Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

51–60 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#51

How cycnical - an article further down (Two young scientists built a $250M business using yeast to clean up wastewater) links to Forbes.com that indeed allows me to set my tracking preferences.However, anything other than 'accept' will result in a message stating 'we are processing the request this may take up to a few minutes'. So they can set hundreds (yeah - that is right, I have seen pages tell me they wanted 500…

This is like the companies that mysteriously lack the ability to unsubscribe you from their mailing lists in less than 30 days, even though plenty of us manage to run systems that normally do it in real time.

Re: Only 9% of visitors give GDPR consent to be tracked

#52
post #40

Earlier quoted context omitted.

It's not personal data, so it's not under the scope of GDPR.

Yeah, no. This about the ePrivacy directive, if you don't have proper consent, you can't read/write tracers regardless of wether this is personnal data or not, except for tracers needed to establish the communication or demanded by the user (carts, login, etc). EDIT: Thought about it, and if you only record the button click and does not identify the user, it works, and I am wrong! In general ePrivacy is very restrict…

GDPR defines what is PII and then regulates when companies may use PII. A page visit counter collects anonymous data. Anonymous data is not PII. You cannot tell I was their 345th visitor.

>> Yeah, no.

Exactly.

Re: Only 9% of visitors give GDPR consent to be tracked

#53
post #41

The article says mobile users are more likely to engage with the banner. Rightly so, cause it takes up precious screen real estate. What are some ways I can protect myself more when browsing the web through my phone?

Depends on the phone, but generally you can't protect yourself as well as on PC, because phones (sadly) are locked down devices running proprietary software. Best you can do is probably DNS-level blocking.

Firefox on Android with ublock works just fine.

Re: Only 9% of visitors give GDPR consent to be tracked

#54
post #40

Earlier quoted context omitted.

It's not personal data, so it's not under the scope of GDPR.

Yeah, no. This about the ePrivacy directive, if you don't have proper consent, you can't read/write tracers regardless of wether this is personnal data or not, except for tracers needed to establish the communication or demanded by the user (carts, login, etc). EDIT: Thought about it, and if you only record the button click and does not identify the user, it works, and I am wrong! In general ePrivacy is very restrict…

There’s no tracer. Just a counter of how many said yes vs how many said no. There’s no personally identifiable information there

Re: Only 9% of visitors give GDPR consent to be tracked

#55

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Quantcast claimed a 91% any consent and 80% total consent rate for a sample point of a more unethical implementation: https://martechtoday.com/quantcast-reports-more-than-90-of-v...

Re: Only 9% of visitors give GDPR consent to be tracked

#56

Earlier quoted context omitted.

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

I can only speak for myself, but actually I go to the detailed cookie settings and unselect everything I'm not ok with. In particular, I unselect ga and Fb pixel because I believe the habit of collecting visit data at an all-seeing central site isn't worth it, and actually is the major characteristic of a dystopian future that hacker culture has always been opposed to. If the consent settings are rubbish, I don't bother and leave the site; OTOH, if the settings are reasonable, I usually accept optimization and some analytic cookies.

I can't stress enough how much of a game changer that is, by revealing the amount of third-party trackers on websites (in the order of up to 500 on a single site) alone.

So I guess GDPR works for me. There's a lack of enforcement, though. But that could change; for example, in Germany, bored law firms (eg those not having clients currently), or anybody actually, can print money by starting an "Abmahnwelle" eg. insist on GDPR compliance within a certain period of time, then sue any site for non-GDPR compliance, all the while being entitled for compensation of their expenses if they have a cause.

Re: Only 9% of visitors give GDPR consent to be tracked

#57
post #22

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

We should have GDPR settings in the browser.

Most sites already ignore the "do not track" flag from your browser.

Re: Only 9% of visitors give GDPR consent to be tracked

#58
post #22

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

We should have GDPR settings in the browser.

You mean, like a checkbox that sends a `DNT` header set to `1`?

I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header.

† the consent (or rather, intent not to consent) is explicit, and although non-interactive at the site level it was interactive at the browser level until MS defaulted it to `1`. Now I'm wishing it were like those notifications/location/webcam/mic access and the dialogs were required to go through the browser itself.

Re: Only 9% of visitors give GDPR consent to be tracked

#59
post #45

Earlier quoted context omitted.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

In 2016, I think, there were 0 airplane crashes and 0 air travel fatalities. Across 200 countries, hundreds of airlines and several airplane manufacturers, probably thousands of airports, millions of flights. If you think that was an easy feat, then I don't know what to tell you. Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy. When people really care, bureaucracy works wonders…

> 0 airplane crashes

I presume you meant commercial aviation, rather than aviation in general. Unfortunately not quite true even there. Your broader point stands though.

https://en.wikipedia.org/wiki/Category:Aviation_accidents_an...

Re: Only 9% of visitors give GDPR consent to be tracked

#60

Earlier quoted context omitted.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

they just need to crack down much harder on websites and hand out big fines for dark patterns until the websites switch to sane defaults. It's just a question of how much the companies in question believe that the EU is going to come after them. Once the cost calculus shifts to being on the safe side it'd quickly turn into a norm, but it requires showing some teeth.

It's already happening, but slowly, slowly. The various agencies need time to get their act together, and have started with the most egregious excesses. It seems rather unlikely at this point that consent forms that apply inappropriate pressure - explicitly called out in the GDPR as invalid - will somehow escape enforcement. I'd expect invalid cookie banners to be on the chopping block sometime fairly soon.

Additionally, the risks to advertisers and websites are quite large, which I'm not sure they fully appreciate (unless I'm misunderstanding something here?) - it's not that the consent form is illegal, after all - perfectly legal to have a confusing consent form. Rather, it's that all the personally identifying information thus collected is illegal acquired and held (and it's hard to argue the violation wasn't intentional, to boot!), and the fines for that can be quite large, and can be applied retroactively to whenever the GDPR came into force. Rules always get stretched, but specifically in this way sounds pretty unwise (unless they're cynically trying to have some subsidiary go bankrupt or otherwise encapsulate the risk).

With any luck, the GDPR norms on this front will become global norms, but it's too early to tell.

Post reply on HN