Please stop putting cookie pop-ups on your website (2022)
olivergrimsley.com
olivergrimsley.com
I fail to understand companies that display page after page of cookies and tracking stuff for you to approve don't see the issue with their actions or the insanity of "allow us to share data with our 1500 partners". Does no one in these business look at this and go: "Hey, why do we need 50 different tracking tools" or "Why do we share customer data with over a thousand other businesses?".
When you actually read what these pop-ups says, then you understand why they are there, and why the problem with the laws isn't that it's annoying, but that it is not much more restrictive.
Targeting advertising is sooo much more effective for small and medium sized businesses and actually makes many businesses viable in a way they weren’t in the past.
The ideal solution would be to find a way for businesses to get those insights in a way that preserves privacy at the individual level. Something like apples differential privacy system but web wide.
I'm starting to question that, but without any proof that just me rambling. Assuming that it works, I'd actually be fine with a site saying "Hey, just letting you know, we use Google Analytics to learn more about you, is that cool?".
The 1500 partners and 50+ trackers aren't numbers I'm making up, those are numbers I frequently see. Sure, you feel you need a tracker, I can easily enough say no to a single tracker. I can also understand a webshop needing to share information with their advertising partner, but not 1500 of them.
The law would never have amounted to anything if the reality was a limited scope of data sharing with a clear obvious purpose. It's the insane amount of tracking and data sharing that triggered all this.
As usual it’s the extreme ends of the spectrum that ruin for everyone.
Retargeting did very little. Ads helps in some cases, but rarely generic ads, it had to be extremely targeted, which was normally done by manually buying ad space with certain TV programs or in specific locations. The big ones for us was price comparison sites, if we could get on HotUKDeals we'd have a great week, but in particular Google Shopping did made a big difference.
Isn’t that what Mozilla and Meta are together experimenting with?
So much user time is spent, for example, on a few big sites which have enough data within their own siloes (based on users' behaviour and topics of interest), they can target pretty well without relying on external data. The big video sites, social media, Amazon/eBay/etc.
And then there's a big layer of smaller sites who can inherently target because they're already specialist in nature.
The losers in this scenario aren't really the brands, they're big generic sites such as news media who don't have any way to acquire targeting information on their own.
Nobody is stopping anybody from advertising or marketing. Simply that if your advertisers wish to track me, then they must ask my specific opt-in permission to do so. And so they should.
If your business cannot survive without illegally (!) tracking and trading in personal data, then you have a scummy business model and a business that has no right to exist.
Yes you are!
The GDPR prohibits conditioning the provision of service on consent to the processing of personal data. Thus mandating acceptance of advertisers tracking cookies ("cookie walls") without providing alternative means of website access are considered violations of the GDPR.
Charge people money up front if you require payment. My attention and personal information are not currencies to pay for services with.
It's not like a news site is selecting and managing 1500 different partners individually.
I can only imagine the disbelief and laughter in court if a thief said "Your honour, it's not like I stole one car, I actually stole 1500 different ones"!
I wished that such statements had some value greater than nil.
Worse, people (including on HN) actively blaming the EU for it. It’s like having a law mandating people are informed when there’s poison in their drink, then seeing people complain about the warning labels everywhere. The label isn’t the problem! As you said, if anything the issue is that the law isn’t aggressive enough.
The EU is exactly to blame for it.
The activity isn't illegal, and the EU didn't make it illegal.
What the *EU did* was make it so that companies engaging in that legal activity now had to disclose it in some way, and thee cookie popups are the best way to do that.
It's ridiculous to try and say the EU isn't to blame when they introduced and approved the legislation directly responsible for the popups.
Industry: we hear you. Here's "informed consent" form riddled with dark patterns because we believe that all data is ours by God's decree, and our 15 000 "partners" agree with us
...
HN: The EU is to blame for this
Cookies, on the other hand... Even for me, who was perfectly aware of the problem long before this legislation, and who was privacy-oriented to begin with, it isn't clear, what's the consent I'm giving. First off, I know everybody uses cookies, and almost everybody uses some trackers. Second, even me, somewhat informed user, I don't really understand, what is that information they are sharing with third parties, and why should I care. I feel kinda stupid when I bother to press "reject all". Like, does it even matter, what I choose? Wouldn't they do it anyway, whatever they do? Then, I use ublock and I hope it helps. If it doesn't, well, tough luck, but what do I do? I do want to read that one paragraph from the medium/NYT article I found on Google, despite how much I hate them. I won't stop using the internet because of... whatever this is.
I can only imagine, what it's like for average user, who is, let's be honest, pretty clueless. I guess for them it is indeed the EU who is too blame here.
GDPR is more useful, but still I'm not sure if it really helps. Like, I remember someone complaining that before GDPR you could bulk-download gpx files from Strava, and now you can only request .fit files, that are supposed to containt more data, but really aren't that useful for most. Well, it's not GDPR you should blame, it's Strava and all their partners/competitors (especially Garmin, god I hate them so much). They are successfully making life harder for you, because they don't want it to be easy to get your own data back. And who is to stop them? Maybe it's a matter of time, I don't know, but it doesn't seem GDPR is effectively enforcing what it is supposed to.
I’ll leave you with two links. The first explains which kinds of cookies do not require consent. You’ll see the list is pretty reasonable. The second is to noyb, a non-profit fighting for privacy (the name means “none of your business”), who has been doing good work thanks to the GDPR.
https://commission.europa.eu/resources-partners/europa-web-g...
