Is the use of reCAPTCHA GDPR-compliant?
dg-datenschutz.de
dg-datenschutz.de
> The difficulty of the puzzle, and therefore the time and resources needed to solve it, is intelligently and automatically scaled based on sophisticated risk signals to protect against advanced bots. Friendly Captcha is completely invisible and require no manual user challenge at all.
So... magic?
> Friendly Captcha does not depend on tracking your users and exploiting personal data.
What "advanced risk signals" are these that do not involve tracking (or fingerprinting) users?
The real [Deutsche] "Gesellschaft für Datenschutz" seems to be: https://www.gdd.de
-
Before edit:
Given this is one of the organisations who help give governments draft laws by advising them, and whose purpose is to help its members obey those laws, that would be rather self-defeating.
And given the web design apparent on the following page, I think this is much more easily explained as "bad web design": https://dg-datenschutz.de/imprint/
If given an active choice nobody* would ever go "yes I want you to sell my data to your 1,414 carefully selected partners". Maybe they want personalisation when they sign up for an account, but you ask them that at signup time, not the first time they land on your page.
* where nobody < 1%
Unfortunately, the cookie dialog was missed by "the translation tool" and both accept and reject kinda look the same to me.
I have uBlock Origin (mind, with the default settings). I also have the Consent-O-Matic autofill extension that's supposed to reject cookies automatically for me.
Neither of them seems to catch cookie dialogs on some german sites. Not that I want uBlock to hide the cookie dialogs, I want them explicitly rejected by the other extension.
Consent-O-Matic does automatically reject most crap on english and romanian sites so I guess they haven't added support for whatever cookie dialog zeit.de uses (and that's popular on german sites?).
> both accept and reject kinda look the same to me
I bet that's very intentional too, and there are other ways to phrase it in German so the two options don't look similar.
- Settings / Einstellungen
- Accept / Akzeptierten
- Reject All / Alle Ablehnen
The English translation is on the buttons in the non-translated page and those translations are fine. There's even a reject all button, which is fine too. The only not so nice thing is that the "Accept" button is coloured green.
Again, I don't want to defend those banners.
"Allen zustimmen" "Ausgewahlten zustimmen"
Yep I could look it up. But using the same verb looks like an intentional dark pattern to me. And I wasn't interested enough in the article to jump through the hoops.
(Our conversation did make me look it up and neither is 'reject all', they're 'accept all' and 'accept selection').
"Do not sell or share my personal information (CCPA/CPRA)."
Most other websites try to hide this fundamental choice from you behind dialogs and endless options. (And of course outside the EU you don't even get to control this, your data will always be collected and sold.)
And as someone who was successful in making such claim, it was a relatively easy process.
I had no idea. 90% of the time I’m getting the Please select all stairs bullshit. Another 5% is an outright block for “suspicious activity”. (I’m on Firefox, FWIW.)
Just yesterday it had me clicking all squares with motorcycles in it. I failed five consecutive times before it let me through.
Almost started to doubt myself.
It's cool that it even allows you to to get past captchas with JS disabled, I like this a lot.
"Das Vorhandensein von datenschutzfreundlicheren Optionen steht im Widerspruch zu einem berechtigten Interesse"
which means
"The existence of more privacy-friendly options contradicts a legitimate interest."
But did they really test if the alternatives block bots as well as reCaptcha?
If not, wouldn't that mean there is a legitimate interest in using reCaptcha?
If the mere existence of more privacy-friendly options, no matter how inferior, means you cannot use a certain service, wouldn't that make the use of pretty much every service illegal in the EU?
A service does not have a right to exist. The user has a right to privacy. The users right to privacy trumps the services want to exist. Not to mention that, yeah, there are ways to get similar or better blocking for free, if you have some technical chops at least. I wouldn't fault a small blog for using googles captcha (although the need is questionable), but any company with at least a few employees should be able to figure this out at a relatively trivial cost.
The user can simply choose not to use the service?
How can you get better blocking for free?