For those who don't, here's a version of the page with no full-screen banner: https://archive.is/bTEse
For those who don't, here's a version of the page with no full-screen banner: https://archive.is/bTEse
No, this is an example of malicious compliance. There are so many bad GDPR banners because the people creating them want you to be annoyed by them. They want to have the easy path being the one that lets them collect as much data as they can and the most private path is as annoying as they believe they can get away with under the law. They want people complaining that the GDPR did nothing but cause all these annoying banners.
It'd be possible for many if not most web sites to not have such banners at all by simply defaulting to privacy-friendly behaviors, but there's too much money to be had in the behaviors the GDPR seeks to reduce.
This site is not using a loop-hole. It is clearly in violation.
Not having an option to reject that is as convenient as the one to accept is not compliant with GDPR.
I, for one, think it's time to start busting some proverbial kneecaps if we ever want publishers to take the matter seriously. The other alternative is to outlaw the collection of personal information without a legitimate purpose (consent or no) _and then_ come down hard on violators. The industry has had ample time to regulate itself and has chosen profit over ethics at every opportunity.
> Not having an option to reject that is as convenient as the one to accept is not compliant with GDPR.
The law, guidance provided by regulators, and court rulings are all quite clear on this: Consent must be freely given, the consent form must not be coercive in any way.
This includes (but is not limited to) making rejecting more difficult than accepting, degrading the quality of service for those who reject, gating the service behind accepting, or requiring payment from those who reject. Collecting personal information without prior consent would obviously also be a (worse) violation of the law.
Essentially: If you wish to process personal data on the basis of consent, then the consent must be freely given, and consent is not freely given if you engage in coercive or deceptive practices, which includes providing a consent form that has an "accept all" option but no "reject all" option.
Here's the relevant text of the regulation:
> 1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
> 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.
> 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
> 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.