Just a remark, nothing more.
PS, I'm also curious why the downvotes for something that appears to be quite a conversation starter ...
Just a remark, nothing more.
PS, I'm also curious why the downvotes for something that appears to be quite a conversation starter ...
There, now only our browser can track you and only our ads know your history…
We’ll get the other two to also play along, throw money at them if they refuse, I know our partner Fruit also has a solution in place that we could back-office deal to share data.
However I could have better phrased my original comment with the word "was" instead of "is".
I promise you every adtech/surveillance js junk absolutely is dropping values into local storage you remember you.
On a company/product website you should still inform users about them for the sake of compliance, but it doesn't have to be an intrusive panel/popup.
No? Github for example doesn't have a cookie banner. If you wanna be informative you can disclose which cookies you're setting, but if they're not used for tracking purposes you don't have to disclose anything.
Also, again, it's not a "cookie" banner, it's a consent banner. The law says nothing about the storage mechanism as it's irrelevant, they list cookies twice as examples of storage mechanisms (and list a few others like localStorage).
The problem with third party cookies that it can track you across multiple websites.
If you don’t use cookies, you don’t need a banner. 5D chess move.
I say it’s a perfect application of how to keep session data without keeping session data on the server, which is where GDPR fails. It assumes cookies. It assumes a server. It assumes that you give a crap about the contents of said cookie data.
In this case, no. Blast it away, the site still works fine (albeit with the default theme). This. Is. Perfect.
Something as simple as "blue" doesn't qualify.
It does not assume anything. GDPR is technology agnostic. GDPR only talks about consent for data being processed, where 'processing' is defined as:
‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
(From Article 4.2)The only place cookies are mentioned is as one example, in recital 30:
Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.Emphasis, mine. You are correct. For personal data. This is not personal data. It’s a site preference that isn’t personal other than you like dark mode or not.
> It assumes cookies. It assumes a server.
How can people still be this misinformed about GDPR and the ePrivacy law? It's been years, and on this very website I see this exact interaction where someone is misinterpreting GDPR and gets corrected constantly.
GDPR rules are around personal preference tracking, tracking, not site settings (though it's grey whether a theme preference is a personal one or a site one).
In this case it's not grey since the information stored can't possibly be used to identify particular users or sessions.
You can use cookies, or local storage, or anything you like when its not being used to track the user (eg for settings), without asking for consent.
Enough to know the general region of the user, not enough to tie any action to an individual within that region. Therefore, not personally identifiable.
Of course, you also cannot have user authentication of any kind without storing PII (like email addresses).
---
Also: in general the banners are generally not required at all at an EU level (though some individual countries have implemented more narrow local rules related to banners). The EU regs only state that you need to facilitate informed consent in some form - how you do that in your UI is not specified. Most have chosen to do it via annoying banners, mostly due to misinformation about how narrow the regs are.