Indeed, and that's exactly what the industry wants. Show me where exactly GDPR mandates the cookie dialogues. Or ePrivacy Directive for that matter.
> Well, it's not GDPR you should blame, it's Strava and all their partners/competitors
Yes. And yet you somehow twist it to blame GDPR
> but it doesn't seem GDPR is effectively enforcing what it is supposed to.
Yea. Enforcement has been sadly lacking
> Make a good product that does not rely on exploiting user data. Advertise in relevant locations without tracking (e.g. if you sell cars, advertise on a car-centric website/forum/magazine).
No, none of this is a light pattern. It's just abstaining from the activity entirely.
Exactly what you say here:
> the two times I replied to you responding to someone else
---
> Honestly I didn’t even realise I was replying to the same person.
I find that very odd, not to pay attention to who you are replying to, but OK.
> quite the persecution complex.
Nah. It's a pretty common behavior or 'pattern' that some people who feel strongly about a position will reply to other child comments by a person they are debating with.
I find it frustrating because it normally leads to a lot of redundancy, with the same points being repeated in multiple places, just wasting time.
I mistakenly thought that's what you were doing. I apologize.
If an activity is explicitly legal, even with regulations, then there should be a light pattern for that activity is there is a dark pattern.
Look at selling cigarettes in the 80s. A dark pattern would be trying to influence kids on the low, which mascots like Joe Camel.
A light pattern would not be abstaining from selling cigarettes entirely, analogous to what you suggest, but rather voluntarily adding labels to packaging and taking other precautions.
What's not right? Giving up pervasive and invasive tracking and selling user data?
> but rather voluntarily adding labels to packaging and taking other precautions.
GDPR, literally, is: if you use data not strictly required for the functioning of your business, ask user for consent.
How is this not a "light pattern"?
Exactly. Abstaining isn't a light pattern. A light pattern would be doing the thing in a non malicious way.
> GDPR, literally, is: if you use data not strictly required for the functioning of your business, ask user for consent.
You're missing the point. You were alleging businesses are using dark patterns while being in compliance with the law. I'm asking what a light pattern would be for collecting as much data as possible which is an explicitly legal activity as long as the regulations are followed.
You answered not engaging in that activity at all, which is not an answer.
"Abstaining from selling hard drugs to minors isn't a light pattern. Show me how we can sell hard drugs to minors even with all the regulations in place"
Though I hate analogies, but this is what this sounds like to me.
> I'm asking what a light pattern would be for collecting as much data as possible which is an explicitly legal activity as long as the regulations are followed.
You either follow GDPR or do not engage in this activity. What is so hard to understand?
Instead the industry came up with the obnoxious cookie banners tricking users into providing any and all data and selling that data to thousands of "partners".
The difference though is that selling drugs to kids is flat out illegal, no ifs ands or buts.
Data collection is explicitly legal as long as regulations are followed, so I think it's a flawed analogy.
> What is so hard to understand?
That the businesses are complying with the GDPR but you're still saying it's a dark pattern and complaining about what they are doing.
I need to remind you at this point the topic of discussion is who is responsible for the cookie popups, not the morality or legality of the activity that the EU felt required regulation. The answer is the EU, because that's how they chose to address the issue.
> Instead the industry came up with the obnoxious cookie banners tricking users into providing any and all data and selling that data to thousands of "partners".
Most cookie banners are not deceptive at all. They are the result of complying with the legislation the EU mandated.
In fact, the cookie banners that are as straightforward and clear as possible, and as non intrusive as possible, are an example of a light pattern in this context.
Oh, right, nobody is going to use that page. So, is it really the EU fault for the cookie popup, which is a dark pattern?
No, the best way to do it is not invade people’s privacy. You can have ads without targeting (we did it forever before the internet) and you do not need cookie warnings if your cookies aren’t invasive.
https://commission.europa.eu/resources-partners/europa-web-g...
> The activity isn't illegal, and the EU didn't make it illegal.
Indeed that is a shame. If only.
You are deliberately missing the point and shifting the goalposts.
You're talking about asking a business voluntarily not engage in lucrative legal business activities. Why would they do that? There are so many more important things business should voluntarily abstain from by that reasoning.
No, as long as the behavior remains legal, a business has every right to engage in such activity.
The only reason the cookie popups are a thing is because the **EU** mandated some sort of notification which basically mapped to these popups.
So it's the EU to lame. No question about it. A business engaging in legal activity is not to blame, since it's the regulations around that activity and not the businesses practicing the activity that are the topic of discussion here.
Stop shifting the buck. It's so incredibly dishonest.
It is baffling that you can make that claim without realising your mistake. Yes indeed, why would businesses do that voluntarily? The answer is they aren’t doing it voluntarily, they are forced by law. In other words, the EU has made the practice illegal. Specifically, it is illegal to engage in that data collection without consent.
Let’s take tobacco warning labels as another example. Governments decided that tobacco companies have to print large warnings on cigarette packs. They didn’t make it illegal to sell tobacco, but if you want to do it you have to include those labels.
https://www.fda.gov/tobacco-products/labeling-and-warning-st...
