebook should not have any right to exist, they earned it. Fine them to oblivion just like I would get a long time behind bars if I wouldn't do my taxes right.
Is this something that's kept secret in European society?
If someone told me they knew where my kids went to school I wouldn't be surprised, it's sort of dependent on our address which is in the phone book.
Is counting visitors all that sites are doing with tracking info?
They're not selling it to ad brokers, insurance companies, governments? They're not matching your name, address, and phone number with your web activity (including sexual interests, "anonymous" embarrassing stories, health concerns, etc)?
I agree that wanting to know the number of visitors is benign and it is not abuse.
But saying companies should be allowed to track me (for whatever purpose) across the web without my consent is also pretty ridiculous.
https://arstechnica.com/tech-policy/2021/07/facebook-adverti...
They have so many "partners" that their cookie popup comes with a search bar.
56 of their "partners" want my precise geolocation data!
16 "partners" want to actively scan my device!
101 "partners" want to "match and combine data from other data sources" (I can't disable or object to this)
102 "partners" want to identify my device. I also can't object to this.
The only way I can really object is to close the tab, so that's what I do.
Isn't it too late by then?
People should have a default expectation that if they give their personal data to companies then it will be recorded. And if they don't want cookies then they should disable cookies. The EU's regulation hasn't revealed anything that is useful to know about.
What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!"
Seemingly it is everyone's fault except the bad actors themselves.
I've seen this attitude from tech people, too, so it's not just a matter of tech ignorance or illiteracy.
It’s an inconvenience to people who care about privacy and use browser configurations that don’t store state between visits.
So now in an attempt to protect regular users, the law ended up hurting users that already cared.
Additionally, the shadiest and incompetent sites still just track people with no cookie banner. So the law doesn’t really provide protection against uncooperative parties, whereas privacy technology does.
Fair point about the banners mostly "hurting" users who care about privacy (but, really though- how much does it really "hurt" you? I'm "hurt" more by the fact that I have to fold laundry several days a week).
But, I take major issue with you saying that the LAW ended up hurting users. Companies are under no legal obligation to make those banners as obnoxious as they are or with so many dark patterns (I sometimes don't know if I'm even enabling or disabling tracking with the way they word it). That's squarely on the web site owners pulling that nonsense.
> Additionally, the shadiest and incompetent sites still just track people with no cookie banner. So the law doesn’t really provide protection against uncooperative parties, whereas privacy technology does.
I agree that the only/best way to protect yourself is via technology and not by relying on people obeying the law.
However, if this is also an argument against having the law, it's an incredibly weak one. You can apply that logic to argue that NO laws are effective. People still murder even though it's illegal- must be a bad law, no?
Actually every single lawyer we asked about implementing GDPR advised us to have one of those obnoxious banners. Because the law is so ambiguous and the penalties so high that is better to play it safe. And we have no ads nor tracking at all on our product website.
You can ignore your lawyer's advice if you want, but it's a bit like a lawyer office ignoring my data security and backup advice: assuming a huge amount of risk.
Frankly, I doubt the veracity of this anecdote. But even so, I'm willing to bet that the lawyers in this story did not tell you that the banners have to cover half the screen and have ambiguous wording to intentionally confuse visitors to your site. When I say "obnoxious banner" I'm not being redundant: not all banners or popovers are "obnoxious".
Or are you in the peanut gallery willing to believe that there is some conspiracy where all websites have suddenly decided to obliterate their user's UX when GDPR appeared just because they are evil?
I live in the EU and I can tell you: ALL banners/popups are obnoxious. They ALL get in my way when I want to do something entirely different. As a (non ad/user-tracking) business I would never afflict them on my users if I had a choice.
The productivity loss here in EU since the GDPR would be staggering - if there was much productivity to begin with, of course.
Some of these bad actors actors with annoying cookie banners:
this is not true. It's just that most people are powerless to fight against the dark pattern onslaught.
So yes, I do blame the government as I would be fine returning to the prior state.
Absolute dreams.
The biggest problem with online advertising is not tracking users. It's a lack of trust between advertisers and pretty much everyone else. If you're going to pay for an ad, you want to be sure it was seen by a real person. I'm not sure that's the concern any more because click-through is more important than "seeing" an ad. Regardless, the goals are to make sure it's easy for a given advertiser to get on many web sites, easy for a site to get ads, and also possible to prevent fraud since there will obviously be multiple parties involved.
I suspect tracking users was an offshoot of just verifying that users were real to prevent fraud in the ad world. Not saying any of it is OK, but it seems like the way to prevent tracking is to find a way to verify authenticity while also preserving privacy.
And that would be fine, as long as Swift was willing to pay for it. But the tracking and personalized ads thing was a numbers game; personalized ads have a higher conversion rate, thus are more valuable, thus we need data to personalize ads.
So now we have this situation where providers were trained to play the GDPR in such a way that they will never have a problem, no matter what they actually do with the data.
And consumers are pissed because they are made to sign things which essentially reduce their rights...
And if someone (like me) thinks the EU did a half-assed job there, the downvotes rain in.
But not as much as you might think. Consent under GDPR only applies to what you were informed of when you consented, and you're allowed to revoke consent (with prospective effect) at any time.
I call upon all German users of this website to write to their MPs! Obviously the German civil service is a bad actor! The German deep state is plotting to discredit our beloved eurocrats and must be shut down! Den Sumpf trockenlegen!
I understand the joke you're trying to make but you clearly don't understand the relation between germans and privacy/tracking regulation to think this makes sense.
And I only picked Germany, because it's one of the few EU countries where stuff like that is rigorously enforced. In the rest of the EU, everything unrelated to the common market and/or getting money from the EU is at best haphazardly enforced.
If you want to, check out france.fr, a website maintained by an agency of the French tourism ministry. (After disabling the 3 dozens of annoyance blocking extensions everyone must use nowadays, of course.) What do you see?
A giant cookie overlay. Égoutter le marais!
No such thing anymore, unfortunately.
Why do I need to be "consuming corporate propaganda" when I just hate that I need to dismiss banners on every news website, when I didn't have to before the regulation?
I don't care about being tracked. But now that all websites need to cover their asses in response to regulation, I'm forced to figure out which button I need to click on to read content, and these websites don't even appear to save my preferences whether I agree to be tracked or not.
Objectively, the outcome of this regulation is that my experience is worse. Are the companies bad actors? Sure! Sounds like the EU should account for companies' bad behavior instead of forcing the internet to be more annoying.
It's important to note that we didn't have to go through the banners after the law, either. We only had to go through them after website operators intentionally picked the most disruptive and annoying popup to serve us. We can blame them. They chose to add it when they could have legally not added anything at all.
It's like the situation described here: https://news.ycombinator.com/item?id=39742766
> The experience you describe is the fault of websites which chose to make things that way.
I don't disagree. But they were less annoying before. So make them go back to being less annoying.
> make them go back to being less annoying
That is a request between you and them (the websites), unless you're talking about legislating a banner-less opt-out, or maybe just willing to file a complaint against the website with a data protection authority, if the banner is already illegally annoying.
Websites have the right to annoy their users with cookie popups, with or without the GDPR (ironically , the GDPR actually has some protections here, websites simply break the law). Unfortunately, it seems many are choosing to exercise that right because they make money doing so.
Your right, the experience got worse.
But the underlying point is there two ways this could have gone. The GDPR simply mandated that if companies track you they have to get your informed consent. So one way it could have gone is companies didn't track anonymous users.
Notice this doesn't apply to non-anonymous users. By definition once you've logged in you've revealed who are and agreed to a far more onerous privacy statement. So one way companies could comply is just to make you log in to see some content (and track you that way), and not bug you otherwise.
But they didn't go that way. They insist on tracking you regardless. Perhaps you don't agree, but I find this even more annoying because I install tracking blocking extensions and that breaks some sites. To me the world would have been a much better place if they had just gone along with the intent of the damned law and not tracked people who are try to remain anonymous.
To be fair it's not so bad. Firefox dismisses the cookie banners for you [0], and I have extensions that block the worst of their effects. If you are using a browser from an ad company and are complaining about cookie banners (which almost to the man use a deceptive UI to encourage you to accept them all so the ads work better), then I don't have a lot of sympathy. Me rejecting as many cookies as I can then blocking their trackers the worst possible outcome for the web sites trying to garner some ad revenue of course, but shrug, the industry could have acted in good faith, and didn't.
[0] https://community.mozilla.org/en/campaigns/firefox-cookie-ba...
The proper way to have done this would have been to go to the W3C or WHATWG and proposed an extension to HTML for sites to define an opt-in manifest or something similar.
We're a pathetic lot.
The real nirvana, IMO, would be better sandboxing between sites.
At a time a solution appeared with "do not track", and we ended up with the industry making sure it was as toothless as possible, opt-in, and google pushing hard to control the browser market.
It is not about cookies.
Are you a lawyer? Are you willing to assume the liability I may incur if I follow your advice?
Cookies that do not require consent [...] or authentication cookies (when users authenticate themselves on your web site to log in in order to check online services such as their bank account).
"""
https://europa.eu/youreurope/business/dealing-with-customers...
If you are worried about GDPR, by far the safest is to just not collect personal information.
A few things not allowed under GDPR:
1. Analytics
2. Third-party resources like fonts or JS libraries
3. CDNs
4. DDOS protection services
And I am sure I am missing many more. I am not a lawyer, but I worked with a few.
What you can’t do is trick the client to download something from a third-party source which then spy on the customer.
The further we take this analogy, the more strained it becomes.
Yes, it's natural to use a cookie to track a session; this is a mechanism invented for that purpose. It's much less natural to share this tracking information with third parties, especially along with a record of your purchases or other interesting actions.
But ad revenue is much harder to obtain without targeting and thus tracking. And a lot of places depend mostly on ad revenue.
This is another case of "buy now, pay later" pattern, stretched to "take for free now, pay in loss of your privacy later". In a funny enough way, many people don't value the information they get on many ad-supported sites as highly as the marketers paying to grab their attention, so simply compensating by adding a subscription or one-time payment to go ad-free sometimes does not even work; the more generic / "doom-scrollalbe" the content is, the worse it works.
But I suppose that was just an example you picked to illustrate the industry's malicious compliance, and not the main point, in which case fair enough. :-)
If the total price of the website without the secret costs of tracking were presented upfront, it would be less of an issue.
There’s a law in California that says that businesses which have chemicals that might cause cancer on the premises need to let people know. That’s great but the levels they set turn out to be lower than what you can feasibly test for and as a result all properties pretty much just put up the signs that say “there might be chemicals here”. The warning is useless and annoying because of market forces which is another way of saying the law incentivized the behavior that occurred.
For data-harvesting companies users are like livestock, and nobody cares about livestock's opinion. It only matters how much value can be extracted from users, even if it's annoying, misleading, and relies on dark patterns.
I used to think this was just an education issue, that people just didn't understand the implications of privacy concerns on the web. But I no longer think this is the case. I think people do mostly understand, and just do not consider this a priority.
We have other more precise words to describe that action. I asked ChatGPT what those could be, here's its answer:
Q: What are some english words meaning "taking money away from people without their knowledge or explicit consent"?
ChatGPT: There are several words and phrases in English that convey the idea of taking money away from people without their knowledge or explicit consent:
Embezzlement: This refers to the act of dishonestly withholding assets for the purpose of theft. It often involves someone in a position of trust, such as an employee, misappropriating funds entrusted to them.
