I know the EU cookie banners have basically ruined the internet, but this seems like a whole 'nother level of obnoxious.
I know the EU cookie banners have basically ruined the internet, but this seems like a whole 'nother level of obnoxious.
There is one case where DPA ruled in favor of the company, but it's currently being appealed: https://noyb.eu/en/pay-or-ok-der-spiegel-noyb-sues-hamburg-d...
Another one ruled against company and court agreed: https://noyb.eu/en/court-decides-pay-or-okay-derstandardat-i...
In theory someone could directly sue some company which engages on this via Article 79, but this can be expensive and depending on jurisdiction the plaintiff can end up with personal liability on defendant's legal costs if court ends up finding that this is actually legal (e.g. Finland has "loser pays" rule in civil suits).
Additionally this does also touch ePD and in some countries there might be different agency which handles ePD complaints compared to GDPR, like in Finland Data Protection Ombudsman handles GDPR, but Transport and Communications Agency (Traficom) handles ePD. If there is something that touches both the Ombudsman usually lets Traficom take care of ePD aspects before they give any GDPR ruling. Both of these can take years.
EU made bad laws that have encouraged this kind of behavior. And now we're all suffering.
Look at the CCPA in California for legislation that accomplishes largely the same goals, but doesn't break the web due to "malicious compliance".
Most of them decidedly don't have the same cookie banners. E.g. in vast majority of cases they don't prevent you from seeing content, and have an easy opt-out mechanism without dark patterns.
This needs repeating, it's a common misconception (deliberately spread by many, too) that the EU requires cookie banners for all cookies.
> This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.
Both in incognito and normal modes. I bet you'll get the same fingerprinting ID in both.
So yes, they can track you in incognito mode, too.
Workarounds include:
- reader mode
- "behind the overlay" extension (and others like it)
- archive.is
- probably many others
Extremely common practice for newspapers websites, unfortunately.
I think the lawmakers should have made all forms of tracking illegal instead. That would make law writing and following easier. And closer to the spirit of what they are trying to accomplish and what everyone wants (except you Silicon Valley O.o)
> Data processing by advertising providers including personalised advertising with profiling (Consent required for free use)
very frustrating because especially a tech magazine like heise should really know better