Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

241–250 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#241
post #93

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Why would anyone consent to be tracked if given a real choice? What are the benefits? The 9% look like an error.

I would certainly. Have you seen the kind of ads people can get on Youtube for example? There's some crazy bullshit there. I would regularly go to Google Ads preference page and correct their profile of myself (sadly many time that would means that I keep getting the same 2-3 ads because it then become too specific, but it's much better than the alternative). I also advise it to people that complains about ads on Youtube. It's also a great way to show people what Google can infers easily from you using your data. Luckily now Google let you pay to get Youtube without ad, so that's what I do.

If tracking means the website I enjoy get more money out of me, and that I get better ads for it, I'm all for it. For website I don't enjoy, I agree completely, I wouldn't share anything with them, but I would also try to avoid them, so essentially, I do that naturally consent or not.

Re: Only 9% of visitors give GDPR consent to be tracked

#242
post #183
post #138

Earlier quoted context omitted.

Those very much falls in the shady part. The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid The second option is really borderline, and could work out for a US-only news website, for example (arguing it doesn't cater to European residents), but would be non-compliant for a business which knowingly serve European residents.

> The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid. I don't quite understand the reasoning on that one. In Europe, and pretty much everywhere else, there are a bazillion interactions every day in the form of one party offering to provide some good or service only if the other party agrees to something. For example, the grocery store…

So, obviously, I Am Not a Lawyer, but this seems easy to explain: when you go to the grocery store and buy something, you tacitly enter into a contract (which is exchanging money for food), where both parties agree.

For someone to use your personal information, they need to have one of the 6 legal basis to do so under the GDPR. One of those legal basis is to have a contract with you (in which case, the contract will define what's allowed and what's not). Another of those legal basis is "consent", which is the one being the most discussed, as it is generally the only one ads can hope to use, so let's ignore the 4 others (legitimate interest, public interest, vital interest, legal requirement, you can easily see why trackers for ads targeting don't fit any of those).

It is generally admitted (or at least I think it is, feel free to dig around for a better source for or against that assertion) that visiting a site is not entering into a contract (probably because a contract has to be fair, and giving up personal information without your knowledge just by visiting a site isn't actually a fair? I don't know that, IANAL).

That means the only legal basis ads companies (or the site that host them) have to use your personal data is to have your consent, which is strictly defined in the GDPR (and other posters have discussed how this definition is mostly ignored)

Re: Only 9% of visitors give GDPR consent to be tracked

#243
There are some sites (e.g. sites by Vox Media like TheVerge) that are outright illegal according to GDPR. There is only "Accept" and cookie information links that don't include any opt-out options. This is not just a dark pattern, but actually not having the settings on the site. Maybe I can email them not to track me. I wonder why aren't they fined a few hundred millions so that this kind of practice stops.

So my guess overall is that GDPR is not enforced at a larger scale and we are very far from enforcing the requirement to have "Accept"/"Decline" buttons equally usable.

Re: Only 9% of visitors give GDPR consent to be tracked

#244

Assuming for a moment that the test websites didn't give a specific reason to trust them more or less than any other website operator. This means that if your website has significantly more than those 9% consent, you're either perceived as very trustworthy, or your GDPR banner is confusing (or, less charitably, deceiving) users. Would be interesting to see how the consent rates for big offenders like techcrunch, news…

I tried Tech Crunch without adblocker and I would have to click out 16 "partners" after clicking "read more" two times. There is like hundreds of "IAB Partners" of which an unspecified amount need separate opt-out on their websites. It is not clear if "select all" opts out or in on the "IAB Partners". So I guess exactly zero visitors opt out there in the intended way. So 100% "opt-in". I tried to opt-out from all to…

Yes, I've also seen the GDPR notices where there is no "select all" function and you have to manually disable hundreds of separate options.

Re: Only 9% of visitors give GDPR consent to be tracked

#245

Earlier quoted context omitted.

Then give it.... in an incognito tab haha.

Incognito basically just means "doesn't show up in my history". There are many, many, ways to track users without needing cookies.

> doesn't show up in my history

AND drop all cookies from all domains.

> There are many, many, ways

There probably are. I haven't ever seen it work though. If I get into incognito, my ads show something different my normal profile.

In theory, they can track you from your OS/browser combination (and many more variables), but is there a way to test it?

Re: Only 9% of visitors give GDPR consent to be tracked

#246

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

Slow on purpose. All incentives for the site owners are against user interests. No one benefits from users clicking to No Consent.

> No one benefits from users clicking to No Consent.

The user does. Or did you mean something else I am missing?

Re: Only 9% of visitors give GDPR consent to be tracked

#247
The GDPR is designed to be explicitly opt-in. Given compliant consent dialogs, of course very few opt in. Hopefully few enough that keeping the tracking infrastructure just for that minority isn’t worth it.

The GDPR is and should be effectively a ban on tracking ads once sites actually comply (or, in many cases - leave the EU market or go under instead).

Whether the alternative is a good solution for paying for content or if it’s the end of the majority of content online isn’t really interesting as both outcomes are better than the status quo.

Re: Only 9% of visitors give GDPR consent to be tracked

#249

Earlier quoted context omitted.

Sorry, privacy as a personal responsibility has failed outright. For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). The GDPR is actually sufficiently abstract IMO to make government enfor…

> For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet h…

That's a weird argument to make. Maybe the businesses ("services") would have not existed with these laws in existence already. The question is would the world be a better place without them. I don't think the answer to that question is so straight forward.

We as society implement laws to prevent undesirable behaviour all the time. You can certainly argue that the law against robbing banks for example has prevented business innovation around bank robbery, but I believe this is a desirable outcome, and I think most would argee.

Re: Only 9% of visitors give GDPR consent to be tracked

#250
post #183

Earlier quoted context omitted.

> The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid. I don't quite understand the reasoning on that one. In Europe, and pretty much everywhere else, there are a bazillion interactions every day in the form of one party offering to provide some good or service only if the other party agrees to something. For example, the grocery store…

Under GDPR consent can’t be “freely given” when it’s bundled as a condition of service unless the consent they’re asking for is necessary in order to perform the service. To use your example: The grocery store doesn’t need to ask if you consent to paying for an apple because if you didn’t consent there wouldn’t be any transaction to perform. Now if you paid for your apple and the cashier said okay hand over your phon…

> GDPR says they have to ask you first (usually in the form of a giant irritating banner as soon as you walk in the door) and that if you say no they have to let you buy your apple anyway.

Can you link to source for this (the part that says you can't deny access)?

Post reply on HN