Do you also blame governments for mandating those warning labels and would prefer there to be none? I mean, you do you, but please don’t accuse others of goal shifting and dishonesty simply because you misunderstood an argument. My position has remained consistent, I gave the poison example (which you chose to ignore) in the first post.
I'm not making any mistake. You continue to make the mistake to blame the businesses doing *legal* activities and complying with the *EU Regulation* that dictates the cookie popups.
> The answer is they aren’t doing it voluntarily,
They are not abstaining from legal behavior that makes them money, like literally every other business in acceptance.
Which means they are not doing anything remarkable, yet you are remarking on it. Why?
> In other words, the EU has made the practice illegal.
Not exactly. The EU has very specifically made the practice legal, but with regulations.
You're doing the equivalent of blaming tobacco companies for including graphic warnings on their packaging as is the case in some countries, when it's not them doing it voluntarily, it's a result of those governments imposing it.
> Specifically, it is illegal to engage in that data collection without consent.
Exactly. The *EU* regulated that informed consent is required, requiring some kind of popup to the user.
So, those companies are engaging in an explicitly legal practice, and doing so in the way the *EU* forces them to do so. So EU gets the blame.
> Let’s take tobacco warning labels as another example. Governments decided that tobacco companies have to print large warnings on cigarette packs. They didn’t make it illegal to sell tobacco, but if you want to do it you have to include those labels.
I genuinely typed my analogy above before I read this part of your reply. Amazing.
> Do you also blame governments for mandating those warning labels
YES!
Those warnings only exist because the governments are imposing them as a requirement.
Seriously, what's not to get here? If we follow your reasoning on the popups, to be consistent you would blame the tobacco companies for those warnings existing.
> simply because you misunderstood an argument.
What is it you think I've misunderstood? What do you think I think your position is as opposed to what it actually is? I'm certain I haven't misunderstood a thing.
What is the subject of the blame you were implicitly referring to in your first comment where you say "Worse, people (including on HN) actively blaming the EU for it."
What is the 'it' your refer to, if not the cookie popups?
> My position has remained consistent
Yes, your position is that the popups are not to be credited to the EU, which is absolutely wrong. They only exist because the EU dictates they need to for companies engaging in a specific legal activity.
You say in your first post "The label isn’t the problem! ", but that's the topic of discussion, that's the subject of the blame we are debating how to assign.
The issue of companies data collection and distribution practices are worth discussing, any any illegal activity needs to be dealt with. But that isn't relevant to who gets the blame/credit for the popups.
Businesses can make a separate page, a settings page, where you enable tracking. This solves the problem.
But obviously the cookie popup is HUGE to cover your view of the page and it's as confusing as possible, even with the requirement of an explicit reject all button.
This is textbook malicious compliance, and the EU has been trying to combat it (the explicit reject all button), but I suspect they don't want to codify in law the exact pattern they want to see (law becomes outdated)
I don't think I am, because even if the cookie popups were made with the genuine best intentions to adhere to the regulations, no malicious compliance at all, the people I am disagreeing with would still blame the corporations engaging in legal activity and not the regulations themselves that dictate the popups.
I don't doubt malicious compliance exists or is a problem, but I don't think it makes much of a difference in this context.
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
I really wish people made a minimum of effort to engage in good faith. It took you longer to post your comment than it would’ve taken to read that notice.
Or, to be fair to all parties, they are there because continuous abuse by the industry forced governmental action.
Don’t invade user’s privacy and you don’t need cookie banners. Can’t get simpler than that.
https://commission.europa.eu/resources-partners/europa-web-g...
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
Let’s please engage in good-faith conversation. If you don’t read a prominent explanatory banner with a blocky information icon at the top of an explanatory page, I don’t know what to tell you.
> Don’t invade user’s privacy and you don’t need cookie banners.
But when it's pointed out all EU websites use cookie banners, you shift goalposts and pretend that others are engaging in bad faith.
Because you keep failing to read properly (and even had one comment flagged on the same subject), I’ll emphasise it this time:
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
Again:
> regardless of the cookies used
In case you still don’t understand, that means it doesn’t matter what type of cookies the EU websites use, they still have to show the banner even for cookies no one else has to show a banner for.
Why does the European Parliament[0] and virtually[1] every EU website[2] feel the need to poison drinks?
> The label isn’t the problem!
The label is useless. See also, California's Prop 65: https://en.wikipedia.org/wiki/California_Proposition_65_list...
1: https://www.europarl.europa.eu/portal/en
Why? It's legal and extremely lucrative.
If it's really an issue, maybe the EU could actually limit these activities instead of just forcing sites to put a notification that they are attempting to engage in those activities?
The UK and EU do limit those activities. They remain entirely legal providing you get explicit opt-in consent.
Neither, you just somehow misinterpreted my comment.
> The UK and EU do limit those activities. They remain entirely legal providing you get explicit opt-in consent.
The point is that they do not limit them sufficiently, clearly. People who complain about the popups want to blame the businesses, but the business are doing in compliance with the law.
That's the point. So blaming the business for the popups doesn't make sense, because the popups are a result of EU regulation, not the businesses doing anything wrong. Because as you say, the EU limits those activities and allows those businesses to do as they do.
I agree. The law should’ve been stronger. But we work now with the hand we have.
> People who complain about the popups want to blame the businesses
Not in my experience. There’s a split between people blaming the business and blaming the EU.
> but the business are doing in compliance with the law.
