Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

41–50 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#41

The article says mobile users are more likely to engage with the banner. Rightly so, cause it takes up precious screen real estate. What are some ways I can protect myself more when browsing the web through my phone?

Depends on the phone, but generally you can't protect yourself as well as on PC, because phones (sadly) are locked down devices running proprietary software. Best you can do is probably DNS-level blocking.

Re: Only 9% of visitors give GDPR consent to be tracked

#42

Earlier quoted context omitted.

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

they just need to crack down much harder on websites and hand out big fines for dark patterns until the websites switch to sane defaults.

It's just a question of how much the companies in question believe that the EU is going to come after them. Once the cost calculus shifts to being on the safe side it'd quickly turn into a norm, but it requires showing some teeth.

Re: Only 9% of visitors give GDPR consent to be tracked

#43
Regarding "engagement rate": is your banner filtered by ad blockers? In my session, there's no banner displayed. Could also be a hint on why mobile browsers are more likely to enable engagement, since they might lack CSS filtering techniques (used to hide the banner).

Other point: third party hosters. It's good to see you as the website creator put effort into GDPR compliant behaviour! Did you also include Netlify and your GDPR-provider into the evaluation? Do they use additional tracking technologies?

btw, your post was copied to https://www.facebook.com/BloggersWorldToday/posts/6238368718... fyi

Re: Only 9% of visitors give GDPR consent to be tracked

#44
post #20

Earlier quoted context omitted.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

All that's required is for the regulators to start holding companies using these dark patterns to account. These things aren't GDPR compliant by any reasonable interpretation, and these companies are basically trying their luck to see what they can get away with. If fines start coming to them they'll change their tune pretty quick.

They are so blatantly non-compliant I wonder if at least some companies are actually trying to discredit the GDPR and the idea of regulation in general by annoying their users while blaming the GDPR.

Re: Only 9% of visitors give GDPR consent to be tracked

#45

Earlier quoted context omitted.

More a problem of enforcement than the legislation IMO. It wouldn't take many cases to be properly litigated before publishers would understand this is a law that is to be obeyed like any other.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

In 2016, I think, there were 0 airplane crashes and 0 air travel fatalities. Across 200 countries, hundreds of airlines and several airplane manufacturers, probably thousands of airports, millions of flights.

If you think that was an easy feat, then I don't know what to tell you.

Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy.

When people really care, bureaucracy works wonders.

Bureaucracy is basically formalizing social interactions for a specific topic. Formalizing something ossifies it, but it also prevents your pilot telling your copilot "Shut up!" just as the plane is about to crash into the mountain.

Re: Only 9% of visitors give GDPR consent to be tracked

#46

I am not convinced that GDPR will ever really be enforced. Severe breaches have mostly been ignored so far and the minor dark patterns that dominate GDPR compliance popups and wrong defaults are going to be the tail end of compliance enforcement. Just like cookie laws before it GDPR will probably just make websites annoying with obnoxious implementations and remain largely unenforced until the EU does something else…

One really incredibly annoying trick that I see more and more is when they pre-check only the "mandatory cookies" option, but then when you want to confirm this selection you end up allowing all tracking cookies. It's because they make the confirmation button less prominent, and something that looks more like the typical confirm button is actually "allow all cookies". I guess a lot of people just click on it automatically.

edit: sorry, replied to the wrong post

Re: Only 9% of visitors give GDPR consent to be tracked

#47

Earlier quoted context omitted.

> attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookies If I understand correctly, this sort of trickery is forbidden by the GDPR, but so far no-one has seen any consequences for doing do.

> so far no-one has seen any consequences for doing do. This is precisely the problem with the GDPR to date. Last August the ICO (British regulatory body) stated that you can't run Analytics such as Google Analytics without a GDPR standard of consent. They've yet to enforce this despite tens of thousands of non-compliant websites.

Meanwhile, there has been talk of permitting first party analytics cookies without requiring explicit consent for at least as long as the GDPR has been around. IIRC, even the ICO previously indicated support for that position, though I can't immediately find a reference for that now.

Re: Only 9% of visitors give GDPR consent to be tracked

#48
post #20

Earlier quoted context omitted.

All that's required is for the regulators to start holding companies using these dark patterns to account. These things aren't GDPR compliant by any reasonable interpretation, and these companies are basically trying their luck to see what they can get away with. If fines start coming to them they'll change their tune pretty quick.

They are so blatantly non-compliant I wonder if at least some companies are actually trying to discredit the GDPR and the idea of regulation in general by annoying their users while blaming the GDPR.

I am sure that's at least part of the thinking.

And judging from comments here on HN, it seems to be working. Just two post above yours there's a comment stating that any government solution cannot fix the tracking issue, and it can only be addressed by a company or an individual

Re: Only 9% of visitors give GDPR consent to be tracked

#49

Earlier quoted context omitted.

More a problem of enforcement than the legislation IMO. It wouldn't take many cases to be properly litigated before publishers would understand this is a law that is to be obeyed like any other.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

Sorry, privacy as a personal responsibility has failed outright. For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc).

The GDPR is actually sufficiently abstract IMO to make government enforcement possible and practical. And if you look at how tracking evolved, much of it is still the same old cookie-setting (from what, 25 years ago?) and the stuff that isn't (like ultrasonic profile matching and other shady stuff) is pretty clearly illegal. So it just needs political will on the national level where the enforcement agencies reside. Max Schrems' cases against facebook have shown time and again that these enforcement agencies are often simply unwilling to do their job, with the Irish one being a particularly bad example. But it is possible to do this.

EDIT

Also, regarding the personal responsibility aspect: we're being tracked by platforms we don't even have a user/customer relationship or any other contract with. Someone uploads a picture of me on facebook, and they build a profile based on that? Uncool. Is that a problem between me and the uploader? Certainly. Does that take responsibility from facebook to not mine that data? Nope.

Re: Only 9% of visitors give GDPR consent to be tracked

#50
post #19

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Yes, exactly. I hoped that he would repeat the experiment with a tricky one, like the horrendous forms served by Quantcast. In those, if you click "Reject all" nothing happens! How is that even allowed boggles my mind.

That's the website fault. The Quantcast form is highly configurable, you can choose to display a "I do not accept" button on the first screen
Post reply on HN