Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

1–10 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#2
The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out.

I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookies.

Re: Only 9% of visitors give GDPR consent to be tracked

#3
I must say I'm really surprised. I'm a frontend developer and probably more keen to keep an eye on this stuff but there are lots of times where I just say yes because the popup is in-my-face and I just want to scroll to the content.

I guess where the article falls flat is where the author says a "proper GDPR content banner" was implemented. No online publication will do this. At least they will trick you with button colors, or some kind of double negative mind trick. Sometimes they will require you to tick all the checkboxes out.

GDPR was a good idea from the start but it's implementation is rather dull - they shifted responsibility to each country without penalization for relaxed enforcing, and now there are countries like mine (Portugal) where we have less than a hundred fines.

Re: Only 9% of visitors give GDPR consent to be tracked

#5

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

Re: Only 9% of visitors give GDPR consent to be tracked

#6
post #4

Unless they do browser fingerprinting, the number will be overinflated by all the people like me who clear their cookies regularly, if not on every browser session, and are therefore re-asked consent on every single visit.

I'd imagine the people who do that to be a very small percentage.

Re: Only 9% of visitors give GDPR consent to be tracked

#7

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Thing is, if someone can show that they were tricked into giving consent when they were not willing to, then you're still in violation of GDPR. So those convoluted forms might not give those companies the legal protection they they hope for.

And yes, I'd assume the "phony consent" rate to be much higher, because in some cases I also cannot find the no button and/or accidentally tap on the huge yes button on my phone when my intention was to click the tiny no link next to it.

Re: Only 9% of visitors give GDPR consent to be tracked

#8

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

A lot higher, that’s why they are shady in the first place.

Re: Only 9% of visitors give GDPR consent to be tracked

#9
I am not convinced that GDPR will ever really be enforced. Severe breaches have mostly been ignored so far and the minor dark patterns that dominate GDPR compliance popups and wrong defaults are going to be the tail end of compliance enforcement. Just like cookie laws before it GDPR will probably just make websites annoying with obnoxious implementations and remain largely unenforced until the EU does something else to try and fix this class of data problems and the cycle will continue.
Post reply on HN