Misappropriation: Similar to embezzlement, misappropriation involves taking something (usually money) for one's own use without permission or legal right, often in a breach of trust.
Theft: Theft is the generic term for taking someone else's property without permission, including money.
Fraud: Fraud involves intentional deception for personal gain, which can include financial deception or stealing.
Swindling: This term implies deceitful behavior to cheat or defraud someone, often involving trickery or manipulation.
Skimming: Skimming refers to the illegal practice of taking cash "off the top" of the proceeds of a business or other source of income without recording it.
Extortion: While not always directly related to taking money without explicit consent, extortion involves obtaining money, property, or services from an individual or entity through coercion or threat.
Pilfering: Pilfering involves stealing small amounts or petty theft, often done stealthily or without detection.
Conning: This refers to the act of deceiving or tricking someone, often for financial gain, through manipulation or persuasion.
Clandestine withdrawals: This phrase specifically refers to taking money from someone's account without their knowledge or consent, typically in a secretive or unauthorized manner.Why not a real regulation then to get rid of hidden fees and heavy fines/jail time for companies that are found to be doing it?
PG's argument (I hope) is that there is no point in talking about "regulation" and "customer protection" if companies STILL get away with their ridiculous and hostile practices.
There is no customer benefit in having user data collection and tracking. Companies do it only to exploit you. Even the usual BS excuses ("oh, we need user data to customize the experience") could be done completely in-device.
I don't want regulatory bodies to just give more hoops for other companies to jump. They will jump it anyway, because it is profitable to do so. What I want is for regulatory bodies to effectively stop predatory practices.
What I think we are missing is a browser option/API that lets the user choose the acceptable tracking level. Similar to the do not track header but more fine grained.
As we are missing that, extensions are doing a good job ATM
https://chromewebstore.google.com/detail/consent-o-matic/mdj...
https://addons.mozilla.org/ro/firefox/addon/consent-o-matic/
I found pretty late about Consent-o matic and it saved me a ton of time handling banners. It's exactly what we should have built-in the browser.
- it's not really a user choice when some browsers set it by default and therefore ignore it
- it's set globally for a browser but a user might want to give away their privacy to my specific site
... and show the banner anyway
Imagine you walk into a restaurant and they hand you a paper that details full allergy information for all of the foods they serve, and then they wait for you to say, "I consent to these ingredients being in the food," before they can seat you. I think that's a closer analogy. We can all agree that the restaurant shouldn't hide that information from you, and that some minority of people might want the information, but do we really have to add this inconvenient step to the process for all people? The current real-world system, where allergy information is available upon request, was working fine.
There are some things that everyone cares about and would be appalled by, that businesses should have to inform people about, and many things that a small minority of people care about. Why stop at cookies? Maybe we should mandate a popup if the website's server infrastructure was manufactured abroad, and another popup if the company that runs the website has higher than average carbon emissions, and another popup if the food in the food court that serves the headquarters of the company that runs the website is not kosher. The lobby of people who care about cookies is of similar size to the lobby of people who care deeply about binary size and about running JavaScript. Should there be mandatory popups to execute JavaScript? If the website is >10MB, should I have to consent on a lightweight page before downloading it? How do you determine which activities warrant a popup warning and which do not?
KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law.
Instead, you have to interpret his complaint with the lens of game theory. I.e. The Law of Unintended Consequences that takes into account what companies actually do in response to laws instead of what we hope they will do.
Your blog post focused on good intentions of the law. PG's tweet focused on actual outcome.
Unfortunately a non-negligible number of people in tech also have libertarian leanings, with a default “gubmint bad!” position, which makes them easy prey for adtech propaganda.
Why is this unfortunate? Because you don't agree with us? The "they would agree with me if they were smarter" trope is tired and gets us nowhere.
GP answered your question, for some reason you decided to cut the quote right before the answer. Here is the part that is missing from your quote which answers your question: '[...]with a default “gubmint bad!” position'
> The "they would agree with me if they were smarter" trope is tired and gets us nowhere.
I say that’s unfortunate
Personally, I find it very very strange that many of the people who call for regulation as a remedy to perverse incentives manifest in commercial markets seem unwilling to recognize the existence of even more perverse incentives in the political realm. If people seeking profit sometimes do bad things to get it, why would people seeking political power be expected to behave differently?
Bad laws boost libertarianism.
At least until you realise what they're doing, then you think they're skeevy corporate toadies with no morals.
Good regulation is regulation that has good outcomes. If a law has bad outcomes it is a bad law. You can separately complain about what companies are doing but that doesn't change the fact that it's a bad law.
It is of course debatable whether GDPR as a whole has bad outcomes, but if we're talking about cookie banners in isolation then it certainly does.
You don't seem to explain what the role of corporations is or what a good corporation looks like. If these things are not symmetric, you need to finish your explanation of why or how they aren't.
Corporations and the whole of property rights only exist because of government protection, so it would be pretty audacious--in my opinion--to assert that corporations have no duty to behave to the benefit of society. I'm not saying that's your claim, but I'm curious as to how close you're willing to get to that claim...
In my opinion it is not audacious at all to reject the idea that corporations should intentionally pursue societal goals or claim to act out of a sense of duty.
Of course we want the effect of what corporations do to be of net benefit to society as a whole. But this cannot be based on their intentions or sense of duty. It has to be based on the systemic effects of them pursuing their own (possibly enlightened) self interest within the framework of the law.
It is for governments to make sure that these effects are beneficial and to intervene when they are not. So the asymmetry I see is that capitalism is a tool of society, not the other way around.
I still find it somewhat silly to reject the idea that a corporation (run by human beings) shouldn't intentionally be evil for the sake of maximizing profit, but I do understand that this is a fairly common Friedman-esque point of view.
But, even so, I guess "duty" was the wrong word for me to use. I more meant that if a corporation does NOT benefit society, we should expect the corporation to stop existing. So, in that sense, there's a "duty" (existential requirement) to benefit society.
> Of course we want the effect of what corporations do to be of net benefit to society as a whole. But this cannot be based on their intentions or sense of duty. It has to be based on the systemic effects of them pursuing their own (possibly enlightened) self interest within the framework of the law. > > It is for governments to make sure that these effects are beneficial and to intervene when they are not. So the asymmetry I see is that capitalism is a tool of society, not the other way around.
I feel like you're circling back around to almost disagree with yourself. Several comments back in this thread someone made a point about "unintended consequences" of the law and applying "game theory" logic to it, and another commenter replied that the companies in question could also have seen the law coming if they misbehaved too badly. That commenter asked if the "game theory" logic shouldn't go both ways, and that we should then blame the corporations for the regulation because the government is just doing what governments do.
You replied that the argument does NOT go both ways because the roles of government and corporations are not symmetric.
But, what you're arguing here seems to be consistent with the view that the "unintended consequences" and "game theory" logic DOES go both ways. You acknowledge that it is a government's duty to intervene when corporations are not benefiting society, and you also say that corporations will pursue their own self-interest within the framework of the law.
I don't mean to put words in your mouth, but the only way I can resolve this asymmetry in my mind is to have a framework where corporations doing things that are bad for society is okay, because the government is supposed to stop them; but if the government is unable to fully stop them from being bad, then it's STILL not the corporation's fault, but the government's...
It just sounds like we've gotten lost in the abstractions of corporations and governments. At the end of the day, these are decisions being made by fellow sentient human beings, and if a corporation's humans make some evil decision, I refuse to let them off the hook with "well, free markets" and "they have no choice but to maximize profits".
On a very general level, the idea is that not every part of a complex system has to incorporate all the principles of the system as a whole. Individual parts of the system can have limited roles and responsibilities. That's fine and it has nothing to do with being evil.
Defense lawyers must defend their clients to the best of their ability whatever horrible things they may have done. Juries, judges, prosecutors, they all have their specific roles to play.
It's the justice system as a whole that should result in justice being done. If everyone involved tried to pursue their own interpretation of generally desirable societal outcomes, the justice system would be unfit for purpose.
And here's the asymmetry again. Those designing the system as a whole have to think about societal outcomes as part of their job (as does every citizen). Those acting in a specific defined role as part of the system can only do that in limited ways or under exceptional circumstances.
Corporations are run by people, but these people act in a limited role that is defined in such a way that pursuing specific societal outcomes does not necessarily boost the likelihood of their personal success or the success of the corporations they run.
If there is a conflict between certain societal outcomes and making a profit then those executives willing to prioritise profits will be the ones running the successful corporations. That's why it's so futile to bet on corporations acting against their self-interest in significant ways. They are systemically incapable of doing that (on average - exceptions are always possible).
That's why I'm saying that if we want to make corporations act in desirable ways, we have to make laws rather than appealing to the conscience of those running the corporations.
>I don't mean to put words in your mouth, but the only way I can resolve this asymmetry in my mind is to have a framework where corporations doing things that are bad for society is okay, because the government is supposed to stop them; but if the government is unable to fully stop them from being bad, then it's STILL not the corporation's fault, but the government's...
The question I'm asking is who can fix a particular issue, and if the issue isn't getting fixed then I'm assigning blame to those whose job it is to fix it.
Corporations collectively can't fix an issue when the only fix is not exploiting a particular economic opportunity. If one corporation stops exploiting the opportunity, another one will.
That said, of course I do blame corporations for stuff all the time. There's nothing wrong with that. Blaming them is sometimes effective consumer power. It can take away the economic opportunity as the reputational damage may outweight the benefits. Blame can also help build momentum for a change in the law.
But if laws are made and they have giant loopholes in them, then I blame lawmakers for doing a shoddy job.
The main problem with GDPR is the scale of non-compliance greatly exceeds the size of any reasonable enforcement capacity, at least until enforcement catches up.
It's more morally permissible for corporate decision makers to install a global surveillance complex than for civil servants to attempt to regulate it.
No, it's more transparent. Unlike cookie banners.
If only cookie banners protected the consumer, but shadow cookies work fine.
I don't know if this mini-competition between regulators and companies is truly zero-sum, there could be some way to get everyone something they want. But with the current regulation, it is zero-sum, and the companies are winning and the EU is losing. And the EU "works for you", so of course you can complain to them.
That's an overstatement of the purpose of the regulation IMO. The purpose is to give the user control over the tracking of their data.
* Transparency
* Accountability
* Proportionality
* Consistency
* Targeting
I'm not certain that the GDPR laws fail any of these. I'm guessing pg is getting at something more nebulous to do with how annoying the UX is as a result of the regulation, and whether it encourages civil engagement. But if he'd simply said "EU regulation has made UX annoying" then he wouldn't have such a snappy tweet.
[0] https://www.icaew.com/technical/trust-and-ethics/better-regu...
EDIT I googled some more and found a brochure from the National Audit Office titled "Principles of Effective Regulation": https://www.nao.org.uk/wp-content/uploads/2021/05/Principles...
It does have a statement in there:
> Good regulation maximises the benefits while minimising compliance costs and unintended consequences. The benefits of regulation can be both to wider society (such as improved environmental or safety standards) and to regulated (for example, through increased consumer confidence), but not all of the benefits are necessarily easy to quantify.
Put that way, I can get on board with what pg's saying.
