With the legitimate individual control over one own data required to run a healthy society and unavoidable to sustain a democracy. If a business can't exist without threatening society, the sooner it's going out of existence the better.
The cookie banner thing is intended to allow the user to explicitly provide consent, should they for some reason wish to do so.
A website might claim some sort of legitimate interest for the initial collection of data but might not think that they can claim that for the retention of data I suppose. That would seem kind of dodgy to me...
Just because a website claims something doesn't mean it is valid. There isn't a lot that falls under legitimate interest for a website.
Navigate to a website of your choice [1]. Let's assume its privacy banner is served by onetrust.
The text at the top of their "Privacy Center" says, verbatim, "We share this information with our partners on the basis of consent and legitimate interest. You may exercise your right to consent or object to a legitimate interest"
If you then unfold the "Manage Consent Preferences" you will notice that you can, _separately_, provide your consent for a given purpose, by sliding the switch to the right to enable it, and also, _at the same time_, "Object to Legitimate Interests" by clicking on the button labeled so.
Of course, this is a dark pattern to make it as cumbersome as possible to object to Legitimate Interest purposes.
[1] (I took vox dot com as an example.)
Legitimate interest is for example a website using your IP to send you the necessary TCP/IP packets with the website's content upon request.
Many websites use the term "legitimate interest" misleadingly (or even fraudulently), but that's not how GDPR defines it.
We are almost 10 years into the GDPR, and we still have these gross misunderstandings about how to interpret it. Meanwhile, it has done nothing to stop companies from tracking people and for AI scrapers to run around. If this is not a perfect example of Regulatory Capture in action, I don't know what is.
I'd argue that's the opposite of regulatory capture.
I'm in Spain, this is probably not the same worldwide.
- they don't care about the cookies they are setting on their properties, if most of the functionality they have require you to be authenticated anyway.
- These "smaller websites" are exactly the ones more likely than not to be Google's and Facebook's largest source of data, because these sites are the ones using Google Analytics/Meta Pixel/etc.
The YouTube consent screen for example includes this as a mandatory item:
> Measure audience engagement and site statistics to understand how our services are used and enhance the quality of those services
I don't believe this complies with the GDPR to have this mandatory.
GDPR says it is [1][2].
> We are almost 10 years into the GDPR, and we still have these gross misunderstandings
Because people would rather smugly and confidently post about their gross misunderstandings. If only there was some place to read about this and learn. I’ll give you the money shot to save 10 more years:
> Fortunately, the GDPR provides several examples in Recital 30 that include:
> Internet protocol (IP) addresses;
From Recital 30:
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses
[1] https://gdpr.eu/eu-gdpr-personal-data/
[2] https://gdpr.eu/recital-30-online-identifiers-for-profiling-...
So, sure, if you stick the user's IP address on a cookie from a third-party service, you are sharing PII. But this is absolutely not the same as saying "you need to claim legimate interest to serve anything, because you will need their IP address".
Source: I have been cursed to work on too many Data Protection Impact Assessments, and Records of Processing Activities together with actual lawyers.
So, apologies if I was not precise on my comment, but I still stand by the idea: you don't need to a consent screen that says "we collect your IP address", if that's all you do.
The misconception is that you need explicit consent for any kind of processing of PII. That is not the case. The law gives you alternatives to consent, if you can justify them. Some will confuse this with “must mean IPs aren’t PII”, which is not the case.
When serving content, you're by necessity linking it to a website that's being accessed.
For example, if grindr.com had a display in their offices that showed the IP address of the request that's currently being handled, that's not saving or publishing or linking the data, but it's still obvious PII.
You are not sharing with a third-party, but that sure falls into processing and publishing it.