Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

81–90 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#81
Surprised no one has mentioned the systems that, if opted out of, redirect users to a 'privacy policy' page and won't allow access to content without opting in.

Or the sites that don't bother with compliance and just show a message to the effect of 'this site operates under a jurisdiction that may have different privacy laws to your country' and leaves it at that.

Re: Only 9% of visitors give GDPR consent to be tracked

#82
post #60

Earlier quoted context omitted.

they just need to crack down much harder on websites and hand out big fines for dark patterns until the websites switch to sane defaults. It's just a question of how much the companies in question believe that the EU is going to come after them. Once the cost calculus shifts to being on the safe side it'd quickly turn into a norm, but it requires showing some teeth.

It's already happening, but slowly, slowly. The various agencies need time to get their act together, and have started with the most egregious excesses. It seems rather unlikely at this point that consent forms that apply inappropriate pressure - explicitly called out in the GDPR as invalid - will somehow escape enforcement. I'd expect invalid cookie banners to be on the chopping block sometime fairly soon. Additiona…

I'm pretty sure GDPR states that it must be opt-in in a non deceiving manner.

Re: Only 9% of visitors give GDPR consent to be tracked

#83

GDPR opt-in questions train people to accept forms without reading or thinking. I think this will be dangerous. And I'm really irritated that I can't access local news sites in America because they aren't compliant -- so they blanket ban European access. That's deeply problematic.

>And I'm really irritated that I can't access local news sites in America because they aren't compliant -- so they blanket ban European access. That's deeply problematic.

The usual answer I get when I complain about this is either "It doesn't happen to me" or "They wanted to steal your data. You're better off without being able to use their site."

I've yet to be convinced by either argument as a European. It's almost like a knee-jerk reaction by some Europeans that if Americans do something we don't like then they're automatically in the wrong.

Re: Only 9% of visitors give GDPR consent to be tracked

#84

I must say I'm really surprised. I'm a frontend developer and probably more keen to keep an eye on this stuff but there are lots of times where I just say yes because the popup is in-my-face and I just want to scroll to the content. I guess where the article falls flat is where the author says a "proper GDPR content banner" was implemented. No online publication will do this. At least they will trick you with button…

> but there are lots of times where I just say yes because the popup is in-my-face and I just want to scroll to the content. I am exactly the same. I use UBlock Origin and Privacy Badger so pretty much nothing gets through anyway but just to get rid of the banner, I click on OK. However, that being said, I only do it if the other choice is "Manage Preferences" or something equally vague: If I am given a clear yes-or-…

I sort of think this kind of behavior is problematic. I also do it often, but for example Gitlab offers some level of tracking: Necessary, Functional, Performance, and Personalization with the first three preselected. there is also a Show details for more information.

I see no reason to turn off Performance and Functional in most cases.

Re: Only 9% of visitors give GDPR consent to be tracked

#85

Earlier quoted context omitted.

Thing is, if someone can show that they were tricked into giving consent when they were not willing to, then you're still in violation of GDPR. So those convoluted forms might not give those companies the legal protection they they hope for. And yes, I'd assume the "phony consent" rate to be much higher, because in some cases I also cannot find the no button and/or accidentally tap on the huge yes button on my phone…

How do you prove you were tricked into giving consent to tracking?

Record screen sharing of 50 people that you instruct to withdraw consent. If 5+ of them fail, you have made your point that the UI is too misleading to provide legal compliance with GDPR => they are now liable for high fines

Re: Only 9% of visitors give GDPR consent to be tracked

#86
This research is interesting because it's highly relevant given Apple's upcoming changes to tracking consent in iOS 14. Unlike the DNT[0] header Apple are in a position to enforce apps actually respecting the users consent preference, either by technical means or by kicking offending apps off the App Store. The walled garden has many problems but this is one of the benefits. Given that almost all apps and websites have implemented GDPR's consent management in a supremely user hostile way[1] that is far from an equal binary choice I suspect we'll see much higher opt out rates in iOS 14. I've seen people argue that users will just continue to click accept at high rates as they do with current consent management solutions, but I think this is the wrong analysis. Users click accept precisely because the amount of effort required to opt out is unreasonable, when both options require equal effort the number of users clicking accept will plummet.

0: https://en.wikipedia.org/wiki/Do_not_track_header

1: https://twitter.com/K0nserv/status/1279361112627167234

Re: Only 9% of visitors give GDPR consent to be tracked

#87
post #22

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

We should have GDPR settings in the browser.

Block any third-party cookies, and then block third-party JavaScript alltogether. Problem solved.

Oh, there's nothing like that in the so-called "HTML standard"? Maybe, just maybe, Google being the standard body might have something to do with it, when Apple have been blocking third-party cookies for years now [1], and is in the progress of banning browser APIs that can be used for fingerprinting.

Best of all, this might rollback all those HTML5 APIs that have no business being shipped with browsers, and bring back the web content we want.

[1]: https://webkit.org/blog/10218/full-third-party-cookie-blocki...

Re: Only 9% of visitors give GDPR consent to be tracked

#88
post #19

Earlier quoted context omitted.

Yes, exactly. I hoped that he would repeat the experiment with a tricky one, like the horrendous forms served by Quantcast. In those, if you click "Reject all" nothing happens! How is that even allowed boggles my mind.

That's the website fault. The Quantcast form is highly configurable, you can choose to display a "I do not accept" button on the first screen

It really shouldn't be possible not to display that button on the first screen, because opting out should be as easy as opting in. Unless the first screen also doesn't have an 'accept' button, but I've never seen that.

Re: Only 9% of visitors give GDPR consent to be tracked

#90
post #4

Unless they do browser fingerprinting, the number will be overinflated by all the people like me who clear their cookies regularly, if not on every browser session, and are therefore re-asked consent on every single visit.

I'd imagine the people who do that to be a very small percentage.

I know many people who only browse in incognito mode.
Post reply on HN