The actual outcome is that they do want to track, and use adversarial patterns and malicious compliance to twist your arm and "force consent."
Paul Graham is still wrong.
No, you've inadvertently stated a contradiction. Your use of the word _"could"_ is literally a hope/wish/intention of the law.
In contrast, the actual outcome is that the companies didn't stop tracking. We _wish_ they would stop tracking. (I.e. "The companies _could_ just stop tracking us!") But that hope still doesn't change the observation of reality.
If companies act maliciously to contort around the law and force users back to making uninformed choices, it is the companies' fault and not the law's. Companies could have followed the interpretation of the law unobstrusively. But they didn't.
Invoking "reality," semanticking a position, do not make Graham's position justified. Neither does it make the blog wrong.
I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences?
The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.
- no fines for non-compliance (or malicious compliance)
- no legal liability for data leaks of PPI
When businesses believe (correctly or incorrectly) that the benefit of tracking outweighs the cost (annoying users, regulatory noncompliance) they will do it. The fix is to make tracking too costly for businesses.
"The Biggest GDPR Fines of 2023"
1. Meta – €1.2 billion (Ireland)
2. Meta – €390 million (Ireland)
3. TikTok – €345 million (Ireland)
4. Criteo – €40 million (France)
5. TikTok – €14.5 million (UK)
6. Axpo Italia Spa – €10 million (Italy)
7. Tim S.p.A. – €7.6 million (Italy)
8. WhatsApp – €5.5 million (Ireland)
9. EOS Matrix – €5.5 million (Croatia)
10. Clearview AI – €5.2 million (France)
"GDPR fines are designed to make non-compliance around data security a costly mistake and they can be separated into two tiers. Less severe infringements can result in a fine of €10 million or 2% of a firm’s annual revenue from the preceding financial year, depending on which amount is higher. More serious violations can result in a fine of up to €20 million or 4% of a firm’s annual revenue from the preceding year, depending on what is higher."
You just copy-pasted a list of GDPR fines.
see: "8 companies that faced cookie consent fines"
https://www.cookieyes.com/blog/cookie-consent-fines/
"In January 2023, France’s data protection watchdog, CNIL, fined TikTok €5 million ($5.4 million) for making it difficult to refuse cookies on its website. The CNIL found that TikTok manipulated consent by discouraging users from rejecting cookies. They required multiple clicks to refuse cookies, but only one click to accept them. TikTok resolved the issue by adding a “Refuse all” button to its site."
This would have a different issue, specifically companies would no longer self-report data breaches, but it's just an idea. There are alternative approaches to getting to "don't track people without consent" that aren't a toothless stick by making it more expensive to track.
... the main cost at the moment. I think we as a society are very close to a tracking/data tax.
An idea could be that the tracking has to be opt-in AND the webpage cannot stop critical use of the page as part of the opt-in process.
Then another round of consequences.. rinse repeat...
Why would anyone opt-in? Tracking provides zero benefits to the site visitor.
Drop the consent requirement? I.e. just don't track people. No third-party cookies, first-party only, and only for the correct operation of the site.
It's not the cookies that people object to, it's the tracking. Tracking provides no benefits to visitors. If there were no tracking risk, there would be no need to require consent.
Sure it does. Visitors get to use all those great sites and apps without paying for the services directly.
I have yet to see any kind of meaningful study showing that tracking improves the ROI on advertising by anything remotely resembling enough to justify it.
Don't ask users what they want. Let me, denton-scratch, decide for all of them. Wow, what a brilliant idea!
That X button is right there at the top near the tab name. Not sure how a user could be forced against their will into staying on the site presenting them with a cookie banner.
Could we really have predicted from the "Law of Unintended Consequences" that companies would respond not by tracking less nor by giving people an easy way to opt out, but with a cookie consent popup that is not compliant and also really annoying to their visitors?
This is better explained by business operators being ignorant of the actual law and being ignorant of the UX impact.
Is there still tracking? Sure. But it's not so blatant anymore. There are hoops one needs to jump through. And that was the point - to make tracking a harder.
None of my projects have cookie banners. Why? Because I use a first party tracking system (Matomo), I anonymize all visits and I respect DNT. It's that easy.
It’s a combination of two things:
1) the law comes to the rest of the world from Europe. We (rest of the world) didn’t vote in the people who brought it. We’ve had quite enough of Europeans making rules for the rest of the world in the past few centuries thank you very much.
2) GDPR encodes an expectation that may or may not be common in the EU, but certainly isn’t common elsewhere. I don’t have any expectation of privacy when I walk in public or when I give any information at all to a business. My solution to this is: a) I wear pants outside, and b) I don’t give out private information. Whether the business ecosystem knows their age and purchasing patterns is largely immaterial to virtually everyone I’ve ever met.
And don’t show me a survey showing people don’t like it - if you prime people with the question, of course they will respond that way. They know their info is being gathered, and they just don’t think it’s as big a deal as GDPR would like it to be.
Now, point (2) is, unfortunately, in the same vein as smoking, pollution, seat belts etc. Uninformed people (uninformed because they have better things to do) are not protected from their lack of knowledge. They suffer the consequences just the same.
And while I agree that and informed person, making a self-destructive choice has (in most cases) the right to do so, there is something to be said about the very, very powerful exploiting the uninformed. And this is where GDPR comes into play. It's protecting normal people, from a very, very big threat, that is not that obvious and is being wielded by the powerful.
GDPR is one of those laws restraining western corporations from going full dystopian future on us all. I said restraining, to be honest, I think it's just slowing them down.
And as far as surveys go - it used to be the same here. Europeans didn't care and said exactly the same things (i.e. the famous "i didn't do anything wrong, so I have nothing to hide") and then activists worked for years to educate them that, at the very least, it's leading them to buy things at higher prices. Now most people are extremely sensitive to their data.
But different societies prefer a different balance here.
Americans are used to a more caveat emptor situation. Europeans want more regulation. Which one to choose is a political choice.
What's happening is that the political choice that the EU went with is being forced on the rest of us, whether we like it or not.
I'm personally glad someone is doing something for my privacy here. My own government, due to regulatory capture, is unlikely to act in my best interests here.
Because the EU is forcing you to do something that you want to do anyway, you now like it?
If you want cookie banner laws in your non-EU country, vote for it.
I don’t want some bureacrat I didn’t vote for issuing diktats that affect how I build my business and my websites.
The entire point is that we all need representatives in government.
The article elaborates on this point: There Is No Cookie Banner Law. Only bad website operators choosing to abuse their users with annoying consent dialogs.
Nobody in Europe is issuing "diktats", meaning citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data. Just don't process EU citizen data and it's not an issue. Better yet, just don't track users.
In any case, your disagreement only serves to underscore that you were speaking on behalf of 1 person, not any country or countries. Otherwise, we wouldn't be disagreeing!
What I object to strenuously is someone dictating terms to the world from distant shores, especially since they seem not to get how the internet works (it’s all funded by ads, online sales, and ads for online sales, all of which involve metrics and tracking!)
The diktats I mentioned include a ruling that Google Fonts are illegal now. So if I’m using those, or I’m using Google Analytics, and a European happens across my site, I’m now a criminal? Fuck that.
The consequences of contravening the GDPR are uncertain but sounds scary. This is terrible for the open and free internet.
To the point: Nobody in Europe is "dictating terms to the world", or "issuing diktats", meaning passing citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data.
> The diktats I mentioned include a ruling that Google Fonts are illegal now. So if I’m using those, or I’m using Google Analytics, and a European happens across my site, I’m now a criminal?
No, because website operators have at least 4 more options:
1. Don't process EU citizen data (block them).
2. Don't track users, period (host the font on the site instead).
3. Don't track users until they log in (convert them).
4. Get users' informed consent (let them know that they'll be tracked on the site due to the choice of google fonts instead of hosting a font).
Wow, that wasn't scary at all! The general attitude I'm getting from some folks, though, is that they want to do anything they want to users without consequence and never change. This attitude is going lead to a lot of anguish. Others have rights, too, and they override our right to do whatever we want to them, in many cases.
> 1. Don't process EU citizen data (block them).
Many webmasters have neither the time nor inclination to read up on EU law. So blocking is the easiest and safest solution to minimize our legal risks. This is absolutely terrible - I grew up dreaming of an internet that is really humanity's network; not islands separated by political allegiance.
I agree that I can tone it down, but 99.99% of the FUD around is directly the fault of the EU for not making it crystal clear what the theory and practice around their internet laws will be.
Did website operators think they could keep violating the rights of EU citizens indefinitely? I mean, based on enforcement capacity, chances are most operators can, but it'd be good to stop. IMO, A network for humanity should prioritize humans and their rights, over tracking and ads, and the lack of respect for those rights is what I find terrible.
Real talk: if you have questions about the GDPR, ask them, and I'm sure the smart folks at HN will be able to help you find answers and overcome obstacles. You can build and not break laws, whether GDPR or ITAR, we can help. Nobody's saying it'll be zero work, but nobody's entitled to run a business doing whatever it wants with zero work, either, and shouldn't expect to.
The EU and the US and China disagree about what user rights are and what reasonable behaviour for a website is.
If one of those parties enforces their vision onto their traffic, it has a chilling effect - splittig the net into federations. By making GDPR super vague, the EU just makes everything worse, including for Europeans. If you disagree that the rules are vague, I'll refer you to the rest of this thread. Nobody knows what's being enforced or what the penalties are.
Real talk though, again: you say you personally feel the GDPR is vague. If you have questions about the GDPR, ask them, and I'm sure smart folks at HN will be able to help you find answers and overcome obstacles. You can build and not break laws, whether GDPR or ITAR, we can help. If you have troubles building, share them with us, let us advise you. Nobody's saying it'll be zero work, but nobody's entitled to run a business doing whatever it wants with zero work, either, and shouldn't expect to.
Really, PG's tweet has little to do with game theory or anything else. It is a first-world-problem whinge about having to click through cookie banners. Assessing the "actual outcome" of complex regulation and legislation is a task beyond the scope of a single tweet.
It might be useful for Graham to determine what claim he is trying to make in the first place. Is he rebutting a particular EU representative for boasting about how good they are at regulation? Or is the idea that the EU shouldn't have the audacity to attempt to regulate in the first place?
Government can, and should, analyze likely (or unlikely) unintended consequences and use those to further shape the law, but at the end of the day, those consequences come from choices that people who are subject to the law make.
I think the big mistake the EU made is they probably thought: “Surely no company would choose to abuse their customers with horrible UI just because they don’t like the law and want to take their collective frustration out on their users!” The EU was obviously wrong about the extent to which companies would throw their users under the bus while maliciously complying.
Which is basically the case here. Almost all websites make money through ads, or at least keep logs of user activity to help them optimize their website, and that's not going to change, so the EU's boneheaded regulations make the customers suffer a little extra.
most sites using tracking are providing you something for no monetary cost to you, instead by showing you targeted ads
Welcome to my new insurance company! Thanks for requesting a quote (it's free! the quote, not the insurance), my agent will swing by to install a GPS chip while you sleep. We're not doing anything malicious with it, we just give you call whenever you're within 5 miles of one of our locations. We'll put it in the bin the vehicle manufacturer conveniently installed for us to hold all the trackers grocery stores and shopping malls use to offer free parking, which you can of course empty out at any time (it's clearly labeled once you remove the oil pan).
