Live data from Hacker News

The GDPR Is a Cookie Monster

emarketer.com

41–50 of 97 posts

Re: The GDPR Is a Cookie Monster

#41
post #33

I fucking hate GDPR policy making every website to show "Cookie Policy" ad pop modal. STOP. Every single time after I have accepted it, I come back the next day, I see the same modal again. I just accept it anyway, so stop. Stop this horrible UX. Sorry, but it really annoys the shit out of me. It does and I am pissed off every single time. If I accept, stop asking.

Are you using a browser extension that may be interfering with the website? I haven't had issues with website forgetting my preferences yet.

Also being in the EU I'm used to these cookie dialogues, except before GDPR if I wanted to opt-out (assuming that it was even an option) I'd often have to wade through multiple pages, opting-out of the tracking which would take a while, especially since they were usually using every dark pattern in the book.

Now with GDPR I still get the messages but everything is opt-in instead of opt-out and I can just click the (sometimes obfuscated) "I refuse" and carry on. It's actually a huge quality of life improvement as far as I'm concerned.

Re: The GDPR Is a Cookie Monster

#42

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

Enter Brave. And uBlock Origin. And DuckDuckGo privacy essentials.

Re: The GDPR Is a Cookie Monster

#43
post #39

Earlier quoted context omitted.

That was my take on it as well: > In a September 2017 study of 250 US digital marketers by Viant, about 60% of respondents said they will no longer rely on cookies for the majority of their digital marketing within the next two years. The absence of any description about what they will use instead is frustrating.

Considering you cannot use cookies for mobile traffic, it's understandable that most firms are moving away from it. Fingerprinting and device IDs have been common for a few years and I don't think it will go away any time soon.

Why can't you use cookies for mobile traffic?

Re: The GDPR Is a Cookie Monster

#44
I just HATE all the pop-ups asking for permission to use cookies now.

Seriously, having to opt-in on a per-site basis has led me to loathe the GDPR. It's a usability disaster. I never thought I'd hate anything more than the "sign up for our newsletter" pop-ups... but these are even more pervasive.

If I'm the kind of person who hates cookies/tracking, I'll just install a blocker and block it everywhere, and then whitelist any domains I need to.

It just makes me feel like the GDPR was a win for lawyers and legalese, and nobody else.

Re: The GDPR Is a Cookie Monster

#45
post #7

Earlier quoted context omitted.

And I hope they will all get heavy fines for doing so. Let's see how well the EU will enforce the GDPR.

They won't. The ICO in the UK has already said they aren't interested in imposing fines [0]. They would much rather nudge companies into compliance. > "The fine is really a last resort," she told Computing. "Even to get to the fine we have to go through a lengthy investigation that might take several months, then we have to take it though the courts. So fines are not our go-to tool." However. I think with egregious c…

It’s totally OK that fines are used as a last resort. As long as they will be used as a last resort.

Re: The GDPR Is a Cookie Monster

#46
post #7

Earlier quoted context omitted.

And I hope they will all get heavy fines for doing so. Let's see how well the EU will enforce the GDPR.

Don't we have a glimpse of (lack of) enforcement based on previous incarnations of laws like this? What about this time is special? And why are laws crafted without ample enforcement mechanisms? At the least that makes them toothless, at the most it gives a piece of legislation that can be pulled out and used only when someone wants a reason to punish a company.

The difference is that GDPR does have effective enforcement mechanisms, precisely unlike previous laws. Now let’s see if they’ll be applied.

Re: The GDPR Is a Cookie Monster

#47

GDPR doesn’t help anyone, so let’s pass more half baked regulations! Let’s just ban companies from using the internet! That will stop internet advertising for good. Thank God smart politicians like me care so much.

In what way does it not help anyone?

It certainly seems to help EU citizens, like myself.

Re: The GDPR Is a Cookie Monster

#48
I feel like the DNT header could have been made a lot better if it worked alongside GDPR. Like, 0 = haven't chosen/prompt me (I want to pick exactly what cookies I want), 1 = don't care give me everything, 2 = functional, 3 = please don't track me at all. You could then just surface this per-site even in the browser, maybe in a way resembling the IE Security Zone settings with their nice sliders.

Re: The GDPR Is a Cookie Monster

#49
post #6

Earlier quoted context omitted.

Yep. If anything, things are worse now. You HAVE to give consent to do anything useful on the website (so blocking the notice won't work), and in the consent form it's usually very hard to turn tracking off, full of dark patterns. Not legal from the perspective of GDPR, sure, but it seems that everyone is doing it. /edit: downvoted for stating basic facts, amazing.

I just don't use sites that won't work until you give consent.

This is actually non-compliant. Sites may not withhold service based on consent. They can paywall things no-problem, but users must not be forced to give consent at any point in order to use the service.

Re: The GDPR Is a Cookie Monster

#50
post #3

I'm glad the GDPR actually manages to enforce one of it's lesser talked about principals: data minimasation. What is worrying about this article is that it implies companies are using other, even less consensual ways of tracking users. Or maybe I'm reading too much into it.

That was my take on it as well: > In a September 2017 study of 250 US digital marketers by Viant, about 60% of respondents said they will no longer rely on cookies for the majority of their digital marketing within the next two years. The absence of any description about what they will use instead is frustrating.

Which is odd, since GDPR isn’t about cookies. Other means of user tracking fall under GDPR too.

(To clarify, it wouldn’t be particularly odd if companies were found to violate GDPR; but the selective move from cookies to other technologies doesn’t change the legal situation.)

Post reply on HN