Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

31–40 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#31

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

> attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookies If I understand correctly, this sort of trickery is forbidden by the GDPR, but so far no-one has seen any consequences for doing do.

> so far no-one has seen any consequences for doing do.

This is precisely the problem with the GDPR to date.

Last August the ICO (British regulatory body) stated that you can't run Analytics such as Google Analytics without a GDPR standard of consent. They've yet to enforce this despite tens of thousands of non-compliant websites.

Re: Only 9% of visitors give GDPR consent to be tracked

#32

I must say I'm really surprised. I'm a frontend developer and probably more keen to keep an eye on this stuff but there are lots of times where I just say yes because the popup is in-my-face and I just want to scroll to the content. I guess where the article falls flat is where the author says a "proper GDPR content banner" was implemented. No online publication will do this. At least they will trick you with button…

I try to make sure to always decline. If there's no easy way for me to do that I leave the site.

Re: Only 9% of visitors give GDPR consent to be tracked

#34

Earlier quoted context omitted.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

More a problem of enforcement than the legislation IMO. It wouldn't take many cases to be properly litigated before publishers would understand this is a law that is to be obeyed like any other.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

Re: Only 9% of visitors give GDPR consent to be tracked

#35

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

I was quite pleased that the cookie banner example was blocked by uBlock. As it should be.

Re: Only 9% of visitors give GDPR consent to be tracked

#36
Assuming for a moment that the test websites didn't give a specific reason to trust them more or less than any other website operator. This means that if your website has significantly more than those 9% consent, you're either perceived as very trustworthy, or your GDPR banner is confusing (or, less charitably, deceiving) users.

Would be interesting to see how the consent rates for big offenders like techcrunch, newspapers etc are. IIRC there were specific studies about which brands are trusted by consumers, and Comcast et al. didn't fare all that well in those.

Re: Only 9% of visitors give GDPR consent to be tracked

#38

How cycnical - an article further down (Two young scientists built a $250M business using yeast to clean up wastewater) links to Forbes.com that indeed allows me to set my tracking preferences.However, anything other than 'accept' will result in a message stating 'we are processing the request this may take up to a few minutes'. So they can set hundreds (yeah - that is right, I have seen pages tell me they wanted 500…

All that stuff is gone if you block javascript on forbes.com

Re: Only 9% of visitors give GDPR consent to be tracked

#39
post #19

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Yes, exactly. I hoped that he would repeat the experiment with a tricky one, like the horrendous forms served by Quantcast. In those, if you click "Reject all" nothing happens! How is that even allowed boggles my mind.

> How is that even allowed boggles my mind.

It is not. But GDPR is sorely lacking enforcement with regard to tracking consent. The last time I checked only 3 cases were brought up (all in spain), and all of those would already have been illegal before GDPR in my non-lawyer opinion.

Re: Only 9% of visitors give GDPR consent to be tracked

#40
post #12

Wait. You tracked users after they opted out of tracking? How else did you get this data?

It's not personal data, so it's not under the scope of GDPR.

Yeah, no. This about the ePrivacy directive, if you don't have proper consent, you can't read/write tracers regardless of wether this is personnal data or not, except for tracers needed to establish the communication or demanded by the user (carts, login, etc).

EDIT: Thought about it, and if you only record the button click and does not identify the user, it works, and I am wrong! In general ePrivacy is very restrictive, only about access to terminal and not about personnal data ( and btw PII is not a GDPR thing, we say personnal data), but here it's ok! So yeah, no to me!

Post reply on HN