Yes these are the worst thing to happen to the web in recent memory.
Yes these are the worst thing to happen to the web in recent memory.
They only need to ask for permission if they want consent for the kind of invasive tracking that the GDPR and related regulations were intended to discourage anyway. And they aren’t required to use popups or banners to get any consent they might need.
The popups, and especially the quite probably legally invalid common implementation where granting consent is made easier than refusing it, are a frequently bad-faith attempt by the industry to continue tracking-centric business as fully as possible contrary to the policy intention of the GDPR. They are not a requirement of the law.
Wow, talk about misunderstanding how that works. I hope it's not a company based within the EU because if they're so clueless about the regulations they have to follow, I'd be confident they're breaking a multitude of other laws (accidentally most likely).
Laws should not be written for spherical humans, they should be written for the real-world humans who actively circumvent laws where they can get away with it. And when legislation makes the world worse for everyone because it encourages self-interested individuals and companies to act in a way that is annoying or harmful, legislators don't get to dodge responsibility by saying that it's their fault and they should have just done the right thing.
We have laws precisely because people can't be counted on to do the right thing.
Not all of them; I don’t have an issue with requiring the use of one charging cable standard, but the privacy and user safety side effects of the legislated undermining of security cannot be ignored.
But I want to collect PII, because then I can sell it to a data broker for $$$ or €€€. So I will get the consent of my users, as requested by law. If users do not want to give consent right away, I'll nudge them through various UI patterns.
I believe you, but can you share the cite for that? Other commenters have implied that it's not true, and I'd like to have the evidence available when I reply to them.
It's still an issue that essentially all sites are required* to include a cookie banner of some kind. IIRC the EU law even claims jurisdiction over sites in other countries that only serve local audiences, on the notion that an EU national might visit the website.
* "Required" here defined as "materially everyone, including the web developers at the EU, interprets the law this way."
Essentially all sites that ship off PII to 3rd party websites or otherwise process PII need to include the cookie banner.
They can also chose not to do those things, yet they do figure it's worth adding a cookie banner instead of changing that practice. So in reality, the websites have themselves to blame here.
This is an entirely predictable outcome of the bill as written by virtue of the fact that it did not require websites to respect settings configured at the browser or operating system level. This was a glaring weakness in the law that was pointed out repeatedly at the time.
How is more choice hurting users? I thought I'd read arguments against user choice on Facebook perhaps, but on Hacker News?
Companies are now forced to give users a choice if they process/sell PII. Users can then chose to accept/reject this (if the company implementing the choice as the regulation tells them to), where both choices should be as easy as the other, and if they reject it, the company should follow what the user says.
I agree with you though that it's a shame "Do-Not-Track" headers weren't built in into this, since it's already there but poorly supported. But that really should have been a given, as then companies wouldn't have any chance of turning it around. But I'm guessing they lobbied hard against that, and seemingly won.
1. That would also block functional cookies.
2. That requires users to know that it's a thing they should care about. It's not cool to spy on people just because they haven't realized what you're doing and taken countermeasures.
Pounding them into submission also makes their consent legally invalid in many cases, at least by the standard which the GDPR requires. Example GDPR complaint about this problem: https://noyb.eu/en/bereal-app-wont-take-no-answer
This aspect of the law is more an enforcement issue (including national Data Protection Authorities which have effectively been captured by the companies they are supposed to regulate) than a legislation issue.
I'm glad that noyb recently got approved to file something broadly similar to what in the US would be called a class action lawsuit, so that they can do some of the enforcement that the governments won't.
Consider donating to them if you want to see proper compliance. They're doing most of the useful enforcement these days. I have no affiliation myself besides also considering making my own donation.
Showing a cookie banner on each site is pounding us all into submission. It's not that any single website's banner is too much; it's that we are all clicking them all day long.
Honestly, it would be awesome if there was an effective way to geofence these banners to the EU. However, IIRC the EU law asserts control over websites in other countries, on the off chance that an EU national might access the website.
Disagree. I have a browser extension installed that makes the repetition across sites irrelevantly easy, at least on my laptop Chrome browser. I don't usually click on them at all except for sites which try to interfere with the browser extension or which try to block access unless I pay them or agree.