What's this, a shopping center now asks before installing a GPS chip on my car (but still somehow offers free parking if I decline)? How inconvenient!
The EU regulation does not prevent ads from being shown, it specifically targets tracking. No tracking > no banner > everyone is happier > go ahead and show all the ads that are required.
The incentives are on both sides to to one-up each other without tracking - hosts by inflating visitor numbers, advertisers by disputing that.
In a perfect world ad(wouldn't exist i know but bear with that) companies would pay X/month for site with Y visitors, where X depends on Y. No need for tracking, and roughly over multiple sites and multiple months it averages out.
Not enough conversion rates(risk for ad company - they could pay less)? offer lower rate per visitor next period. Site gets spike in visitors(risk for host - they could charge more)? report higher estimated Y for next period.
What we got instead is an insane tracking infrastructure that costs way more than any possible profit gained for both sides. It's not even profit - it's avoiding being 'scammed', avoiding risk.
Remember that all that tracking bullshit started before targeted advertising was mainstream and widespread. It all started with bots and inflated click numbers, and inability to accept risk.
Tl;dr banning targeted advertising won't remove all tracking bullshit
I'll take regulated market over unregulated one though.
it's much simpler for both sides, no crying about bots, etc.
of course it's not great if you want to target Putin et al. ( https://www.wired.com/story/how-pentagon-learned-targeted-ad... )
ad networks can simply send out banners to sites for time slots, and that's it. do you want to advertise healthy food? send it to yoga sites (insert it on #yoga hashtag profile pages, insert it after videos/snaps/tiktoks/reels that the AI categorized as yoga, etc.) ... it's called item-to-item recommendation (use the content of the page - as it was done for - again - decades)
it's perfectly possible to ban and remove tracking bullshit
your solution here just makes ads less valuable, which isn’t a win for advertisers or sites. if you can remove tracking, and still allow targeting, then you’ve hit gold. short of that you won’t find meaningful buy-in.
After all the current implicit user profiling and targeting is already not a 100%. Many people use adblockers, many devices are used by more than one user, etc. (In this day and age we are still baffled how Amazon/Google/whatever advertises us - for days - the same fucking thing we just purchased yesterday. Of course, because based on their model it's still the most likely thing the user might buy or click on, etc.)
Google seems to be already moving away from individual profiles with FLoC - of course they still want all of the data to be able do dynamically allocate users to cohorts (to maximize their profits).
And this is why Tiktok and Instagram just went ahead and are now doing direct sales. (They put a link on the video overlay where the user can go and buy whatever shit the video talks about.)
> isn’t a win for [...] sites
this is something that a lot of people are pushing back on, because their claim is that we need some slack in the system for sites to be able to pursue their own creative vision (however lame, banal, mundane, or seemingly useless it is). before every click was tracked it was okay if some article (or video) underperformed, because in general the advertiser got the increased sales (or brand awareness or whatever they measured)
Many of us are old enough to remember untargeted ads, and pretty much all anybody saw at the time as an ad for cialis/viagra. 14 year old girls, 25 year old men, it didn’t matter, clearly you’re in the market for ED meds. this is a regression and i’ll take anonymized profile data over seeing completely irrelevant ads.
One thing that stood out to me from your post is this
> Many people use adblockers, many devices are used by more than one user, etc.
adblockers see no where near the adoption you seem to think, as it’s not many users, it’s a very small minority. and most users in fact have their own device and have for some years now. you seem to be detached from reality.
exactly. let the user decide. that's why it's out to be opt-in/out.
> you seem to be detached from reality.
I'm simply stating factors that are not insignificant compared to the difference we are talking about.
the policy discussion starts with cost-benefit analysis of "implicit profile-based ads" vs "alternative ads", and I'm simply stating that there are already many factors that ad networks consider.
FB/Meta rolled out Advantage+, which is a machine-learning-based full campaign optimization system. (The advertiser uploads many banners, and Meta tries all of them for various target groups, and learns which one to show for which users.) ... and it did all this because of Apple's ATT (app tracking transparency)
It sounds like that's a natural outcome of the point of the law in the first place: people felt that, for too long, tracking has extracted too much value from them without their consent.
Whether a website "buys in" to complying with the law is of course a risk analysis they can conduct for themselves. Neither advertisers nor sites are entitled to a "win" here.
I could ask permission and delay, or I could just capture the data and run experiments or A/B testing. You should also learn that nobody knows everything, and saying something isn’t required usually is just showing your own ignorance as in almost every case you’ll come across you will find at least one valid use.
What are you learning from users' personal data that changes how you do this? Shouldn't your site be accessible, regardless of usage?
> We are also committing that going forward, we will only use cookies that are required for us to serve GitHub.com.
A few pixels further down, on the cookie banner:
> We use optional cookies to improve your experience on our websites and to display personalized advertising based on your online activity.
I guess now we finally have a rule-of-thumb figure for what "going forward" means: 3-4 years, tops.
Doesn't require tracking of individuals.
> or at least keep logs of user activity to help them optimize their website
Doesn't require tracking of individuals.
If I order something from an online shop, they don't need to have a banner in order to take my name and address to post the item to me - that's fully expected and reasonable. They do need my consent if they want to use that to post adverts to me though.
Only if you maintain your own ad inventory, instead of using Google/Facebook ads like 90% of online advertisers do. And neither of those platforms work without installing their scripts on your site.
After all, Google and Facebook still show ads if a user doesn't consent right?
I bet they'd add that option in a heartbeat if people would leave them otherwise.
The scale of this kind of thing is ridiculous. Opening a basic news site and I'm asked to consent to my data being taken and used by 750 companies.
Building a house doesn't require powertools, but if your company tries to do it with handtools we'll see who goes bankrupt first.
Analogies can be pithy but are rarely useful as an argument. Talk about reality.
I am sure the construction sector is overflowing with grumpy people who feel like aspestos is the best form for isolation.
How dare they!
</sarcasm>
Just because you made money of it, it doesn't mean it is right.
The principle seems sound, but the EU is deadlocked over reforms to create some extra exemptions, e.g. for security scans/mandatory updates, or privacy-respecting audience metrics. EU regulators are already sort of turning a blind eye to those, so it's fair to say the EU isn't great at regulating - it's not fixing what society mostly seems to see as bugs/overreach in the original (now decades-old) law.
[0] https://en.wikipedia.org/wiki/Do_Not_Track
[1] https://dig.watch/updates/german-court-affirms-legal-signifi...
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A...
And the GDPR's subsequent entry into force created the current emphasis on how actively (and individually) you need to consent to things, and how much you have to be told about them first. Stuff like "clicking anywhere on this site, tells us you consent" was a lot more common, pre-GDPR
So it is a responsibility of the browser vendor to implement this.
The Cookie banners aren't from the browser they're really from the site.
That said, it seems fair to require the browser vendor to implement it. The browser is the one that exposes a method to store data on the machine (ex. Cookies, LocalStorage) so it seems fair that they should know the user wanted data to be stored.
In the end we are better off with this legislation and its future iterations and additions than we are without it. The extent to which people's data is misused is simply ridiculous.
'Meddling' causing citizens to lose visibility and corporations to gain more power over data?
Correction: people should not be able to escape responsibility by saying this.
The problem is that right now people do escape responsibility for saying this because the EU is not properly enforcing these new laws.
Introducing a law and then not enforcing it has consequences, and those consequences should have been foreseen. Either the law is unenforceable due to practical constraints, in which case it's a bad law, or the EU is failing to enforce it due to inability.
Hopefully the EU starts putting more focus on enforcing its existing laws rather than creating new ones.
You have to admit that if these same people can't be trusted to follow a simple "do not track" directive, humanity is in big trouble.
But I don't think it's that developers "can't" follow a DNT cookie. It's that they won't because it doesn't benefit their employer's financial interests.
Making a rocket that lands, on the other hand, does directly correspond to SpaceX's financial interests.
Imagine if the banner said "This website is known to the state of California to cause cancer". Would you keep visiting the site?
Like if every time you went the bar, the bouncer asked "Hey, can I punch you in the face?". Would you keep going to that bar?
As annoying as the banners are, they actually aren't annoying enough to change mass-behavior.
You don’t need a banner for the data that is necessary for the service to work at minimum level. There is no role for the consent since the site won’t work otherwise.
If it even exists!
To the point: Not using a site is not the point of it. Insert "yet you participate in society" meme
How does it show that?
It shows that they prefer to get on with their day over clicking cookie banners. It says nothing about whether they agree with the philosophy of the GDPR.
(a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.
(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations).
(d) Vital interests: the processing is necessary to protect someone’s life.
(e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
The maximum fine is 20 million euros or 4% of revenue, whichever is higher. Sure, it probably won't be imposed on a first time violation, but why take the chance?
Could you imagine any lawyer advising a company against requiring consent, even if they have some cover because of a legal obligation? Isn't it much safer to deny service to those that refuse to consent?
Sure, it'll annoy the customer, but right now the customer is used to minor annoyances.
We were advised by our lawyers (a top SV tech law firm) that we should include a cookie banner in the EU even if we're only using cookies for functions like login. After eventually switching legal counsel (for unrelated reasons), we were told the same thing by our new counsel.
Either EU law covers cookie banners that use cookies for routine functionality, or it's so (deliberately) vague that even top tech law firms would rather everyone add a cookie banner than risk running afoul of the law. Either case validates PG's argument here.
1. There are users who will come to your website with specific purpose or expectation of your service.
2. Then there are users who came to website by accident and might just try out things without understanding what is happening.
The banner recommendation from the lawyers is likely for the 2nd case. The users haven't subscribed to the service with certain expectation or knowledge what is expected from them to service to provide what they want. Or they have zero expectations about the service to provide something for their needs.
For example, the login case, the group 1. probably wants to stay logged in if they came to service with expectation of personal service, which cannot be linked to the person without an account.
Or the lawyers just did not understand your service well enough and just said that put the banner be done with it. For group 2. it is unlikely that someone did not expect or want to stay logged in all the time, but that is for minority and arguable case whether is fair to assume that.
So, how did you ever expect the lawyers not to recommend adding the banner? That's like going to a plumber and ask them if you should DIY or not some installation. Of course they're going to recommend you get a professional...
Thankfully we have EU institutions to protect us from these evil companies. But somehow the EU institution websites all have cookie banners too.
Let's say you make a law to reduce working hours from 40 to 37 hours except in "emergency situations". Now a company will force employees to sign off on "emergency situations" every week or they'll be fired. They're clearly not complying to the spirit of the law? Is it really your fault when you make a law like that? I'd say only to some degree, the people trying to abuse every loop hole are much more responsible in this case.
Companies using dark patterns, hiding the "reject all" option behind an additional click (which even is illegal) and even trying to collect all data possible are much more responsible than the EU's law. Oftentimes they are collecting data just because, not even thinking about it, because they'll add GA to their WordPress site without even looking at it or whatever. That cookie banners have become the standard around the web is sad because it just shows how much everyone is trying to track you.
I can't really comment on what the lawmakers foresaw or intended, but I'd argue that cookie banners are actually a) good, and b) the fault of companies who can't imagine a better way to treat their users.
The reason I think they're good is that they cause a psychological nuisance to users of software which doesn't go out of their way to do them well or avoid their necessity. Over time I hope this will tend to cause an association in users minds that sites with cookie banners are somehow seedy or unscrupulous, like pop-up ads.
