These definitely need to be enforced better.
I'd accept a straight opt-in/opt-out choice if, as per the law, opting out was just as easy as opting in and opting in was not any sort of default. But the stalky side of the industry (most of it) doesn't want informed consent, they don't want to have to acknowledge the idea of consent at all.
The majority of the cookie banners that you see aren't even compliant with the regulations that the site owners claim that they are caused by, some aren't even close to compliant. At that point it isn't “malicious compliance” but instead “overstepping as far as they feel safe”. Almost none of the cookie pop-overs would be needed at all if allowing advertisers to follow you around your life was opt-in. You don't need to ask permission for anything that is strictly necessary, like non-permanent session tracking & auth tokens, presenting that part at all is part of the theatre to try convince users that the regulations are the problem not the sites themselves doing things that need to be regulated.
One of the most annoying bits of many is “legitimate interest” which basically means “we see your opt-out preference, but fuck you and your preferences we want to stalk you and we will”. Note that these are usually implemented in such a way that if you don't explicitly object they'll be allowed, even if you click the “reject all” button without opening the concertina UI element that hides them from default view.
The phrase “cookie banner” itself is misleading, though we are guilty of that as well as them. You are opting in/out of the ability for them to do things, cookies are just part of the options they have for implementing those doings.
And while I'm having a little rant… “We value your privacy!” — no you don't, you lying sack of shit. You value the opportunity to sell the possibility of invading my privacy to the highest bidder.
Cookie banners predate the GDPR by like, a decade anyway. They were the soft attempt to get tracking companies to back off; instead, tracking companies just attempted (and mostly succeeded) at tiring out the user.
I highly recommend the Consent-O-Matic extension to fully reject all that crap automatically[0] in lieu of corporations properly complying with the law and accepting the general rejection signals like DNT and GPC.
When I run into a website that it doesn't work with, I sometimes use the report function and set it myself.
However, most websites with a cookie banner that's too obstrusive for Consent-o-matic turn out to be useless clickbait LLM spam that's not worth the effort. So most of the time I just go somewhere better and leave the obnoxious cookie wall to itself.
I think it all turned out fine (for the time being) thanks to cookie walls :)
Im all for them.
But with uBlock Origin and Firefox, we have solid tooling to almost never see them now.
GDPR is also not the issue. The issue is incentives to track people.
The tracking itself is : if there is a banner, it shows you this company is indeed disrespectful.
But when they employ the practices that make them have them, I'm glad I can say no.
It's understandable, they can do whatever they want without any consequences right now, but that needs to change.
Even the enforcers are just not mentally ready (or just have too many cases) to really, really slam the monopoly of force on offenders.
But regulator obviously didn't know how cookies work, what they are good for, what they are bad for and whatever they try to outlaw now gets correlated via different means. User-agent, ip and some other browser fingerprinting.
So bottomline, we have to click once more (or every time, when private/incognito mode) when you visit a site.
The regulators are very aware of it, that's why the law doesn't say anything about cookies. You'd know that if you cared to read it. It's only been 6 years, and the law can be read in it's entirety in an afternoon or less. So I see why the task of actually learning anything about GDPR beyond what the industry tells you to seems insurmountable to most IT people.
BTW I do not use much websites with that banners because they are for idiots. Good forums and torrent trackers don't have that because there will be always an anark spirit on the Internets, no matter how severe the censorship is going to be. And this part of the Internets is really better part than the opposite one.
Cookie banners are not a part of GDPR. Especially not the common dark-pattern-riddled "we sell your info to thousands of companies" ones
There was the Do Not Track header. That the industry you're defending immediately used to fingerprint and track people
> This is a perfect example of government overreach done wrong.
The law doesn't say anything about cookie banners. The blame for them lies squarely with the great amazing privacy-preserving and customer-loving industry of ours.
Cookies should be a client thing, browsers should forget them once the tab/window is closed by default, and there should be a button by the url bar to remember cookies for that domain. EU should mandate the default settings in preinstalled browsers on all devices sold in eu, and that would solve 99% of the problem.
It used to be, you open a website, you can view the content. Now it's more like you open a website, get an overlay popup, take 30 seconds to solve the dark pattern logic puzzle of disabling tracking, then you view the content. Every. Single. Time.