Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

61–70 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#62
post #58
post #22

Earlier quoted context omitted.

We should have GDPR settings in the browser.

You mean, like a checkbox that sends a `DNT` header set to `1`? I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header. † the consent (or rather, intent not to consent) is explicit, and although non-interactive at the site level it was interactive at the browser level until MS defaulted…

> I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header.

Then I think that's the best kept secret of the industry.

Re: Only 9% of visitors give GDPR consent to be tracked

#63

Earlier quoted context omitted.

Thing is, if someone can show that they were tricked into giving consent when they were not willing to, then you're still in violation of GDPR. So those convoluted forms might not give those companies the legal protection they they hope for. And yes, I'd assume the "phony consent" rate to be much higher, because in some cases I also cannot find the no button and/or accidentally tap on the huge yes button on my phone…

How do you prove you were tricked into giving consent to tracking?

I think it is responsibility of the company to show that meaningful consent was freely given.

Re: Only 9% of visitors give GDPR consent to be tracked

#64
post #45

Earlier quoted context omitted.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

In 2016, I think, there were 0 airplane crashes and 0 air travel fatalities. Across 200 countries, hundreds of airlines and several airplane manufacturers, probably thousands of airports, millions of flights. If you think that was an easy feat, then I don't know what to tell you. Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy. When people really care, bureaucracy works wonders…

And the aviation industry is not exactly a massive innovator at this point. The most commonly used commercial aircraft today were developed before the world wide web was even a thing.

Why don't we just skip a few steps ahead - delete the internet and go back to cable TV? That's where we're headed for anyway.

Re: Only 9% of visitors give GDPR consent to be tracked

#65
post #54
post #40

Earlier quoted context omitted.

Yeah, no. This about the ePrivacy directive, if you don't have proper consent, you can't read/write tracers regardless of wether this is personnal data or not, except for tracers needed to establish the communication or demanded by the user (carts, login, etc). EDIT: Thought about it, and if you only record the button click and does not identify the user, it works, and I am wrong! In general ePrivacy is very restrict…

There’s no tracer. Just a counter of how many said yes vs how many said no. There’s no personally identifiable information there

the downside of this method is that it is impossible to discard duplicated negative answers.

Re: Only 9% of visitors give GDPR consent to be tracked

#66
post #58
post #22

Earlier quoted context omitted.

We should have GDPR settings in the browser.

You mean, like a checkbox that sends a `DNT` header set to `1`? I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header. † the consent (or rather, intent not to consent) is explicit, and although non-interactive at the site level it was interactive at the browser level until MS defaulted…

Technically with GDPR defaulting to 1 is the only correct option. MS were only ahead of the time :)

Re: Only 9% of visitors give GDPR consent to be tracked

#67
post #4

Unless they do browser fingerprinting, the number will be overinflated by all the people like me who clear their cookies regularly, if not on every browser session, and are therefore re-asked consent on every single visit.

that should not matter, the obvious choice would be to ask every time until they say yes. It is also the simpler choice, if the user opts out of all tracking then you cannot track their choice.

Re: Only 9% of visitors give GDPR consent to be tracked

#68

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

I think they're all Quantcast websites. I like that Firefox extension that adds a "I refuse" button: https://addons.mozilla.org/en-US/firefox/addon/qookiefix/

Re: Only 9% of visitors give GDPR consent to be tracked

#69

Earlier quoted context omitted.

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

Which is why GDPR, although theoretically a good idea, is pretty much useless in practice. I'd like to see how many websites offer a reasonable consent widget that doesn't opt you in by default, keep nothing checking but a huge button to tick and accept, or the usual million-and-one checkboxes to untick, and many other cheap tricks that even the most vigilant of consumers will fall to at some point. I use everything…

> Which is why GDPR, although theoretically a good idea, is pretty much useless in practice.

This is very much not true. GDPR isn't restricted to regulating tracking on websites. It also restricts and regulates what companies can do with the customer data they are in possession of. Through my day job I constantly interact with large enterprises (Fortune XXXX) that have vast amounts of personal data through their regular operations (banks, telcos, car manufacturers, airlines, insurance companies and the likes). Nearly without exception they go to great lengths to ensure the data is managed correctly, not used for purposes the customer hasn't explicitly consented to etc. This is as a direct result of the GDPR.

Re: Only 9% of visitors give GDPR consent to be tracked

#70

Earlier quoted context omitted.

I honestly don't trust governments/bureaucrats to be able to come up with a solution for this issue. This is one of those problems that evolves very quickly, and the solution probably needs to be done by a private company or by each person individually.

Sorry, privacy as a personal responsibility has failed outright. For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). The GDPR is actually sufficiently abstract IMO to make government enfor…

>For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc).

But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet has gained massive popularity because most of the resources on it are free. Look at porn - all of the known sites and run on ads, all the paid sites are essentially unknown. I don't know anybody who uses the latter. Wouldn't Facebook, Twitter, news sites etc have gone the same way if they required you to pay? Just look at what happens when a paywalled article gets posted. Either somebody posts a way to bypass it or a lot of people will never read the article.

Post reply on HN