So legislators do expect such a struggle, and the shape it takes may be partly their fault, but it's clearly not all their fault. The more power the private interests have, the more likely they are to find some way to fight the regulation. They will certainly do everything they can to convince the public that the legislators are bad at regulation.
In this particular case, however, websites showing banners are also harming themselves as their competitors now have an interest in not showing banners and offering a better experience -- i.e. the regulation makes it worthwhile not to display banners in competitive situations. So we'll see how this all turns out.
If nothing else, at least now people know just how much they've been tracked. One can only hope that this increased consciousness would help people to choose services that don't track people. For example Hacker News doesn't need tracking cookies nor a cookie popup, and it seems to be doing just fine, even in terms of the law ;)
I think the bigger issue here is that this law did not fix anything, destroyed what little EU online advertising business existed, and focused on the wrong thing. For starters, the european people did not ask for this law, they have bigger problems, it was campaigned by specific german interest groups for which most EU citizens are indiffernt. Ad tracking is/was not a concern for the vast majority of EU citizens (who , again were never asked about this law) . Internet and social media addiction, however, IS an issue that most citizens have, and the EU has spent so much energy and capital on this pointless cookie banners issue, that it doesnt have more to spend on solving the addiction issue. Premature legislation always does that, and the worst is, there will never be accountability for such wrong decisions. The people who inspired the legislation are not up in some kind of election, and the upcoming MEP elections have nothing to do with EU politics and everything to do with domestic politics (Show me a country where MEP election results are not considered a proxy for national elections).
But it doesnt matter how many times someone points the political misaligments , there is no mechanism to change that until something really grave happens, when it will be too late.
A couple of observations:
1. Players like OneTrust and the consultants who specialize in this, are highly incentivized to play up the risks of not being compliant. My layman’s estimation of the legal risks is that the risk for good faith actors is actually pretty low. If the authorities find that you are not in compliance, you will most likely get a chance to rectify this, and possibly a slap on the wrist. Those scary fines measured in percent of global revenue, is not going to be what you face for an honest mistake.
2. Those businesses that rely on invasive tracking, and therefore really must use these banners, benefit from everyone else mistakingly believing that they too must compromise their UX with these banners. It makes what they do seem normal and acceptable.
If the cookie law was written properly then it would have just been a browser setting that had to be respected and this whole thing would have been completely transparent to the end user and they would have benefitted by default.
Instead through incompetent government employees we now have cookie banners for the rest of eternity on almost every site and they're not even standardized so worst sites like where journalists publish can have more and more obtuse ones.
GDPR's Article 7 [0] is very clear:
> 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. [emphasis mine]
[0] https://gdpr.eu/article-7-how-to-get-consent-to-collect-pers...
The enforcement/implementation of a law is so deeply entwined with the text that it's deceptive to separate them.
If a law is written in a way so as to make enforcement hard, or if the government doesn't have the resources to quickly and consistently apply it, then it's a bad law because it enables weaponized targeted/selective enforcement of a new law that wasn't present before.
Regarding the link you posted, they have a banner at the bottom saying:
> We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it. [Ok] [No] [Privacy Policy]
My understanding was that such an implicit consent ("we will assume that you are happy with it") is not legal so I find it a bit surprising to see it used on a website dedicated to the GDPR.
"Prior to giving consent, the data subject shall be informed thereof."
Means there must be some sort of a cookie notification (which could of course take a small space of the screen, but still).
The existence of this notification makes it easier to initially give consent. If withdrawing later is to be as easy, the notification must never disappear.
* There was an option of making this non-intrusive, by requiring it to be a browser setting, they chose not to
* The law went into effect ~6 years ago
* Companies still break the law by employing dark patterns
My take is that it makes both the law, and the courts bad.Clearly, national prosecution authorities can't be arsed and we don't have enough citizen-activists filing strong lawsuits.
In an ideal case, if it was just a law, a simpler wording could be "you are allowed to collect anonymized data, but not monetize/share it without permission from users. We may ask you to furnish proof that you havent been doing that at times, failing which you would face massive fines (as %age of revenue whatever)."
Problem is collecting basic anonymized usage data[1] is needed by companies to improve the product, provide a better experience, detect misuse. They bundled those use cases with everything else meaning the law was too broad and we got cookie banners given every site needs basic analytics. On flipside, worst is that most websites use Google Analytics, so they might have had to display the banners anyway.
[1] Moreover, it's vaguely worded so we companies do not know if they have committed a GDPR offence. By general understanding IP addresses are under GDPR. You can get that via request headers. So, to be on the safe side, even anonymized analytics tracking is considered under GDPR
> Moreover, it's vaguely worded so we companies do not know if they have committed a GDPR offence.
Only if they are trying to skirt the law.
notice the part about how purposes cannot be bundled together. EU's own website does that till date.
> NOT needed to improve your website
When I say usage data, aggregated data about how many people bounced off my page, or how long it took for my webpage to load under different internet connections is absolutely needed for me to make sure every user that comes on the page is having a good enough experience. I may not save any info, but those numbers are definitely used in aggregate. if the bounce rate is too high, content is not useful for people i am reaching. If i cant know that, how does the webpage gets better. That is usage data. I do not care about who the person is, but I would want to know whether it was one person doing one action 100 times or 100 different people doing the same action. Makes a massive difference.
I've clicked 3 cookie banners today alone and its not even 2pm yet.
How many cookie banners have I clicked in my life so far? How many cookie banners can I expect to click over the remaining 40-50 years of my life?
The law is objectively bad.
No, the websites you visit are probably bad.
Which cookies did you have to accept/reject? What do they do? Why do the websites believe they must ask you to accept them?
Also, the law allow browsers to automatically accept/reject the cookies on your behalf (actually, the law does not care about which specific technology the websites use to collect and process personal data). You, as a user, can choose a browser/extension that rejects these cookies by default, except the necessary ones. I use https://addons.mozilla.org/en-US/android/addon/istilldontcar... and I haven't see a single cookie banner for years on desktop and mobile. I don't like cookies and I like the law.
(Also, if a lot of people did choose the 'everyone all the time' setting, that would arguably be a poor outcome, because it's unlikely that this is really what people want.)
The only alternative to that binary logic is cookie banners. So to be clear, you are advocating for cookie banners.
The reality is that the overwhelming majority of people do legitimately want option 1, which makes cookie banners redundant. The only reason that cookie banners exist is as a high pressure sales tactic to sell users into option 3.
So yeah, you can never compel a site designer to stop doing a thing without compelling them to stop do that thing. The only middle ground is a middle ground.
>The point is that you'd still get cookie banners even with option 1
The adtech will absolutely freak out and destroy any attempt to make such setting as soon as there's a risk of it working.
The law could have been written in such a way that we could use a browser setting and avoid incessent popups which irritate users and desensitise them to genuinely useful warnings.
Whatever the good intentions of EU lawmakers, they seem inept at technical legislation because they ALLOW companies to continue doing shady things, and rather than tackle it, the legislators create a law that merely annoys users.
as written elsewhere (since you obviously didn't read anything) your proposed solution would be just fine. But people opted out of impmenting it that way since it would yield less profit.
Also, if you feel certain, and a ready to defend in court, that practices you have on your website does not constitute tracking. Then you don't have to show the banner either.
Personally, I am much more pragmatic about these regulations - with good reason. I still have to hear about some small innocent company hit with a massive fine. Empirically speaking, it is mostly huge multinational companies with plenty of resources to manage these things down into details who have gotten fines after repeat offences.
All in all. If you assume malicious regulators, then it is going to be stressful to work in a market. From US influence, I also do understand the sentiment, though it is rarely mirrored with EU citizens who generally don't assume hostile regulation.
No they don't. But enforcement requires complaints, actions, and budgets. Remember that the EU has no police, it's down to national governments to enforce regulations.
Also, take fraud. There are plenty of laws against fraud in any country - and still it happens every day in one way or another. That's not because all fraud laws are bad, but because enforcement is complex and costly.
I don't think that's a specialization of EU lawmakers, particularly. A far as I can recall, laemakers started thinking about internet regulation around the turn of the millenium, and I didn't welcome the prospect; I assumed that regulation would favour state intelligence and police agencies, and would be drafted by adtech lobbyists. Why? Because I didn't think the civil servants who are supposed to draft these laws had the requisite competence.
Sometimes life really is is fact a zero sum game and you need to punish the offenders in order to protect the victims.
>Instead through incompetent government employees
Or greedy companies, one of the two...
Even worse, this thread is full of armchair lawyers that will confidently tell you there's no need for cookie banners in particular cases. Nevermind that there's hardly any case law about this and each country seems to interpret it differently. Any actual lawyer would tell you to slap it on there to stay protected.
I bet the number of cases of illegal implementations due to insufficient consent are vastly smaller than the blatantly illegal consent implementations(i.e. those that make it harder to reject consent than accept it). Companies clearly don't care about following the law anyway.
Presumably, lawyers err on the side of caution? That doesn't mean they're right.
I'm not talking just de-emphasising the reject option here, but cases where there is no reject option or it's buried beneath 2-3 more clicks.
...
Any actual lawyer would tell you
Assuming you're not yourself a lawyer, doesn't speculating about what an actual lawyer would say or do make you an armchair lawyer?
In my opinion the EU's big failure with GDPR has been slow and ineffective enforcement against blatantly illegal implementations.
Instead law is written in a technology neutral way. It is so neutral that it isn't even called "cookie law". It is called ePrivacy directive. It has only 5 times the mention of "cookie" as an example.
Reference: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A...
The law does not mandate websites to display a cookie banner. There are already "Do not track" settings in browsers. A website could choose to honor that setting and don't track you without ever showing you a cookie banner. But most don't.
They didn't do this before the regulation. It doesn't much matter whether a website could do better, they simply aren't going to do better unless forced to.
> A website could choose to honor that setting and don't track you without ever showing you a cookie banner. But most don't.
Exactly! Either fix the regulation to say they can't make UX worse or throw it away.
Yes, because they just tracked you and you didn't have a choice and didn't even know that they were tracking you probably.
You don't seem to understand what GDPR does. Very simply, it says: "Hey, if you run a website and want to store cookies in your visitors browsers that helps you track them, you need to ask them first if that's ok".
There are multiple paths websites could take:
1) Don't set tracking cookies -> No need to ask the visitor for consent
2) Honor "do not track" headers sent by browsers -> Only need to ask visitor for consent if the browser didn't set "do not track" header
3) Ask the visitors, but do it in a nice way that doesn't disrupt the whole browsing experience -> some examples are given in the blog post
There are a lot of browser extension that hide or click reject cookies for you, so you don't need to see 99% of all cookie banners. Have you tried using some of them?
There's no loophole. There's just limited enforcement. Most of the banners you see every day do not match the requirements at all.
This kind of behavior reminds me of the book: "Language vs. Reality: Why Language Is Good for Lawyers and Bad for Scientists" - Nick Enfield, Linguistic Anthropologist [1]
[1] https://mitpress.mit.edu/9780262548465/language-vs-reality/
We deal with similar issues developing and releasing software. Instead of not ever releasing software, or only writing perfect software that never has issues, we have a couple of options.
1) In critical life or death situations, spend a ton of time modeling all states of the system and program in a way that very strictly controls for these states, with a lot of testing. See NASA/JPL coding standards for critical systems.