Most aren’t. The GDPR says explicitly that withdrawing consent must be at least as easy as giving it. Yet most popular websites make it incredibly simple to accept but obtuse to refuse.
However, you may have noticed that’s starting to get better. More and more websites have a clear way to reject now. Meta (Facebook / Instagram) in particular are now way clearer than at the start. We have to thank organisations such as noyb¹ for that. They have been tireless in that fight and won a number of high-profile cases.
I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit. I have to see it that way because blaming the businesses for engaging in a legal activity and doing something mandated by regulation is crazy to me.
> Most aren’t. The GDPR says explicitly that withdrawing consent must be at least as easy as giving it. Yet most popular websites make it incredibly simple to accept but obtuse to refuse.
Most popups have two buttons, accept or reject. It doesn't really get simpler than that.
That’s absurd. By that logic Europeans would also have defended Chat Control, but that wasn’t the case. A person doesn’t become a blind zealot because they think differently from you.
> I have to see it that way
No, you choose to see it that way.
> blaming the businesses for engaging in a legal activity
Perhaps you’re too attached to the rule of law. Being legal does not mean being right, moral, or generally good. Slavery was legal at one point and then it wasn’t. Lead paint was legal and then it wasn’t. Those things weren’t good when they were legal. Companies knowingly engage in harmful legal behaviours every day.
https://www.sydney.edu.au/news-opinion/news/2024/05/02/how-c...
https://www.decof.com/documents/dangerous-products.pdf
> Most popups have two buttons, accept or reject. It doesn't really get simpler than that.
I addressed that in the previous comment. That’s becoming more common now, after years of fighting malicious compliance. Again, thank noyb and organisations like it.
It's hardly absurd, it's a common pattern in nations and online rhetoric.
> By that logic Europeans would also have defended Chat Control, but that wasn’t the case.
Just because people may defend one thing out of tribalism doesn't mean they would defend everything out of tribalism.
It's specifically EU users on HN I see trying ti shift the blame to corporations. I find it bizarre, honestly. Correlation isn't causation but in this case I do think there's a link.
> No, you choose to see it that way.
Meh. I believe it's a reasonable position backed by evidence.
> Being legal does not mean being right, moral, or generally good.
Yeah, this has nothing to do with the actual root point being discussed though, which is which entity gets the blame/credit for the popups.
That's the EU, no question. You don't like the data collection practices or consider them immoral? That's fair and reasonable, and we can talk about that, but it's a separate albeit adjacent issue.
> Slavery was legal at one point and then it wasn’t.
This is why you shift the goalposts. Now you're talking about slavery. The original point you made in this thread and the topic being discussed are the popups, regulation of an activity not the activity itself.
Slavery is not analogues to popups. An analogy involving slavery would be if there were government mandate signage every 100 feet in town centers advising slaves are people and should be treated humanely (which obviously didn't happen, but it's hard to twist such a bad faith example to still make a point).
> That’s becoming more common now,
It's been common, i.e. the norm, since the laws came into effect.
You keep saying that. How do you know? Even if you looked at the profile of everyone you interacted with, I doubt you’d be able to ascertain nationality.
> I find it bizarre, honestly.
And I find it bizarre that someone would kowtow to corporations purposefully exploiting them, but I’m not going to pretend to know where those people live and accuse them of tribalism.
> This is why you shift the goalposts.
I’m not sure you understand what an example is. They are made so we can find a common ground on a subject and discuss the merits of an idea, not to change the subject. They are often employed when agreement is hard to reach on some specific matter and are meant to bring a more general concept into light so both parties can understand where the root of the disagreement comes from.
> It's been common, i.e. the norm, since the laws came into effect.
You are wildly misinformed. If they had been the norm, there wouldn’t have been so many cases of complaints and organisations created specifically to combat those.
But I don’t think continuing to converse with you is a good use of anyone’s time. There’s no point in discussing when the other party is already locked in a predetermined belief that whoever disagrees with them is doing so out of tribalism.
Because I find the position not to blame the EU so baffling and irrational that I was curious about the people who advocate that position. The first few times I checked the profiles it was very clearly EU users. I kept checking, while being very aware of and cautious of falling prey to confirmation bias, yet the same pattern kept holding.
> Even if you looked at the profile of everyone you interacted with, I doubt you’d be able to ascertain nationality.
Enough EU users freely comment in their history that they are in the EU somewhere, because enough threads come up where it's relevant. It's really not that hard to ascertain nationality of HN profiles with activity at all.
> And I find it bizarre that someone would kowtow to corporations purposefully exploiting them,
No one is doing that in a context relevant to this thread. It's literally a red herring.
The issue to who gets the blame/credit for the cookie popups. That's it.
> I’m not sure you understand what an example is.
It's been so hard for me to bite my tongue and withhold snark due to your positions, and yet here you give in to the temptation freely. Kind of frustrating. Please remember the HN guidelines.
> They are made so we can find a common ground on a subject and discuss the merits of an idea, not to change the subject.
Exactly, but to use an analogy you're discussing how people speeding are a problem while everyone else is complaining about the sirens of a police unit specifically to catch speeders are too loud.
Your position is a red herring. You keep talking about the immoral yet explicitly legal practices of these companies, and it's entirely irrelevant. As long as those companies are engaging in legal activities, then the blame for how they engage with them goes to the regulators.
I did a search for “moral” in this thread’s history. I matched exactly once (twice with this one). That’s not “keep talking about”, that’s one mention. Even then it was a general point of not conflating legality with morality, it was not specific to this practice.
You’re ascribing preconceived notions from the straw man in your head, not my words. I thus point you to those same HN guidelines (I agree they are quite good).
> As long as those companies are engaging in legal activities, then the blame for how they engage with them goes to the regulators.
This, right there, encompasses the whole nature of our disagreement. This law prescribes several ways to comply and not be annoying to people. Thus if a company complies in an annoying way, it’s on them. It’s absurd to say that the blame for how you engage with a rules is on regulators. The text of the rule is on regulators, how someone engages with that text is on them.
Well that's the wrong approach. I didn't say you kept using the exact word 'immoral', I said you were talking about the "immoral yet explicitly legal practices". That doesn't mean you are using the same exact words I used generalize your various comments and position.
> That’s not “keep talking about”, that’s one mention.
No, it is “keep talking about”, because in every comment discussing who is responsible for the cookie banners, you refer to the activities that are being regulated, rather than the regulation which is what is actually relevant.
> You’re ascribing preconceived notions from the straw man in your head, not my words.
No, no strawman. Every time you try to shift the buck to blaming the companies and not the regulation, and that's what I'm responding to and calling out.
> I thus point you to those same HN guidelines
Out of a petty attempt to do so after I did it because of your snark? I haven't violated the guidelines in any of my replies, and there is no strawman here. I'm addressing your arguments and your arguments only.
> This law prescribes several ways to comply and not be annoying to people.
What method do you propose companies that want to engage in the explicitly legal activity of data collection as long as user consent is obtained obtain that user account? In a method less annoying than a cookie banner?
If you again suggest they just abstain from the explicitly legal activity of data collection as long as user consent is obtained, then you would again be trying to shift the goalposts.
> Thus if a company complies in an annoying way, it’s on them.
So what's the less annoying way than a cookie banner at the bottom of the screen to obtain consent, that doesn't rely on the goodness of the hearts of people running the corporations (because that would very surely be a very naive outlook to think that was realistic)?
> The text of the rule is on regulators, how someone engages with that text is on them.
Sure, and the cookie banners are pretty much the least annoying approach that is compliant with the regulation.
Don't take the piss!
It's about a _GENERAL_ data protection act that prevents companies and jobsworths having free rein to your personal data. This has sweet FA to do with patriotism as you know perfectly well.
> It's about a _GENERAL_ data protection act that prevents companies and jobsworths having free rein to your personal data.
The context here is limited to assigning blame/credit for the cookie popups.
> This has sweet FA to do with patriotism as you know perfectly well.
Tribalism then.
Goatcounter or Plausible will do fine. Some decent frontend log parsing will also be a viable strategy.
Stop feeding Google your customers data for free.
And marketeers want this data because sales data only tells them where they succeeded. Not where they failed to sell, which is more interesting to them because that's where the growth is found.
It'll be really hard to wean them off this.
No they can't. The US doesn't even let them decide whether to supply chip machines to China. Or for Schiphol Airport to reduce slots for noise abatement. the US immediately trumped up diplomacy and raised threats to stop those things.
Banning google analytics is just unthinkable in the current relationship between EU and US. I agree they are a predatory company but this is unfortunately how things are right now in the balance of power.
If enough people do it, it will have an effect. Remember when Apple pulled the advertiser ID unless users opted in? That really got the ad industry barking. That they feel. Ad Nauseam they don't. It's way too fringey.
For companies doing this the right way, the banner was just the tip of the iceberg, loads of work went into ensuring compliance behind the scenes, so customer and employee data was not shared with 3rd parties unknowingly. In one case the list of 3rd parties went from +400 to about 70, this is in my opinion a win for privacy, the culture around sharing your data went from casual to cautious.
Secondly, the culture around trusting meta and google blindly with behaviour data changed drastically. Businesses became aware of how much valuable data they share with these platforms, which actually puts them at great risk, should you really give these platforms detailed data on what customers browse and buy on your site, so they can use the data to sell targeting for competitors, or direct users towards their own shopping platforms?
So, yes the law is not perfect, we all hate the banners, but at least what happened in those early implementation days when the banner became law, was a change in culture around how data was shared and a better understanding of the risk for the business of using 3rd parties.
Almost. It hardly worked as intended, but at least it increased awareness. The fact that some sites tried to comply and actually provided a full list of all sites that they sell your private data to is somewhat a win. It got to a lot of wider public that realized "they sell it to 97 companies?!".
I personally think local governments or EU wide institutions should have a registry of companies and their sites with ratings, so we could integrate that directly in our browsers, company registries, phone dialer apps. iFixIt style.
- Clarity of EULA: 1/10, impossible to understand without lawyer's interpretation.
- Length of EULA: 1/10, pops up every week with no diff or summary of changes
- Legality: 4/10, historical track record of rules that are not compliant with local laws of xxx
- History: 1/10, no way to track what were the previous versions of the document or when they changed
- ...
EDIT: to give some context and prove it's possible to provide metrics to legal documents, in Poland we have a formal "Registry of Forbidden Clauses" with references to lost court cases:
Tracking is plainly not permitted without consent.
According to some poorly thought out law in certain territories, sure.
