Almost. It hardly worked as intended, but at least it increased awareness. The fact that some sites tried to comply and actually provided a full list of all sites that they sell your private data to is somewhat a win. It got to a lot of wider public that realized "they sell it to 97 companies?!".
I personally think local governments or EU wide institutions should have a registry of companies and their sites with ratings, so we could integrate that directly in our browsers, company registries, phone dialer apps. iFixIt style.
- Clarity of EULA: 1/10, impossible to understand without lawyer's interpretation.
- Length of EULA: 1/10, pops up every week with no diff or summary of changes
- Legality: 4/10, historical track record of rules that are not compliant with local laws of xxx
- History: 1/10, no way to track what were the previous versions of the document or when they changed
- ...
EDIT: to give some context and prove it's possible to provide metrics to legal documents, in Poland we have a formal "Registry of Forbidden Clauses" with references to lost court cases:
Alternatively: Only allow the website to set cookies if it presents headers with the different options, in a standardized way so the user can chose to pre-set a preference and not be bothered with the cookie nag modal.
Tracking is plainly not permitted without consent.
According to some poorly thought out law in certain territories, sure.
In practice, however, there is no technical mechanism by which users, or anyone else for that matter, can detect whether they're being tracked or consent to it. There are browser extensions conscious users can install to block certain browser features, but these are not infallible, and they're constantly playing a cat and mouse game with trackers.
The cookie policy only applies for cookies, not for general tracking. And even with it, companies loophole their way by claiming "legitimate interest". Many popular websites show cookie consent forms with upwards of a thousand of these companies, and deliberately use dark patterns to make it impossible to deny all of them. It's absolute insanity.
But in general, cookies are a red herring. They're used as sacrificial offering aimed at governments and the public to show that a company really cares about user privacy by not using them. When in reality they've been relying on far more sophisticated tracking methods for many years which are technically impossible for the public to even comprehend.
And let's not forget about the shady data broker market, where our data is perpetually transacted against our will or knowledge, let alone benefit.
We need far more technical experts in governments to pass strict regulation against this nonsense, in a way that it actually benefits the public. But I'm not holding my breath that this will ever happen, considering the corporatocracy we're living in.
sigh There is the law.
The law that legitimate companies obey.
Such data protection law means I can trust my bank will not track me and provide my personal data (all the booze and fags I've spent money on) to my insurance company, and my insurance company cannot accept such data gathered 'unfairly'.
The only people who object to such data protection laws are scummy tech companies who haven't yet understood unnecessary personal data is now a liability, not an asset.
No. It isn't a "cookie policy".
The GDPR states I must give a specific opt-in approval to provide my personal data and allow it to be passed on.
You can use as many cookies as you like, but if you want to track me personally (advertisers take a bow) then you need my specific consent to do so. And so you should.
I'm amazed I have to keep explaining this to American web designers who should know better. This has been law in the UK and EU for quite some time now and is a prerequisite to doing business here.
The GDPR is a bloody good law. It makes the gathering of unnecessary personal data a liability, as it should be. See here: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...
Fail to see how it’s value-signalling ...
GDPR isn't about cookies, or browsers.
However, we have codecamp graduates gluing left-pad modules together until something works instead of engineers building websites and it shows.
If this is the case, you need to re-asses both your work culture and 'belief' in what Google is telling you.