> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.
I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.
If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.
If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.
As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.
No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.
Non-malicious compliance with privacy laws would mean respecting people's privacy.
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested.
If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested.
No consent needed.
On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed.
Javascript measuring which sub-parts of the page they lingered on -- consent needed.
Tracking how often they come back without buying anything -- consent needed.
Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED.
See the difference?
GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.
Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.
The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.
The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"
https://web.archive.org/web/20190627174442/http://www.hse.go...
https://web.archive.org/web/20200131200512/https://blogs.ec....
You do if you want to track your users. Very different thing.
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
Because if it is, I also want to do it that way.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB).