The regulation doesn't mention cookie popups. The easiest way to comply is to not collect nor store any such information.
Utopia is just around the corner as long as everyone does exactly as I say rather than being driven by self interest.
Relying on self-interest is Laissez-faire, that had the result of (1) the invention of communism and (2) basically ended even in the US with the Great Depression.
Communism kinda had the same problem, as it made false assumptions about human nature and self-interest.
If you're a site that has even basic analytics reporting requirements, how do you do any of that without?
"Don't do these things" is a decent option for sole traders, microbusiness and hobby website operators, but good luck selling that to anyone "in a suit" (more likely $500 jeans or chinos nowadays).
At least based on the so called cookie law. There is also GDPR, but you'd typically agree to that on signing up, not on accessing the site.
Once again, there is no law requiring cookie popups. Gathering data fairly and transparently (e.g. login credentials) is perfectly fine. However if you wish to pass my data to third parties to track me (advertisers take a bow) then you need my explicit opt-in permission to do so. And so you should.
This isn't difficult to understand and has been law in the UK and EU for quite some time now.
Explanation is here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
If your analytics are anonymous, as they should be, you don't need a cookie, nor a consent banner.
> How do you manage login sessions without?
You don't need to ask for consent for that, because it's a necessary requirement for functionality.
I think with few exceptions, most web admins just want to get the cookie notice sh*t out of the way and get on with work that matters.
If you're talking about GDPR, then it regulates that businesses have to have reason to store and process PII. I don't see a reason to be unhappy about that.
The regulation and its outcome was clearly not understood or intended by those who mandated it. Absolutely everyone is suffering from this.
As for the "not care", I think the primary issue is that most people don't make much effort to understand the things they use. If they understood what was going on, they would be more upset and possibly make some effort to get things changed/reverted.
I would put a bit of blame on big corporations for not spending some of their lobbying money on fighting this requirement - not because they should get a free pass at misusing our info, but because they should be well equipped to know that the regulation will be addressed in a crappy way that costs them money and annoys users.
There seems to be a nuance missing here in most of this discussion.
The obnoxious cookie popups is the industry's malicious and calculated response.
The obnoxious cookie popups is the industry's malicious and calculated response.
This is a good sibling comment about this: https://news.ycombinator.com/item?id=41576346