Ironically I think the analogy explains why many people find "source available" to align with their moral compass more than "open source" necessarily does.
38 karma · joined August 10, 2017
Ironically I think the analogy explains why many people find "source available" to align with their moral compass more than "open source" necessarily does.
That isn't actually true (or at least is only allowed in the "it's a small enough violation of the law that the enforcers have bigger fish to fry" sense).
Cookie banners are required to gather informed consent, which is relevant for two EU legislations: the ePD, which requires it to access or store _any_ data from terminal equipment, and the GDPR which requires it for personally identifiable data. Most people only consider the latter, but the former is a much bigger hurdle to pass.
Despite Plausible's claim of not requiring cookie banners, their processing still accesses data from the terminal equipment. That was made very explicitly clear in a 2023 guideline from the EDPB[1].
The one saving grace for Plausible is that the ePD is a Directive, so the actual implementation into law differs by Member country. The claim might be true for some EU countries, but certainly isn't for all.
I've written a longer analysis of this in the context of Plausible for anyone interested[2] (although it might be worth skipping the first section, to get to the meat of the issue).
[1] https://www.edpb.europa.eu/our-work-tools/our-documents/guid... [2] https://jfagerberg.me/blog/2022-06-09-analytics-cookie-compl...
The response from Plausible is essentially "we've checked with legal council, and stand by the statement". The conversation with the lawyer started out well, but he stopped responding when I asked about the ePD, not GDPR.
There generally seems to be a lot of confusion, even in legal circles, about what ePD requires informed consent for. Many think that only PII requires consent, or think that anonymization bypasses it. That amount of confusion makes it very easy for a layman (e.g. Plausible) to find _someone_ willing to back up their viewpoint.
The EDPB released a guideline in 2023 that explicitly states that what Plausible et al. are doing is covered by the ePD's consent requirement, but that's a little too late: the implementations in member countries already differs massively on whether it's covered[4].
1: https://github.com/plausible/analytics/discussions/1963 2: https://plausible.io/blog/legal-assessment-gdpr-eprivacy 3: https://news.ycombinator.com/item?id=42792485 4: https://matomo.org/faq/general/eprivacy-directive-national-i...
[0] Section 4.3 of https://ec.europa.eu/justice/article-29/documentation/opinio...