2) For less critical situations, or those were modeling all states of the system are impractical, we release, observe, and iterate. Yes there will be edge cases, bugs, and loopholes. But we can observe them, iterate, and release updates.
I think case 1) is impractical for changes to large legal and economic frameworks in the real world given how many variables are at play. If we could model the entire economy and see how it would react to a given change, the world would be a very different place in lots of ways already.
A lot of politics seems to work against 2) and that hurts our ability to improve things. "I will pass a law that does X" and "I will repeal the law Y that is not working, see look at these loopholes!" are good political campaign statements.
"I will gather and analyze data on the operation of the current system and support an iterative change that intends to improve things, implement that change, and then observe the results to determine if future changes are needed" is hard to rally around either in campaigning or when actually doing the work of getting political support to pass law.
I think decent example of this in government, although far from perfect, is the feedback loop of the NTSB and FAA. The NTSB's job is to observe and report on failures of air safety, and the FAA's job is to apply those lessons to future air regulation. Of course there are many examples of this not working perfectly, but it's a more concrete feedback loop than most governmental action has.
More observation of the analysis of the impact of laws after they are passed, and follow-up iterations where we compare the expected and actual results and make updates, would probably result in a lot less gnashing of teeth over "bad government regulation" but I'm not sure how we get there politically.
It has even been implemented in Internet Explorer when it had 90%+ market share.
And then Google intentionally sent malformed P3P header to bypass user preferences in IE.
When Safari added a heuristic rejecting Google's 3rd party cookies, Google has found a technical workaround to bypass it (and has been fined for doing this).
When IE and P3P were totally dead, browsers have tried to give adtech the simplest to implement bare minimum setting - the DNT header. The adtech has completely ignored it.
There are trillion-dollar businesses relying on tracking, and they will do whatever they can to undermine any technology and lobby against any law that would harm their business.
Well, then, the EU should've just made _this_ the law.
And we'd have called it the "Just don't track" law.
Rant & Details:
> There is no law for cookie banners.
> What the EU is saying, you need my consent when you want to track me, profile me and sell my behavior off to ad companies.
> or “Look, Why take a chance?” (Remo Gaggi),
This kinda proves PG's point.
Rant: I find it incredible that folks defend the EU by saying things like "There is no law for cookie banners". No, there is a law. The law is reason people think "Look, Why take a chance?" and build crap like cookie banners in. The law is not a bunch of words on paper. It's the institution that incentivizes or punishes people for their actions; thereby influencing people's behavior.
If the EU is incapable of creating a law where it is unclear even to quite some lawyers where the boundary between allowed and forbidden is, the EU politicians are the incompetent ones.
In this case, the unclear point is around the notion of "legitimate interest". I guess something like fraud prevention can be thought of legitimate interest. But ad companies just said, "well, we make money out of tracking the hell out of users, so it's in our legitimate interest to keep doing it, and never mind that the whole point of the law was explicitly to rein in our industry's nasty behaviour."
So now law practitioners how to hash out amongst themselves what "legitimate interest" actually means in 2024, and this of course can change in 2034, so you write the law to not have to be updated every time the tech industry invents new ways of being naughty.
Really, no. Not being willing to let go of user tracking, and now realizing that it's against the law if you get it wrong, is why people think "Look, why take a chance?" and grasp for shitty dark patterns to cover their asses.
My business did not track its customers online and had no banner. Period.
Most people are copy cats, and if some big websites add cookie banners, they think they also need to do it because these big sites are doing it. And then they blame the law.
If you're not a copy cat and understand your businesses, there is no need to blame the law for making you do something you don't need to.
And yeah, laws can be complicated to understand sometimes. That's with most laws. But that is why we have lawyers. But yeah lawyers are also often copy cats, it seems. At least in tech. So it's always good to keep thinking for yourself too. Don't believe everything other people are telling you. Do some investigation and research yourself. It's also not that hard.
Honestly I think most people see it this way, even if it’s an unpopular stance in some tech circles.
Examples for what that means given by the EU itself [1] include "cookies that allow web shops to hold your items in your cart while you are shopping".
And on the policing - there are a lot of laws that cannot be "policed". It requires trust, goodwill, collaboration and savy users to report violations to the webmaster or relevant ICO.
How do you know if your neighbour is not producing meth in his basement?
Yes, users could block all cookies but this will break functionality on a lot of sites, so it's not reasonable. And yes, sites could communicate which are functionality cookies and which are tracking cookies, but as you say it's hard to police this, so pushing the issues to the user's software won't work.
What the law does is fixes all this by requiring sites to obtain consent in certain scenarios; but if your site only sets cookies required for the site to function (shopping cart, login cookies), or if it tracks users for the purpose of security (eg a bank that detects when you log in from a new device / location) you DO NOT need to obtain consent, no banner required.
It seems like a point dear to the author's heart, given the way he highlights this and puts it in bold at the top of the article.
But while it sounds good on the surface, it doesn't take much digging to show it's silly. If you store any kind of data about a visitor to make their life more convenient, is that tracking? Shopping carts? Notification preferences? etc.
It's actually a bit ironic to ask visitors if it's ok to track them. If they say no, you have to track them to at least remember that choice.
Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?
No. It took effect in 2018.
Probably because they're not particularly technical people, and also because of the asymmetric incentives for them personally.
Tell someone to put a cookie banner up when they didn't need to: no consequences.
Tell someone not to put up a cookie banner up when they did need to: potentially big consequences for them and their career.
https://ec.europa.eu/justice/article-29/documentation/opinio...
This says that cookies for a shopping cart or user preferences are exempted from consent. The ICO and the CNIL say the same, as expected.
> consent is not required [for] cookies that are strictly necessary to provide an online service that the person explicitly requested. e.g. […] when your customers use a shopping basket
So shopping carts (user clicked to add to cart) and notification preferences (user clicked to indicate preference) don’t require consent. Same for authentication cookies.
The page is quite clear; the confusion likely arises from how companies implement it.
[0]: https://europa.eu/youreurope/business/dealing-with-customers...
If you really care about not annoying your users and don't intend to track them more than what's absolutely required for the service to work, then talk with your lawyers more. Of course, it is not free as it requires extra work, and it may carry some risk (which your lawyers should minimize) but it may be worth it, many people press the "back" button as soon as they see a cookie banner and try their luck elsewhere.
> A cookie that is exempted from consent should have a lifespan that is in direct relation to the purpose it is used for, and must be set to expire once it is not needed, taking into account the reasonable expectations of the average user or subscriber. This suggests that cookies that match CRITERION A and B will likely be cookies that are set to expire when the browser session ends or even earlier. However, this is not always the case. For example, in the shopping basket scenario presented in the following section, a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours in the future to take into account the fact that the user may accidentally close his browser and could have a reasonable expectation to recover the contents of his shopping basket when he returns to the merchant’s website in the following minutes. In other cases, the user may explicitly ask the service to remember some information from one session to another, which requires the use of persistent cookies to fulfil that purpose.
(Criterion A is cookies that are user “for the sole purpose of carrying out the transmission of a communication over an electronic communications network” and criterion B is cookies that are “strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service”).
If your shopping cart cookie has a lifetime longer than the "reasonable expectations of the average user or subscriber" you may need to obtain consent. That a sufficiently vague criteria that it may not be clear if your particular shopping cart cookie requires consent or not.
[1] https://ec.europa.eu/justice/article-29/documentation/opinio...
A tracking warning a login/sign up would be enough. No need to ask for cookie consent at every visit. It would just be part of the typical T&C.
> It's actually a bit ironic to ask visitors if it's ok to track them. If they say no, you have to track them to at least remember that choice. Easily solved with a cookie that says "don't track". If cookie is set, don't track anything.
Please, read the basics about the law before disparaging criticisms, I constantly have to educate users on HN about this misrepresentation of GDPR and Cookie Law.
If it is crucial to provide the service or the service is explicitely requested by the user (i'd argue a shopping cart is), I think you don't need consent (see Article 5 of Directive 2002/58/EC).
It's not "you're not allowed to store anything about the visitor without their consent", it's "you're not allowed to track them across your site, or share that data with others, except if it's directly necessary to provide the service". That last part refers to session tokens, shopping carts, and yes, also to remembering the "no tracking" choice. If you ask a site to remember something (such as "no tracking plz" or "I want to buy this product" or "keep me logged in plz") then that's explicitly asking it to do something that in technical terms is tracking, but not in operational terms.
It's like, the EU makes a new law that makes it illegal to break into people's houses, and all the pedantic HN'ers start saying "but this is stupid! what if you lose your key? you need to be able to hire a locksmith to let you back in!". That's obviously not how the "no break-ins" laws work, and it's also not how the GDPR works wrt tracking.
If you break the GDPR, there's a fair set of warnings before you can actually get the kinds of humongous fines that the law is infamous for. This means to me, as an entrepreneur, that if I follow the intent of the law as best I can, then worst case scenario if we still get it wrong, then there's a big enough chance we're in the clear. And then if somehow we do get a warning from the local privacy authority, we learn and adjust. This is fine.
We don't need to be maximally pedantically safe. We just gotta not track people and then we don't need a cookie banner. It's great.
Not really - basic functionality like you describe does not require consent, AND any cookie specifying non-consent is in itself anonymous.
If you really make it anonymous, the downside then is that you have to keep asking the same visitor over and over again, each time they visit.
These are first-party cookies as they're served by the host domain, so they wouldn't need an opt-in under GDPR. Site owners should try to limit that to core functionality, like updating shopping cart state as you navigate from page to page.
> It's actually a bit ironic to ask visitors if it's ok to track them. If they say no, you have to track them to at least remember that choice.
That's not how it works. The cookie banner opt-in asks if you want to accept cookies aka tracking. If you say no, no cookies are downloaded, so the site has no idea that you have visited it. So the next time you arrive on the site, it will provided the popup again, as though it's your first time visiting.
They insisted we implement a cookie banner which would set a cookie to say whether or not you had accepted cookies. This was the only cookie.
[1] Never a good sign when legal and compliance just book a meeting with you like that and you don't know any normal context.
And while the main visible results today are bad (cookie banners of various levels of annoyance) it is bad mostly due to existing dark patterns and encourages changes in the right direction. Will those chances come and, if so, when, is to be seen. My 2c.
If I'm allowing my browser to set cookies, I don't need an EU law forcing websites to ask me everytime if I'm ok with a cookie being set.
It's how we wish people worked, but it's not how people work. The area of people that actively care about being tracked is not equal to the area of people, that would say yes if you point blank ask them "do you want to be tracked?" (with all the fears that this question triggers), and it's not equal to the area of people who would actually be happy to give up the affordances that tracking allows for in their every day life, even if they really do not like to say "yes" when asked to be tracked.
All of this is compatible because, hi, this is us. We close our eyes, and pretend they are open. We love to not consider consequences, while thinking of ourselves as considerate. Well, not always. We do make "a few mistakes" every now and then, of course. This makes the whole thing believable, to ourselves and each other.
I understand that it makes for good internet banter to ignore all that but what else it is good for, I do not know.
Perhaps because the big tech has captured the regulators with a lobby revolving door.
Look at how big a tantrum Apple is throwing regarding 3rd party app stores.
I’m glad EU is doing what it’s doing.
And the various data locality laws. Data is precious.
I wish US would impose stronger fines when data is misused or hacked into due to negligence.
Sure lots of EU laws, practically speaking no difference at all.
I hope the EU sticks to their guns. A few years ago, there was a flood of HN posts about optimizing initial page loads etc, because research showed that even a few hundred milliseconds slower load times measurably affected how often people clicked on buttons named "buy" and "sign up" and the likes. Then GDPR happened, and this somehow became a non-topic and instead we get 3-screen tall "TrustArc" modals that take half a second responding to a click? This makes no sense at all!
I hope, and believe, that it's just a matter of time before people re-discover that yes, actually, if you make a page fast and nice and friendly, you get more clicks/signups/purchases/$kpi, and that cookie banners hurt business.
If this is true, then what we're seeing now is just the initial path of least resistance: do what we did before, plus do what the lawyers tell us to. As the key GDPR rules have gradually become "common knowledge", we ought to be seeing gradually more sites switch their approach and focus on fast UX again, ie, no cookie banners and thus no tracking. Sure, it's work, and I bet the math doesn't always work out against tracking, but I bet often enough it does.
Thank you. The industry needs more such testimonies showing that letting go of tracking is okay and won't sink the ship.
But Volkswagen was very discreet about it, and when uncovered everybody was against them. Website are being obnoxious, instead, and people accuse the law. Go figure!
It's a stretch though. I prefer more obvious analogies.
There are extensions like “I don’t care about cookies” for this but also uBlock Origin has a list checkbox for it.
There was the DNT header. Few sites acknowledge it (and thanks to those who do!), and when Microsoft went against spec by setting it default-on in their browser, advertisers whined that they can't see informed consent anymore and just shut down the whole initiative. Note: Microsoft is also in the advertising business, so if you're into that, that might be another angle for your favorite conspiracy theories.
Finally, there's consent-o-matic, available as browser extension for various browsers, and it lets you state your preferences. https://consentomatic.au.dk/ Would it have been better to integrate that into browsers properly? Sure. But the social and economical dynamics being what they are, this is probably the best we can get.
And that probably can be automated...
Sure, you can say that websites have the option of "Just don't track", but realistically we know that that will never happen. Particularly since a lot of websites are actually tracking the user for the purpose of making the experience better (such as remembering settings, recent search terms, etc...), rather than tracking for the purpose of selling data to advertisers. But, from the user's point of view, they won't know what they have agreed to anyways. So essentially we get to a scenario where 99% of the websites have annoying cookie banners, when we already know that 99% of users won't read the terms anyways...
If the EU was good at regulating things, they would come up with a solution which puts the responsibility primarily on the website. One example of this could be if EU defines like ~5 different "data ratings", with pre-defined conditions of what sort of data was allowed to be tracked for each rating. Then the websites are responsible for choosing the rating that corresponds to their level of data gathering, and if they report it incorrectly, the EU could fine them.
The result of this is that when a user visits a website, you can quickly see a "badge" in the browser which lets you know what sort of tracking this page has (thus the user learn what each rating means, and get a better understanding of what they agree to). This is very similar to what Apple already does in the App Store in the "Data Linked To You" section for each app.
Eu bureaucrats could have expected that many companies _need_ tracking to survive.
While most people do not actually care about tracking.
Not to mention that behind most companies are the people who earn their living. By honest work (advertising is not guns smuggling you know).
So eventually those stupid bureaucrats didn’t really solve anything, but made life slightly worse for everyone.
Which proves original Paul’s point.
Big websites are tracking people, unknowingly to them, giving them lots of power, because information is power these days. And the sites that treat their customers fairly and honestly, ie they just want to offer you their product/service and are not interested in making a profit from your information, are not highlighted for their good intentions.
This law makes the difference clear to users. Maybe most users don't care, like most users don't care about open source, or fair trade products. But I'm personally happy that the EU cares, because I care. And I understand that most people don't care because they are ignorant about the issues and consequences. But I do find it a bit funny that a lot of people on HN don't seem to care. And I think the cookie banners are a good way to start to make people aware of these issues. It won't solve it in one go of course, but at least it starts to make people think about it in some way. And maybe there are better ways, but you gotta start somewhere.
You know what else is true?
If dumb bueroucrats don’t spend time on a silly solutions to artificial problems - they would spend it on solving real meaningful issues.
I think we can at least agree on that.
How much power exactly does a website get by saving a cookie with my data?
No, people don’t care because there are no consequences. Except just better targeTed ads.
Most people on HN are hackers, they know exactly how this works.
If you were brainwashed to be scared - doesn’t mean I as a user must pay for it with my attention.
Educate me step by step please using some simplified example.
"They" are the ones that have control over the data. The ones that collect and process all the data, or the ones that buy it. Mostly FAANG and their clients, which are also governments.
For example, a few months ago, ironically, a department within the EU ran a campaign on X, persuading people to vote for CSAM laws. But they micro-targeted specific groups. And this is actually prohibited by EU laws itself, by the Digital Services Act (DSA). See this article:
https://techcrunch.com/2023/11/15/oops-2/
And microtargetting is actually a common practice, used for political campaigns in the US, Australia. It's also used by Russia for disinformation campaigns. See:
https://www.nytimes.com/2018/08/16/technology/facebook-micro...
And:
https://www.justsecurity.org/41199/connecting-dots-political...
Also the wiki about microtargetting is interesting:
https://en.wikipedia.org/wiki/Microtargeting
I hope this helps you understand how tracking cookies can be used against you. Of course it doesn't affect you directly personally when you visit some websites. But you have to see it in the grander scale. We are collectively a group. And as a group we can be influenced, manipulated, etc. And ultimately that affects the individuals inside the group. And this has always happened, it just happens more automated these days. But if we, as a group, stand up against it, we can empower ourselves, and we can make life better for us as a group, which will ultimately impact our personal lives as well.
Did you know that the bigger company is the easier it is for it to workaround those silly cookies limitations bureaucrats impose?
Did you look out the window recently? Did you notice any positive political changes after these stupid regulations took place?
What other evidence you need to admit it was a dumb and useless regulation? Even if it had originally a good intent to it.
Imagine a group of people living in a big house that hasn't been maintained and cleaned in a long time. Then someone starts cleaning a little window. And someone says: look at the rest of the house, do you see any change? Well of course not, but you have to start somewhere. And maybe we didn't even use the right cleaning product or technique. But by doing it, we're learning about what works and what doesn't. And we might inspire other people, and they could start cleaning other parts of the house, and we can collectively make a significant change.
It's a slow process and it might seem impossible to some people. But it is possible. Look at history, if we never made any law and order we would still be walking around as wild men.
The change we would like to see might not even be in our own lifetime. But think of the next generations. They have to deal with what we leave behind. And I'm very happy our previous generations layed the foundations for law and order on which we can continue to build.
Yes things are not perfect and they will never be. But there's always room for improvement. And why not work towards improvement instead of deterioration. Why not have a positive outlook instead of a negative one.
I'm not saying you have to go out on the street and go protesting with billboards. But we can at least try to support each other improving the system. Again we have a long way to go, but there is hope. There always is. If there wasn't, we wouldn't be here.
Following this logic - why don't you cut out few buttons on your keyboard?
To raise awareness about online gaming and pron addiction.
It's not much, but you have to start somewhere, right?
I understand you see it as an inconvenience, making the UX worse. But it's not about that, the cookie banners actually provide you information about what they use the cookies for. Which 3rd parties they share it with. It is about raising awareness.
And yeah, you have to start somewhere. If you don't do anything, nothing will change, and deterioration continues.
You do understand that the ones in control of this data have a lot of power. Do you wish to change it or are you satisfied with the situation? If you have a better idea on how to deal with this issue, that could be a helpful contribution.
What I mean by this is that tracking in web properties is a joint decision (in most tech companies anyway) between Marketing, Legal, and Product as functions and executive leadership overall. This is actually a “big” decision, because it’s a binary decision that guides future trajectory.
Companies can choose to:
A. Make decisions about where to expend resources on ads, product feature development, localization, accessibility, et al on web properties based entirely on the “gut check” of their employees in each function and trust the outcomes.
B. Carefully measure and track everything so that decisions are supported by data and results are tracked, simplifying decision making and reducing the potential bias of employees and eliminating the need to trust employees to make good decisions and being able to validate outcomes.
If your product /is/ a web-app, the impact becomes even more pronounced.
At the end of the day, the only way to get an organization to give up tracking is to directly force the issue in the law or solve the underlying issues that create a trust gap and competency gap within large organizations. I think the latter is likely impossible to solve, so the former is the only option. In line with the banality of evil, companies are not maliciously deciding to track you, if there is any malice here its towards their own employees down the line, who aren’t or can’t be trusted to do their jobs without tracking.
Because Option B is the only likely option here, the net effect of the law as it stands today is to have a cookie banner everywhere. There’s literally a SaaS called Cookie Law that helps companies comply with these rules.
But I'm pretty sure that close to 100% of pg's YC startups do track their users. So here's pg's shitting all over the regulators who made him a flower by still allowing his businesses to track people by tricking them into accepting cookies.
Ugh
The law may be a one-liner that just wants to protect the users privacy. But this vagueness makes this law so extremely bad. Companys don't know anymore what's allowed and what not, so in order not to risk getting sued by some greedy shenanigans they just put up some cookie consent wall up. Can i use tools like Microsoft Clarity or Google Pages without getting sued by not having some cookie banner? Who knows anymore without getting an expensive lawyer and then i have to deal with the expensive technical changes required to implement these regulation wich especially hurts small or one-person software shops while big co doesn't care anyway.
>there is no cookie banner law
There definitely is. The article explicitly states this:
>you need my consent when you want to track me
"tracking" here means storing data:
>store information in a visitor's browser is only allowed if the user is provided with "clear and comprehensive information", in accordance with the Data Protection Directive, about the purposes of the storage of, or access to, that information; and has given their consent (wikipedia)
The actual directive also explicitly states this
>consent may be given by any appropriate method enabling a freely given specific and informed indication of the user's wishes, including by ticking a box when visiting an Internet website (32002L0058.17)
Yes, without any consent. For instance logging in a site, doesn't require the warning.
You don't pay for (almost) anything on the internet. Nobody does, because the requisite infrastructure doesn't even exist to allow you to pay for a page at a time. Until that changes, the creepy companies will keep finding ways to follow you around- both to earn money from advertising, and to ensure you're not abusing their systems.
Huh. I always thought that as soon as you use a long-term cookie that could technically be used for tracking, you have to get permission.
Which also means you have to get permission when someone logs in to your website. Though I guess the act of logging in could be seen as giving permission.
Anyway: I don't add cookie banners on my websites, and I don't use any tracking.
http://www.pisrs.si/Pis.web/pregledPredpisa?id=ZAKO8611 -- 225. člen (piškotki)
Companies can easily not deal with EU shenanigans. Just leave the EU. actually: many do.
This is probably the worst omission from the EU law, no limit to the number of times you can be asked.
I told you my answer last time I visited… but you didn’t like it so you ask again, and again, and again. Every time I visit you ask me. <rage quit>
It was my understanding that it is deprecated because it was completely disregarded and thus gave a false sense of safety from tracking and it was used by tracking company to do additional tracking.
For cookies to function, browser (acting on behalf of the user) and website have to cooperate.