In practice, however, there is no technical mechanism by which users, or anyone else for that matter, can detect whether they're being tracked or consent to it. There are browser extensions conscious users can install to block certain browser features, but these are not infallible, and they're constantly playing a cat and mouse game with trackers.
The cookie policy only applies for cookies, not for general tracking. And even with it, companies loophole their way by claiming "legitimate interest". Many popular websites show cookie consent forms with upwards of a thousand of these companies, and deliberately use dark patterns to make it impossible to deny all of them. It's absolute insanity.
But in general, cookies are a red herring. They're used as sacrificial offering aimed at governments and the public to show that a company really cares about user privacy by not using them. When in reality they've been relying on far more sophisticated tracking methods for many years which are technically impossible for the public to even comprehend.
And let's not forget about the shady data broker market, where our data is perpetually transacted against our will or knowledge, let alone benefit.
We need far more technical experts in governments to pass strict regulation against this nonsense, in a way that it actually benefits the public. But I'm not holding my breath that this will ever happen, considering the corporatocracy we're living in.
sigh There is the law.
The law that legitimate companies obey.
Such data protection law means I can trust my bank will not track me and provide my personal data (all the booze and fags I've spent money on) to my insurance company, and my insurance company cannot accept such data gathered 'unfairly'.
The only people who object to such data protection laws are scummy tech companies who haven't yet understood unnecessary personal data is now a liability, not an asset.
Alternatively: Only allow the website to set cookies if it presents headers with the different options, in a standardized way so the user can chose to pre-set a preference and not be bothered with the cookie nag modal.
However, we have codecamp graduates gluing left-pad modules together until something works instead of engineers building websites and it shows.
If this is the case, you need to re-asses both your work culture and 'belief' in what Google is telling you.
GDPR isn't about cookies, or browsers.
No. It isn't a "cookie policy".
The GDPR states I must give a specific opt-in approval to provide my personal data and allow it to be passed on.
You can use as many cookies as you like, but if you want to track me personally (advertisers take a bow) then you need my specific consent to do so. And so you should.
I'm amazed I have to keep explaining this to American web designers who should know better. This has been law in the UK and EU for quite some time now and is a prerequisite to doing business here.
The GDPR is a bloody good law. It makes the gathering of unnecessary personal data a liability, as it should be. See here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
Fail to see how it’s value-signalling ...
Of course, people either aren't willing or can't. Them's the breaks.
To add, there are estimations about how much ad money average user generates and it's very much affordable
to be fair that is the choice. And ideally, the invisible hand would show that this is a horrible idea and cause a huge spike in traffic, but alas.
I think "stop putting popups cookies" on websites is an extreme stance, but I agree we could use fine tuning on the little things to help keep the spirit of the law. It should indeed be opt-in and not "ask for forgiveness". And it should adhere to current compliances.
While this ruling does not specifically only use the ePrivacy directive (it is instead based in GDPR), laws do not exist in a vacuum.
"Configure my preferences" -> Untick all the things -> Make sure you click the almost invisible Save button and not accidentally click the big green "Allow All" button.
Horrible. If we can force websites to do this, we should be able to force websites to read my request header NoDamnTrackingCookiesFfs
However they are very bad at enforcing it, sadly.
There's no upsides for a website from providing an easy "Never track me" button, or just not using analytics cookies - you don't have to put up cookie consent banners for technical cookies used to save e.g. light/dark mode preference
How is such a banner even supposed to work when there is no choice for the user to make?
I mean, someone has to make that banner, so it's quite a way from the rash decision to its execution, where at any point (preferrably immediately) someone could and should step in and say "we are not required to do that and we should not spend any money on it". In my experience, non technical deciders are often sadly under-advised, sometimes because tech people who might know better fail to communicate even very simple facts like in these in an understandable way.
This is indeed the obvious solution. I don't understand why the EU didn't mandate the do not track flag to be obeyed. I know some browsers already removed it but that was because nobody bothered to obey it. As soon as it can be mandated it will be useful and come back quickly.
Also, there was criticism from the advertising industry that the do not track was on by default but that's how tracking should work in the EU anyway: opt in.
By not doing this the EU keeps getting flak for the many cookie walls.
1. Because the implementation is simply left open?
2. Because it's nearly impossible to verify?
Point 2: you can't check/verify if parties, especially those outside the jurisdiction of the EU, really honor things like the 'don't track' flag.
It's unfortunate that so many companies decide to implement the requirements in the laziest and sleaziest possible ways.
What do you mean verify? If it's set then it's set. It gets automatically injected with every web request. It's not possible to make sure the user manually set the flag or if it was default, no. But in the EU the law says that tracking must be opt-in so this is perfectly good behaviour in line with the law.
- Browsers would come with the no tracking signal enabled by default (why wouldn't they?) so that tracking would become opt-in.
- Nobody chooses to be tracked.
- The whole industry built on tracking users collapses, namely advertisement
- Web sites who based their business model on advertisement go under
Because of this I bet that the industry is lobbying extremely hard for solutions that are maximally useless and inconvenient for the user. Unless the user "chooses" to be tracked of course.
In that vein, another proposal for stemming the flood of cookie consent banners comes from the German government and outlines a multi vendor strategy with very little technical guidance for centralized consent management systems:
https://www.heise.de/en/news/Consent-management-German-gover...
> - Nobody chooses to be tracked.