Also, for people without such an extension, seeing the banners could be a reason from complaint to the website itself. No law requires them to do the kind of tracking which requires them to gather consent, nor to gather the consent in such an obtrusive way as they often choose when they do want to gather consent. The most effective way to get websites to stop being obnoxious to their users would be if they had to deal with user complaints about it, not anything legislators can do.
> Honestly, it would be awesome if there was an effective way to geofence these banners to the EU. However, IIRC the EU law asserts control over websites in other countries, on the off chance that an EU national might access the website.
I've already explained to you in other comments how that summary of GDPR jurisdiction is wrong. But hey, when I'm in the US and a website lets me deny consent, I'm happy for the extra protection from tracking. Conversely, when I see the difference in banners when I go to the US - yes, most sites do geofence their own banners to EU-based visitors - I am horrified at the tracking people aren't being told about outside the EU.
I hate the cookie banners too, but I blame the bad actors more than the legislators that at least gave me more information and rights than I would otherwise have had.
I'd argue that what is hurting the users, are the companies who insist that they need to track individuals in those ways. If they didn't, they wouldn't have to show the banners in the first place, and no user would have to confirm/reject anything.
Maybe I'm alone, but I prefer a choice every day of the week, as then I can at least chose for myself. The alternative is just unchecked privacy-violations, and that sounds worse to me, but we're all different, luckily.
That would be an interesting discussion, but that's not on offer. What is instead on offer is dozens of choices every day of the week. Is any person really expected to read and understand a dozen or more privacy policies every day?
People are expected to make reasonable choices in their day-to-day life or suffer the consequences, yes. If you don't want to read the privacy policy, click "Reject" and you don't have to. Tired of clicking reject every day? Send an email to the company and tell them to get rid of it. They can, they just don't want to, and prefer to annoy users instead, because that makes them more money.
We give people the option to take a loan. If they take a loan without reading the terms and conditions, and sign up for very unfavorable terms even if it was very clear, then usually you have to stand for that choice.
Why would allowing/rejecting data collection work any differently?
If people would just spend like 10-15 minutes reading up what they're arguing about, we'd actually get some substantive discussions on this topic.
Also, if the site is using a third party service for the cookie banner, the cookie for remembering "reject racking cookies" might be stored as a third party cookie that the browser then doesn't store at all, depending on the browser settings.
This is all commonly believed but isn't accurate. The only reason the web developers at the EU (correctly) feel like they need to ask for some kind of consent is because they want to use that consent to process visitors personal data beyond the scope of the essential cookies which I was describing. For cookies within only the essential scope, they wouldn't need consent or a banner at all, unless some law other than the GDPR requires proactive in-your-face disclosure of the fact that cookies are being set at all.
The relevant consent doesn't have to be gained through a banner, but at least the EU websites' implementation doesn't involve dark patterns of making it easier to grant consent than refuse it.
As for claiming jurisdiction over sites in other countries, a slightly simplified version of the rule in GDPR Article 3 is that they claim jurisdiction over such sites when they are targeting people in the EU, or when they are processing the data in the EU, or when they are an EU company processing the data outside of the EU. They do not claim jurisdiction over foreign sites that only serve foreign audiences, and they even give examples like that in their official guidance.
To give one clear example right here: The GDPR does not generally apply to the case where someone in the EU visits a US-based website of a ski resort in the US, not even if they purchase a ticket via the website from the EU. By contrast, if the ski resort sets up a .eu website, translates their site into major EU languages that aren't very common in the US, allows purchasing in euros and via EU-centric payment methods like SEPA bank transfer and other methods specific to various EU countries, and so on, they're clearly targeting people in the EU so then the GDPR would apply.
And so much unofficial guidance has inaccurately stated that nationality or citizenship is what determines GDPR rights. The most official sources, and the better unofficial sources, are clear that the location of the data subject matters but not their nationality or citizenship. An EU citizen doesn't get any more GDPR rights while in the US than someone who isn't an EU citizen.
You inadvertently highlight one of the main issues with the GDPR: unclear guidance.
From the "Does the GDPR apply to companies outside of the EU?" page at gdpr.eu:
"If your organization uses web tools that allow you to track cookies or the IP addresses of people who visit your website from EU countries, then you fall under the scope of the GDPR. Practically speaking, it’s unclear how strictly this provision will be interpreted or how brazenly it will be enforced. Suppose you run a golf course in Manitoba focused exclusively on your local area, but sometimes people in France stumble across your site. Would you find yourself in the crosshairs of European regulators? It’s not likely. But technically you could be held accountable for tracking these data."