First, the website sends a snippet of data to the browser, the browser then stores that data, and sends it back to the server on subsequent requests.
If the user doesn't want the cookies to function, all he has to do is tell his browser to stop sending the cookies back. The website has no way to forcefully store the cookies on the users computer and then snatch them back from their hard drive. The browser, and ultimately, the user, is the one that decides to store and send the cookies back.
But legally, website owners are held accountable for the inability of users to stop themselves from sending the cookies back. It doesn't make sense.
If the rest of the Internet worked this way, you would need to call Google on the phone and tell them that you consent to them sending you HTML before being able to load google.com on your browser.
Most decent browsers block google analytics these days.
The facebook pixel was retired as far as I can recall.
At this point I just have a local analytics setup just to let me know how many visits a particular page got.
Create dumb and pointless rules and enforce them with highest passion.
Believe that you're the smartest person who only understands these rules.
Serve nothing but the soul sucker bureaucracy.
Many people are leaving Germany pretty much because of this. Startup founders often do pointless work just to not get in prison.
The author of course has zero experience building anything. He is the amazing CTO. He'll teach you how to do. Because he's superior than rest of the world.
The society here has tendency to descend into madness with a strange group behaviour.
History. Rhymes.
There is no EU cookie banner law
You're making it sound like it was a switch that I could simply turn on/off as a web dev. The reality is that most sites are a complete clusterf*k of 3rd party components, dependencies, backend services etc.
Doing an audit of which of these components are compliant with tracking / cookie laws is just not a realistic ask. Hence why devs decide to just tack on a cookie banner and call it a day.
just don't build rockets
Instead, the law and requirements should be adjusted to make the horror of cookie banners stop.
I never could understand who thought asking website owners to get your consent is a good idea. Think of when you are installing an app on your phone, is it the app asks permission to use your location or your OS? Access to cookie storage is the same, a browser should allow or not allow webpage to store something on your device. Same as most of the browsers do for notifications btw.
Fixing ~200 browsers is much easier than fixing millions of the websites, you can also setup default preference, you can also have a clear, unbiased UI.
On the other hand, nobody is entitled to free content on the internet. Hopefully people will become annoyed enough that they will stop visiting the sites of data exploitation companies altogether.
Just use Consent Free analytics like Wide Angle Analytics.
If you don't want to be tracked: disable js, disable cookies, don't go to website you know will track you.
As a user: the way you can check whether you have a tracker is as trivial as interacting with a cookie banner. Plus the cookie banners are all different but the UI to check cookies on your browser is standard and the same. if the EU wants to do something: force browser vendors to educate users on how to use their software
1) didn't bother to read the article
2) didn't bother to read any previous articles and so have continually spread nonsense about what the regulations actually required
3) defending all the companies that decided to be fuckwits with barrages of notices to users instead of actually sincerely trying to reduce their creepy nonsense and then - if anything was left that required disclosure - explained it honestly
Working for Lockheed Martin or RTX is a more moral choice than working in adtech IMO.
I sometimes come across articles in local publications that ask me to subscribe - dude, seriously? Do you expect me to subscribe to an Alaskan publication when I live half the world away and could not care less of what happens there, but just want to read this one article that seems interesting?
So instead we have ad funded websites that have to do what they have to do in order to make some money and keep publishing whatever it is they publish. Hence tracking cookies.
Everyone's needs would be better served if we could pay for content the same way we did back in the day of printed newspapers. You buy today's edition and you get today's edition and no one except the newsagent is tracking you (if you happen to regularly buy the newspaper from her, she'll remember you, and she may even suggest additional newspapers to buy but it's implied, right? we dislike machine tracking, not humans remembering our buying habits).
Alas, we don't have that. We have intrusive tracking and subscriptions, even though technically it's something we could build in weeks (lest the payment companies didn't make it unfeasible, for their own benefit).
And people do sometimes try to figure it out. Bundles come to mind. Everything -- except micro transactions allowing you to purchase just. this. article. And while micro transactions don't exclude tracking, companies are more likely (is this wishful thinking?) to be careful with a paying customer's experience than with freeloaders, which is what we insist of being, while putting up demands as to what publishers can do with our data.
This is one option. Another is that advertisement goes back to those days: you associate advertisement to a content and to a rough geographical location, and that's it. No personalised ads is still possible.
Right now, it's just irritating for the average person and slightly inconveniencing those who actually break the rules.
This is the same situation with the cookie banner regulations. If the goal is to eliminate tracking, then making tracking illegal is the straightforward path (or make "do not track" actually mean something legally). Otherwise, ignoring it might be better. Implementing a policy that only frustrates the general public without effectively addressing the problem is not the right approach.
This is what the OP cannot understand.
EDIT: To the downvoters - I don't think you understand what the purpose of the downvote is on this site.
They would be a LOT less frustrating if:
a) they were standardized — they currently add a hefty cognitive load while parsing them, deciding which action to take, etc.
b) they worked properly — I would say, more often than not, they 'forget' the previous setting. I should never see a cookie popup on the same site twice unless I clear my browser settings.
As an aside, it's supposed to be as easy to decline as to accept; so if you give a 1 click 'accept all' then more than that (whether two or dozens) is unacceptable.
- bright red or green “OK” button that opts in to all tracking
- muted “save settings” button
But aha, gotcha, the default settings still have a bunch of tracking enabled, so you have to uncheck all of those, then remember to press “save” and not “OK”.
In the worst ones there’s an artificial delay when you uncheck one of the third-party boxes, as if it has to file a form in triplicate for the unusual request of not immediately sending all your account info there.
If you don't care about tracking, ok. But some do. The EU tried to cater to both audiences which I think is fair. Turns out most people that did not care about tracking would also not consent when they are asked about it specifically and there are no immediately perceived downsides visible.
And therein lies the false premise that makes the whole thing absurd.
Most people have no idea what "cookies" are, don't understand what difference it makes when you reject them, and are never going to learn - and we shouldn't expect them to! Leave the technical stuff for the programmers.
The cookie law only makes sense if you think that there's any significant overlap between "people who understand what cookies are" and "people who need help with internet privacy", for which I refer you to the Venn diagram in this comic: https://churchm.ag/eu-cookie-law-history/
If companies wouldn't try to frame the whole thing in technicalities, it could be a simple popup listing the features on the website that need sharing personal info and users could turn that off.
Regardless of whether cookie banners could technically be avoided, Graham's point stands that this regulation has served no purpose other than to annoy consumers.
Even disagreeing now forces you into another full-page pop-up where you have to itemize your disagreement before clicking on Reject All.
Ironically, the author felt compelled to announce that he’s not providing legal advice. There is also no need for him to make that disclaimer. But hey, why take the risk?
The number of unique visitors is a very useful metric (both in itself, and combined with the number of visits).
The EU has made it impossible to track this simple and harmless metric without inconveniencing all users with awful UX.
Under the GDPR / ePrivacy Directive, ANY user-based unique identifer used for advertising, analytics and tracking will trigger the need for consent.
---
General Data Protection Regulation (GDPR)
Article 4(1) defines personal data as "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
Article 6(1) outlines the lawfulness of processing and states that processing is only lawful if and to the extent that at least one of the following applies: "the data subject has given consent to the processing of his or her personal data for one or more specific purposes."
---
ePrivacy Directive (Directive 2002/58/EC)
Article 5(3) requires prior informed consent for the storage of or access to information stored on a user's device: "Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service."
The next level is to not store PII unless there's a specific reason in the user's interest (improving site quality doesn't count, logging in does). Therefore, you can see how many people visited a page, aggregates of device types etc. Just not anything that identifies an individual.
By not sending the data to third-parties, you already comply to most of the GDPR policies.
This ambiguity leads to companies implementing cookie warning popups based on a risk-averse interpretation of the law
HN loves EU regulations though. HN also loves Paul Graham. I got my popcorn ready to read what people will write.
Edit: to those downvoting, yea, it’s agreed that tracking is bad but the tone of the article completely ignores that a lot of the web’s content depends on this model so if it “just didn’t track” a large swath would no longer exist.
That’t not "doing sketchy shit with people's data"
I can’t believe how many people have bought into this EU regulation hook line and sinker. It’s ridiculous, imagine the man hours that have been wasted in the last 7 years just clicking cookie bars. And as OP says, it’s completely unrealistic to not have them.
For instance the website selling ads has every reason to inflate view and click count numbers, the ad buyer has reasons to diminish those numbers. In fact if you measure an honest pipeline it is going to look that way because some people drop out at each stage.
One reason you have 87 trackers on a typical web site is that many sites and advertisers figure if they have a large number of trackers they can’t all be wrong.
Site X could show ads to users just fine without third-party cookies but then advertisers would not be so sure about the stats.
> Site X could show ads to users just fine without third-party cookies but then advertisers would not be so sure about the stats.
Feels like 99% of people would prefer this. Maybe advertising becomes less effective, but it may actually become more effective if it leads to more ads being visible since they are no longer ad-blocked.
So you need to tell people you are doing that, so they can consent.
You think it’s some sort of choice you have between being tracked or not, but it’s not, it’s between having a fairly decentralised internet or not.
And unfortunately with recent google SEO changes almost all small blogs at this point have been wiped out. Googles own properties, Reddit and Quora, and large websites like NYT and CNET are the only websites left in search rankings.
Selling my personal info to external companies so that they can manipulate me easier is sketchy in my eyes if I don't consent
What? What are you even talking about? Google does not sell your personal info. You’re delusional
Turns out you were the uninformed one. From the context through parent posts you can clearly see this was about a website using google adsense and by that, the company sells my info to an external (google) which then tries to take advantage of me to extract money from me.
That is what I am talking about and I think this was clear from the previous posts. I think you owe me an apology
This is not how it works. You might not be medically delusional but you are saying things that are not true.
Of course it is. If you add AdSense to your website you are letting Google track your users in exchange for a cut of the profits. Of course you should have to warn your users that they are being tracked at the very least.
But I agree, taking advantage of me telling you personal info by selling it to externals is unfair without consent
You say this like it's a bad thing...
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
The relevant part:
> Article 5
> Confidentiality of the communications
> 3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
If you want to argue that companies have a legal alternative to showing you cookie banners, then by all means do so. But don’t say there’s no law because there clearly is. This is a misleading and inflammatory headline.
Edit: Yes, I read the article. To draw a distinction between “must obtain consent” and “must show UI that obtains consent” is of no value unless you want to write an article with a shocking headline.
It is amended by Directive 2009/136/EC, which changes especially the cookies part.
> (66) Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere (such as spyware or viruses). It is therefore of paramount importance that users be provided with clear and comprehensive information when engaging in any activity which could result in such storage or gaining of access. The methods of providing information and offering the right to refuse should be as user-friendly as possible. Exceptions to the obligation to provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user. Where it is technically possible and effective, in accordance with the relevant provisions of Directive 95/46/EC, the user’s consent to processing may be expressed by using the appropriate settings of a browser or other application. The enforcement of these requirements should be made more effective by way of enhanced powers granted to the relevant national authorities.
If you read the exceptions part, you know that you don't need a banner on strictly necessary case.
If the functionality explicitly requested by the user -- e.g., logging in, or changing the default language or currency, or what-not -- no consent is necessary to keep cookies. Cookies are only necessary for things the user didn't implicitly ask for, like tracking.