Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

301–310 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#301

Earlier quoted context omitted.

Incognito basically just means "doesn't show up in my history". There are many, many, ways to track users without needing cookies.

> doesn't show up in my history AND drop all cookies from all domains. > There are many, many, ways There probably are. I haven't ever seen it work though. If I get into incognito, my ads show something different my normal profile. In theory, they can track you from your OS/browser combination (and many more variables), but is there a way to test it?

The EFF has a great tool demonstrating the method: https://panopticlick.eff.org/

It’s not theoretical; it’s used in practice today.

Re: Only 9% of visitors give GDPR consent to be tracked

#302
post #96

I would say that it means 9% of visitors "click away" any banner they see without reading it. And usually clicking "yes" will do away the banner in the most hassle free way. I am surprised the number is so low. I surely click "Yes" on any banner immediately without reading it. My guess is that the number was so low because his banner (by its simplicity) looked unusual enough that many people read it. With the typical…

I'd be interesting to perform another test, with "No" and "Yes" buttons swapped (and the banner text updated accordingly).

Re: Only 9% of visitors give GDPR consent to be tracked

#304

Earlier quoted context omitted.

I have the complete opposite view. Companies provably can't be trusted on anything touching privacy, and individuals don't have any power to act on it. Governmental oversight and bureaucracy is the only tool that works for a problem like this. It's a proven, efficient, and universally approved way to already enforce food, fire, travel safety and so on. It's only logical that privacy safety follows the same steps. GDP…

But privacy isn't like food, fire or travel safety. Even assuming absolute cynicism it isn't very exploitable for them to use it for bad purposes. I liken the difference between actors to a housecat and a large dog with a lamb. The cat at worst could give some scratches but at worst would probably just annoy the lamb jumping into its wool and kneading it. The dog ideally would look after tbe lamb but could also infli…

I'll actually argue that it very much is.

First, there's the historic precedent of collected information eventually making it into the wrong hands. The Preussian "pink lists" are a classic example, but essentially everything that ended up as PRISM can be taken as a more modern example.

And yes, putting power into government hands so regulate the collection of that data, and then arguing that it's dangerous because of the government might seem a bit contradictory. It's not in my mind. These types of legislation are supposed to disincentivize the collection by private entities after all. Government and intelligence services are (too) close but they are distinct.

And then there's the very real [1] ([2] if you want it more juicy) possibility of corporations targeting individuals for one reason or another directly. Here in the west, this sort of thing would result in your Uber becoming more expensive or unavailable, but imagine being a government critic (or activist against e.g. organized crime) in Brazil right now. All that data going god-knows-where, with the express intent of the collectors to sell it to anynone? Not a great outlook.

[1]: https://en.wikipedia.org/wiki/Greyball [2]: https://news.ycombinator.com/item?id=23529035

Re: Only 9% of visitors give GDPR consent to be tracked

#305

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

DockerHub uses a company/product called "TrustArc: TRUSTe" and they have _exactly_ this method. The slowdown is intentional. People who come up with sort of tactics and those who implement them should go to jail. It's beyond infuriating. I've decided to not upload my images to dockerhub because of this. Edit: jail time is not for anger obviously, but for intentionally swindling people. It'll be handled on a case by c…

> The slowdown is intentional.

Yes, it appears to be. If you check the network tab of your browser, you see it makes about 8 requests. Then it waits for about 5-10 seconds and makes again 5 requests.

Re: Only 9% of visitors give GDPR consent to be tracked

#306

Earlier quoted context omitted.

Perhaps I’ve oversimplified a bit. GDPR has a paragraph that’s often called the “coupling prohibition” - Article 7(4): > When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia , the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. It som…

This really shouldn't be left to interpretation, both Article 7(4) and Recital 42 define what is "freely given consent" and in no way limits the actions i can take as a site owner. It is clear that a "cookie wall" isn't considered a "freely given consent" so you can't process personal data based on that.

Correct you can’t process personal data based on it. And the underlying implication is that none of the consent you’ve obtained via a cookie wall is valid because you haven’t given any users the opportunity to “refuse without detriment” (because their options are to consent or see nothing). So the information you’re processing on behalf of users who clicked “I agree” - even the users who do in fact knowingly and willingly agree to the information processing - might be lacking a legal basis.

Re: Only 9% of visitors give GDPR consent to be tracked

#307

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

It's the official solution created by Interactive Advertising Bureau and as the standard way to opt-out for all the companies in this organization: https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...

There are serious doubts if this is a complaint way to handle cookie consent.

Re: Only 9% of visitors give GDPR consent to be tracked

#309
post #205
post #192

Earlier quoted context omitted.

GDPR doesn't actually require consent to process personal data. It requires that the processing be lawful . Consent is one basis for lawfulness, but it is not the only one. There are 5 others. One of these is that the processing is necessary for the performance of a task carried out in the public interest. You could probably make a colorable argument that research for publication into the effectiveness of GDPR implem…

Not if you're a private company or an individual

That basis of lawfulness, from Article 6 section 1(e), is "processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller".

On the face of it there doesn't appear to be any restriction on who can use that basis.

The only recital I've found that mentions this is Recital 45. It says:

> It should also be for Union or Member State law to determine whether the controller performing a task carried out in the public interest or in the exercise of official authority should be a public authority or another natural or legal person governed by public law, or, where it is in the public interest to do so, including for health purposes such as public health and social protection and the management of health care services, by private law, such as a professional association.

That seems potentially pretty expansive.

Re: Only 9% of visitors give GDPR consent to be tracked

#310

Earlier quoted context omitted.

A meal paid for by money is a transaction where both parties understand what’s being exchanged. Not paying for it criminal. A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down?

> A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down? I'm not sure that'd be viable in general, like what would the economic impact globally if all websites that barely can manage to keep the lights on today because of effective ads just disappeared? Maybe the impact could be even positive, like by disallowing politically very-targeted ads, among all other kinds of targ…

I wouldn't miss it. If they can find a viable non-tracking business model, I'd imagine most would. People used to pay for newspapers so there's pretty good precedent.
Post reply on HN