Even their explanation is not clear. Notably, it's different from your understanding of whether it would apply. Which: I don't blame you, the law is not explained well anywhere I have seen. And their conclusion of "Not likely. But technically..." is not sufficient as official guidance.
What if we go to the law itself?
" 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union. "
Section b doesn't have the carveouts you asserted. Is that exemption in one of the other 98 articles, or an amendment, or elsewhere? Or does it not formally exist?
If the hypothetical US ski resort uses e.g. Stripe that allows people to pay in whatever payment mechanisms are common in their countries, does that alone mean I am "targeting" EU residents? What if my billing page allows a customer to select Belgium in the billing address? What if I don't block shipping addresses in the EU?
The intent here is not to litigate this to death, but rather to point out that the reason so much of the understanding of the law is contradictory is that the thing itself is complex. People don't want to get sanctioned, and putting cookie banners on sites is a way to prevent sanctions.
https://www.edpb.europa.eu/sites/default/files/files/file1/e...
Examples 8, 10, 11, 12, and to some extent also example 3 are pretty good examples of the rules discussed at more length throughout the PDF.
The quote you cited from that unofficial page, and the official provision you cited in your edit, is about monitoring the behavior of people in the EU.
Unless the unofficial site has evidence that anyone official is interpreting it in the way they're implying is potentially possible, it's so unlikely as to be scaremongering. So many laws can be interpreted in unlikely ways that aren't worth worrying about without a reason to worry about them.
To be clear, I don't think it's unlikely that the GDPR might apply if the golf course in Manitoba is specifically monitoring the behavior of people in the EU. but if they are monitoring the behavior of their primarily non-EU user base overall, failing to exclude the EU from their statistics shouldn't be a reason for the GDPR to apply.
This is exactly the problem, and exactly why the EU is to blame for those popups.
Instead of outlawing a behavior they had a problem with, they are trying ti discourage it. The way they try to discourage it is why we have all these stupid popups.
Out of curiosity, you mean against the spirit of the GDPR rather than the letter of it, right?
> 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
Being as easy to withdraw as to give consent is technically a different thing from being as easy to refuse as to give consent, since consent that is refused was never given in the first place but consent that is withdrawn was previously given. But yeah, courts have been clear that both of these actions must be as easy as giving consent, and both requirements are too often not complied with.
> It shall be as easy to withdraw as to give consent.
It is. You click the reject button.
The non EU sites are due to the EU trying to claim global jurisdiction.
The EU are very much to blame for the popups, because even the non dark-patterns one are annoying.
Nope, including EU big business sites as well. There are also EU big business sites which illegally claim the legitimate interest basis for advertising and tracking purposes of data processing which have already been ruled by the courts as not acceptable justifications for the legitimate interest basis.
> The non EU sites are due to the EU trying to claim global jurisdiction.
The EU is trying to protect the data of the people in the EU. There's no way to do that while allowing companies outside the EU to freely violate the privacy of people in the EU. Otherwise these rules become laughably easy to circumvent for all but the smallest EU companies which are also the least dangerous from a privacy and tracking perspective.
> The EU are very much to blame for the popups, because even the non dark-patterns one are annoying.
Disagree. They're not supposed to be annoying enough to impair site usability. The truly compliant ones aren't.
Maybe some, but generally businesses are not breaking the law willy nilly like that.
> There are also EU big business sites which illegally claim the legitimate interest basis for advertising and tracking purposes of data processing which have already been ruled by the courts as not acceptable justifications for the legitimate interest basis.
And did the EU follow up?
> The EU is trying to protect the data of the people in the EU.
The problem is it's unenforceable nonsense and has led to this foolish cookie popup situation.
If they had limited it to entities with a presence in the EU, it would have worked better. At the moment it applies to some malicious Chinese teenager who blatantly wants to collect and sell the data of Europeans who visit his self-hosted low-traffic blog.
> The truly compliant ones aren't.
Yeah, they really are. It's still something you have to interact with to make it go away.
If your response says something if companies don't track they won't need a popup, then you have missed the point.
I can accept that our website visiting patterns, and maybe our specific countries of residence within the EU, expose us to different experiences in this regard. I stand by my statement as a description of my own personal experience, but I'm willing to believe your own personal experience too.
