https://commission.europa.eu/resources/europa-web-guide/desi...
> Cookies and similar technologies that generally do NOT need consent
> (…)
> Authentication cookies, for the duration of a session
I think you did need to explicitly tell the user about it.
But I think (not fully sure) they did relax that recently so just listing it in you Privacy Policy or similar should be enough by now.
But also due to how enforcement is designed it's not that you really had to worry about anything if you only have non-censent requiring cookies and list them clearly in the privacy policy. Worst case a privacy agency tell you to "improve on it" without penalty.
It's just which site (or app) today doesn't use something like Google Ad Network, or Metas Ad Network, or Apples Ad network. All of which do not support ads without tracking (which still are very viable, e.g. select ads based on what the side/ad is about).
For websites, Hacker News doesn’t seem to use any of that. For apps, Alfred doesn’t do any tracking, nor does Wipr, or Inkscape, or mpv.
That’s exactly what it does.
https://commission.europa.eu/resources/europa-web-guide/desi...
They list more types of cookies which do not need consent than the ones which do.
0: https://web.archive.org/web/20250301000000*/https://commissi...
(but some informational requirements have been slightly relaxed recently I think)
The page has existed for several years, it was just at a different URL before. Here’s a version from 2021:
https://web.archive.org/web/20210623122357/https://wikis.ec....
GDPR isn't unique in that. When HIPAA came out in the US, no one was sure what it actually meant. I personally talked to hospital administrators who were convinced that we'd have to put up a "take a number" device in waiting rooms and call out "#53? It's your turn #53!", which the owners of the practice I ran flat-out refused to do: "the waiting room is currently occupied by Mr. Smith and Mrs. Jones, who have known each other since kindergarten, and I'm not going to refer to them as numbers". It took several years to build consensus on how to comply with it.
In case it wasn’t clear, I wasn’t trying to “gotcha” you or anything. I took your message to be in good faith. I just knew the website used to exist on another page because I remember having it in my bookmarks and it breaking and having to search for the new one.
> but that's still several years after the law was deployed
Maybe, I do not know. I didn’t search for it before then, so for all I know it was available at some other domain too. Or maybe it wasn’t, that’s the earliest one I remember.
The text on that website does state that some DPAs have found some first-party analytics acceptable, but that's not something that is confirmed by CJEU. And ePD does not have single-stop shop so you need to follow every DPAs directions if you are offering services to that DPA's country.
it does have such exception, always did (as long as the cookies are not used for tracking or other non essential things etc.). It might not be supper explicit but it's explicit enough to have you on the safe side.
you do have to inform people, but there are very non intrusive ways to do so (as it's informational only, i.e. no user interaction like confirm/accept is needed at all). (I think? they also have removed part of the explicit informational requirement for some things recently, i.e. it's good enough to list it on your site in the TOS/Dataprotection section/sub-site.)
there are other (I think not EU wide but nation specific) laws which get confused with it and handle things different, based on sites storing their data on your computer (and with that any cookie)
the reason most sides don't do anything like that isn't because they can't. It's because they try to harass user endlessly until they always click on confirm and can be tracked. Or because they don't know better due to a endless slew of systematic misinformation spread by advertisement agencies like Google Ads.
It is not. They even list more types of cookies which do not need consent than the ones which do.
https://commission.europa.eu/resources/europa-web-guide/desi...
> The EU's official resources on data protection, for example, have a popup.
Because it’s mandatory for them, not because the cookies are invasive. See the top of the page of the link above:
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
Nonsense. It's easy to create a site that doesn't need a cookie pop-up. Indeed the mere existance of a cookie pop-up screams "we are tracking you and selling your info".
only if your site insist to use any of the widely used Ad networks
through there are Ad Networks which base ads on what is on your site instead of who visits
and the popup you link is _not_ a GDPR popup but is related to some other older and very misguided law(s). (Not EU wide laws, but EU sites want to be compliant with every member countries laws.)
Having a EU decision which requires countries to remove this older misguided laws has been on the agenda for years. It's just given that most sites anyway will have popups (e.g. for Google Ads) things move way way way to slow :(