> - The whole industry built on tracking users collapses, namely advertisement
> - Web sites who based their business model on advertisement go under
This seems like the perfect outcome to me, but I doubt we'll be this lucky
Companies like Google and Meta would lose their huge moat because they're the only ones with the kind of pervasive tracking network that make tracked ads viable. They no longer have a big advantage over smaller ad players. And them losing their huge market position isn't a bad thing IMO.
I don't think ads would disappear, they would just become untracked. Neither would websites. They will find a way.
GDPR is a general regulation. It doesn't concern itself with browsers, or cookies. It's on industry to come up with a solution for specific technologies.
Oh, and for browsers they did. It's called the "Do Not Track" header, and the industry immediately sed it to fingerprint and track users.
> By not doing this the EU keeps getting flak for the many cookie walls.
No. It's the industry winning the PR wall. The EU never mandated the cookie walls. It's the industry's calculated malicious compliance.
Well, in the end the industry might end up with EU strictly regulating every single technical aspect of this, but then the industry will cry about government overreach or something.
They do this anyway. They should have mandated this be honoured (or any other type of tech). If that were the case the browsers would have brought it back in short order.
> The EU never mandated the cookie walls. It's the industry's calculated malicious compliance.
Exactly. And this is their fault for not regulating this properly.
GDPR mandates honoring user consent.
It's a general data protection regulation. It doesn't talk about specific technologies.
> this is their fault for not regulating this properly.
What "this". Should there be a separate law for browsers? And a separate law for mobile apps? And a separate law for desktop apps? And a separate law for offline businesses? And...
Or should we blame the people and industries who couldn't care less about user privacy?
Ublock just blocks the popup which breaks some sites that don't work until you make a choice, which you can't because it's blocked. The other plugin answers it for you in the background with your chosen options.
Wait, is it when you pull the page by moving your finger to the bottom of the screen and the “header” pops up?
No those are a different sign of design ineptitude.
They mean the popups that appear as you try to read what you followed the link for.
I'm afraid that these banners, because these are called "cookie banners" and not "consent to us using your data and giving it freely to other companies banners", will just go away, people (& companies) will be happy, and the consumer stays a fool.
It remains even if "cookies" were replaced with "smart dust tracked into your house by cyber-ants".
Unlike cookies.
The regulation doesn't mention cookie popups. The easiest way to comply is to not collect nor store any such information.
Utopia is just around the corner as long as everyone does exactly as I say rather than being driven by self interest.
Relying on self-interest is Laissez-faire, that had the result of (1) the invention of communism and (2) basically ended even in the US with the Great Depression.
Communism kinda had the same problem, as it made false assumptions about human nature and self-interest.
If you're a site that has even basic analytics reporting requirements, how do you do any of that without?
"Don't do these things" is a decent option for sole traders, microbusiness and hobby website operators, but good luck selling that to anyone "in a suit" (more likely $500 jeans or chinos nowadays).
At least based on the so called cookie law. There is also GDPR, but you'd typically agree to that on signing up, not on accessing the site.
Once again, there is no law requiring cookie popups. Gathering data fairly and transparently (e.g. login credentials) is perfectly fine. However if you wish to pass my data to third parties to track me (advertisers take a bow) then you need my explicit opt-in permission to do so. And so you should.
This isn't difficult to understand and has been law in the UK and EU for quite some time now.
Explanation is here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
If your analytics are anonymous, as they should be, you don't need a cookie, nor a consent banner.
> How do you manage login sessions without?
You don't need to ask for consent for that, because it's a necessary requirement for functionality.
I think with few exceptions, most web admins just want to get the cookie notice sh*t out of the way and get on with work that matters.
The regulation and its outcome was clearly not understood or intended by those who mandated it. Absolutely everyone is suffering from this.
As for the "not care", I think the primary issue is that most people don't make much effort to understand the things they use. If they understood what was going on, they would be more upset and possibly make some effort to get things changed/reverted.
I would put a bit of blame on big corporations for not spending some of their lobbying money on fighting this requirement - not because they should get a free pass at misusing our info, but because they should be well equipped to know that the regulation will be addressed in a crappy way that costs them money and annoys users.
There seems to be a nuance missing here in most of this discussion.
The obnoxious cookie popups is the industry's malicious and calculated response.
The obnoxious cookie popups is the industry's malicious and calculated response.
This is a good sibling comment about this: https://news.ycombinator.com/item?id=41576346
If you're talking about GDPR, then it regulates that businesses have to have reason to store and process PII. I don't see a reason to be unhappy about that.
I would really like to see these die. Regulators should just work with browser vendors to make an API that I can set at the browser level, and websites just read that to know my preferences and leave me alone.
Let me explain why with an example: say you're the type of people who doesn't care about "privacy" online ("I've got nothing to hide"), or you do; and you want to "support " certain ad-supported websites you're a fan of; but not that new clickbait toilet paper your aunt sends you.
I can't think of any way to have a good UX to opt in or out of "tracking" cookies which people would actually use (few will bother changing the defaults, and most mindlessly click ok).
And yes, it's mostly selling garbage, but that's hardly unique in 21st century capitalism.
Preferences should be expressible in any form a user seems fitting their needs. If they want to block-all,enable-per-site or enable-all,block-per-site, or block-mask, or enable-mask, or top-down rule priority list — they should be able to. Designing preferences in any other way is a dark pattern not worth considering as a fully user-controlled mechanism.