It's also possible that I've increasingly realized that "reject" allows the companies to get away with illegally misusing the "legitimate interest" basis for data processing, so I've mentally stopped assuming that it means what it says because it often doesn't. See below for more on that.
> Out of curiosity, you mean against the spirit of the GDPR rather than the letter of it, right?
No, I mean against the letter of it as well. The free, informed consent which the letter of GDPR requires according to public and legally binding official interpretations (such as from the European Court of Justice) is not present when those dark patterns make it harder to refuse consent than to grant it.
Similarly, EU courts have been clear that simply wanting to do a bunch of tracking to facilitate more profitable personalized advertising does not legally justify the legitimate interest GDPR processing ground, but so many sites default to allowing processing based on "legitimate interest", including when you click reject for the consent question, for many of the same advertising/tracking partners where the "consent" basis is off by default. They also don't usually have a way to object en masse to these, and it's often tricky to correctly click off every single "legitimate interest" button which is falsely and illegally claimed to be a valid legitimate interest.
Plus, I've heard reports that many sites set these cookies even before consent is granted, and/or don't properly respect the refusals of consent and objections to legitimate interest processing. However this is from memory and I don't have stats or evidence to back up this statement.
The problem in all of these respects is primarily very weak and reluctant official enforcement of the rules by the relevant Data Protection Authorities and very low fines when they do enforce them. It's more profitable for companies to take the risk on genuine GDPR compliance, beyond some mild public-facing lip service and the lowest-effort bit of engineering they can do to underpin the public-facing lip service.
I appreciate your attempting to reconcile different anecdotal experiences. In the spirit of objectivity however, I would insist that big businesses are not breaking the law.
> The free, informed consent which the letter of GDPR requires according to public and legally binding official interpretations (such as from the European Court of Justice) is not present when those dark patterns make it harder to refuse consent than to grant it.
I think here we've shifted the problem to dark patterns. The problem though is with the popups at all, because even when they are compliant, they are no less annoying, just slightly more clear.
> The problem in all of these respects is primarily very weak and reluctant official enforcement of the rules by the relevant Data Protection Authorities and very low fines when they do enforce them.
They probably shouldn't have claimed global jurisdiction then. Since that's a big part of what has resulted in so many poorly done cookie banners.
Take a look at the many GDPR violation complaints which noyb.eu has filed against big businesses, almost all of which they eventually win in court. Yes, many big businesses are in fact breaking the law in this regard.
> I think here we've shifted the problem to dark patterns. The problem though is with the popups at all, because even when they are compliant, they are no less annoying, just slightly more clear.
The truly compliant ones are far less annoying. They all generally need only a single click to refuse consent, and they are also easy enough to ignore while using the site without ever responding to the banner at all.
> They probably shouldn't have claimed global jurisdiction then. Since that's a big part of what has resulted in so many poorly done cookie banners.
It's also essential to actually achieve the goal of protecting the data of people in the EU, much of which is done by companies which are based outside the EU. Do you not see the big truck-sized loopholes which would exist without that? All they would then have to do is change the website's contracting legal entity to a foreign partner or parent company and then they could refuse data subject access requests, track without consent, and so on if the jurisdiction provisions in Article 3 were as narrow as you're advocating.
Define big business here. Coca Cola? IBM? Amazon?
> The truly compliant ones are far less annoying. They all generally need only a single click to refuse consent
No, they yare still annoying. It's still something you are forced to itneract with that diverts your attention.
> It's also essential to actually achieve the goal of protecting the data of people in the EU, much of which is done by companies which are based outside the EU.
The problem is it's unenforceable nonsense and has led to this foolish cookie popup situation.
If they had limited it to entities with a presence in the EU, it would have worked better. At the moment it applies to some malicious Chinese teenager who blatantly wants to collect and sell the data of Europeans who visit his self-hosted low-traffic blog.
> All they would then have to do is change the website's contracting legal entity to a foreign partner or parent company and then they could refuse data subject access requests, track without consent, and so on if the jurisdiction provisions in Article 3 were as narrow as you're advocating.
They can already do that because EU has no jurisdiction outside of the EU no matter what they claim.
Also, we are basically having the same conversation in two places. If you want to consolidate your two replies into just one I would not object.