I can't think of any way to have a good UX to opt in or out of "tracking" cookies which people would actually use
Virtually any UX is better than cookie popups as they are now, cause they get designed with interests of a site owner in mind. This alone makes it the worst possible UX on average.
Most users are now giving explicit consent to be tracked! What a dream! Before, they had to worry about legal grey areas!
Now the legislation says it's fine, as long as they click "OK". Which almost every user does because they are tired and annoyed by the pop ups.
Thank you legislators!
Are there any tools to check websites to see that they do what they say they will do? Or is it a manual thing?
That's simply not true. In order for consent to be valid under GDPR, the service should operate normally if you decline tracing cookies. Otherwise it's considered a "forced consent" and is not valid.
Then you don't need cookie banners or gdpr consent popups. It is not that hard. But you want to screw your clients for profit, I know, in that case, you need them or get fined. Which you should be for misusing my information/behaviour and privacy. Nothing good did come of ad tracking, user fingerprinting and data selling, so I wish you many fines.
Under the GDPR sites are emphatically NOT allowed to deny service over rejecting cookies.
Iirc the only valid options are providing a paid alternative or blocking service to the entire class of GDPR covered citizens.
https://gdpr.eu/cookies/ # Cookie compliance
Both Europe and California consider IP addresses PII and this is the result.
2. You are allowed to legitimately process PII for legitimate purposes related to your business: e.g. combating fraud
3. What you emphatically aren't allowed without consent: collect vast amounts of data, store it indefinitely, and sell it to 15 000 third party "partners"
Here's the twist: Good news is (for me), I can[1] track and do whatever I want with any other IP address. You visit my site? Well, thanks to nobody else I care about having GDPR-like regulations in place, I can make sure I'll not only track you down and display ads across all advertiser networks, feed them your visit in all imaginable and unimaginable ways, but I can do it in such a targeted way that it's borderline scary. I can literally use any information you gave me on my websites, like your name, your location, proximity to anything. And if I can't then the advertiser can. And in the case of that particular lawsuit mentioned in the article, collecting all user consents, their IP addresses, and basically which websites they visited, its like a gold mine for advertisiers. If it isn't one yet, it can be turned into one with the click of a button.
It's like that one case a few years back, where a health insurance company bought a bank and started closing bank accounts from people they knew were risk patients.
Simply connect the dots...
GDPRs promise was to make it harder to do so. It wasn't the plan to annoy the hell out of everyone with banners. The whole idea was to not allow tracking unless you opted in, because quite frankly, its scary.
And no, I'm not a fan of GDPR or overregulation. But in reality, there hasn't been any tech I've come across that really protects the non-technical internet users at large. There's uBlock and plugins, but not installed by default or built into standard mobile browsers. Apple might be close for regular consumers to stop the excessive tracking and companies like FB really hates them for it (for good reason, it costs them big $$). Google will never shoot their own foot by integrating non-tracking tech into any of their products.
So, no, my opinion is don't stop that darn annoying cookie pop-ups unless you also stop the tracking. If you stop the tracking, remove the cookie pop-up. As easy as that.
[1] I don't do it, but I could. I'm not a reckless psycho-marketer.
An excellent point!
Websites can't know if someone is a citizen of country X, country Y, country Z, or even no country (indigenous people, sovereigns, legal constructs, AI's, international groups/associations, companies domiciled in space, other actors/legal constructs, present and future, etc., etc.)!
That is, they cannot know implicitly, without being explicitly given the appropriate information, if someone/something (non-human actors and/or legal reprentatives) accessing a website are citizens of a given country -- or not!
Now websites can do what many courts do, rightly or wrongly, and that is to presume an arbitrary citizenship/jurisdiction for a given website visitor (or visiting actor -- whatever is on the other side of that HTTP/S request)...
But will that be the correct presumption to make in all cases?
Probably not!
So perhaps the future needs a way for visitors to set in their browser (or by some other mechanism!) -- their citizenship and/or jurisdiction!
Of course, then we'd get into some weird scenarios like "what if website X in country Y decides to decline people who have set their browser to "I'm a citizen of country Z" -- sort of like the equivalent of a limiting country's physical immigration policy -- but for HTTP/S requests...
If the HTTP/S requests are not in the citizenship/jurisdiction of a whitelist specified by each website, then, "no HTTP/S response for you!" (Sort of like the HTTP/S version of Seinfeld's Soup Nazi -- "No soup for you -- come back in 1 year!" :-)).
Of course, the whole set of ideas I've outlined above, were they to come to fruition in the future -- sort of would violate the spirit of openness, trust, and good faith that was present in the early World Wide Web...
Remember that the early World Wide Web was built in such a way that all HTTP requests were answered with no need to provide a password or other credentials, no need to accept cookies (the early WWW / HTTP didn't have them!) and could be contrasted with FTP sites of the time which did require passwords (although many would be set to allow username "anonymous", password "anonymous" logins).
That is, the early WWW / HTTP -- was a passwordless, cookieless, loginless, "just give me the information", information-passing protocol, which in its earliest incarnations served academics (no one else had access to the Internet at that time!) who only wanted to share academic infomation (papers and the like!) with other academics, regardless of their country, jurisdiction, or their acceptance or rejection of any potentially access-limiting and resource denying cookie!
So, in conclusion, an excellent point!