Live data from Hacker News

French watchdog fines Google, Amazon for breaching cookies rules

fr.reuters.com

111–120 of 144 posts

Re: French watchdog fines Google, Amazon for breaching cookies rules

#111
Typical nature of doing business in Europe. Arbitrary laws, borne in good faith but implemented so badly and erratically that everyone is forced to ignore them. The same laws are then wielded as a baton against whomever the state wishes to punish at the time.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#112
post #54

Earlier quoted context omitted.

Many sites, upon clicking reject, do not actually disable anything and simply suggest you disable cookies in your browser (sometimes with instructions).

Which is probably not legal.

Probably not. That's why we need legal enforcement, and not "users learn how to use the cookie options of their browsers" as these sites and the top level comment on this thread suggest.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#113

Earlier quoted context omitted.

You should probably get familiar with the actual regulation before writing such a critical comment. Of course it takes into account the finality of the cookie (or any tracker for that matter).

Can you direct me to the part of the regulations you are referring to?

It's called ePrivacy. Necessary trackers are excluded from consent. This is a directive so each country will have its specific interpretation, for the french one, you can go to the CNIL's website. The final document is not translated, but you can read the draft[1], specifically the 9th paragraph.

[1] https://www.cnil.fr/sites/default/files/atoms/files/draft_re...

Re: French watchdog fines Google, Amazon for breaching cookies rules

#114
post #93
post #81

Earlier quoted context omitted.

Session cookies for handling a login make sense. Session cookies on static pages are a violation of people's privacy.

What about a session cookie that is used for more than just authentication like for example tying browsing sessions on different devices by the same user together?

If it's only to provide the stated purpose of the site (think those "scan a QR code and approve this login on your other device" setups), it likely falls under the legitimate interest exception. If it's to provide cross device tracking for better advertising, then you need consent.

Lawyers are unlikely to take kindly to arguments of the "Well technically the advertisments are an integral part of the site", that will surely be raised in response to this. This is why the law is not code and gets interpreted by judges.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#115
post #93
post #81

Earlier quoted context omitted.

Session cookies for handling a login make sense. Session cookies on static pages are a violation of people's privacy.

What about a session cookie that is used for more than just authentication like for example tying browsing sessions on different devices by the same user together?

Is that information going to be shared with 3rd parties? Is this tracking solely for the use of the product or for profiling the user?

Those are the concerns with GDPR, you can do whatever you want if you are explicit about it AND have consent of the user.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#116

Google is fined 100 millions because tracking cookies are saved on the device before opting-in AND after opting-out, and because the cookie modal isn't clear enough. [1] Amazon is fined 35 millions for similar reasons, but the amount is lower because they acknowledged and fixed the issues in September 2020. [2] [1] https://www.cnil.fr/en/cookies-financial-penalties-60-millio... [2] https://www.cnil.fr/en/cookies-fina…

Those amounts don't seem near enough to make it financially worthwhile for them to change their behavior.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#117

I have mixed feelings. On one hand, the data harvesting targeted by cookie laws and associated privacy stuff is important and legislators/regulators are right to target it. OTOH, effectiveness is pretty marginal. There have been some (minor) gains on disclosure. Somewhat better progress on data selling/sharing/security. But, no real gains on consent, which is a big part of the regulatory effort and this specific case…

> OTOH, effectiveness is pretty marginal. There have been some (minor) gains on disclosure. Somewhat better progress on data selling/sharing/security. But, no real gains on consent, which is a big part of the regulatory effort and this specific case. From experience, a lot of folks were waiting to see what Google/Amazon/FB/etc were doing and using them as examples of what to do. These fines should help apply some dow…

I agree, and it's a good point about the industry using Google/Amazon/FB/etc as a template. I hadn't considered that in this context.

My greater reason for "scoring" progress on consent as "no real gains" is less about "compliance" and more about the goals of this compliance. What does consent mean to a non-lawyer and would do we want legislators/regulators to pursue it in the first place?

The model of consent being litigated here doesn't, imo, lead to noticeably more choice or dominion vis a vis companies. It just leads to technicalities about how popups need to be designed. Form rather than substance.

I think the reason these laws have been more effective on disclosure is that the legible, lawyerly definition of disclosure is the same as the common sense one. Consent... not so much. The actual point is not whether or not a document was correctly initialed on page 6.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#118
post #25
post #4

Earlier quoted context omitted.

Companies would still have to be mandated to respect said options, as when the voluntary DNT was added, companies went "lalala can't hear you"

Then they should’ve been fined for not respecting dnt

DNT was a browser initiative and had no legal teeth

Re: French watchdog fines Google, Amazon for breaching cookies rules

#119
post #111

Typical nature of doing business in Europe. Arbitrary laws, borne in good faith but implemented so badly and erratically that everyone is forced to ignore them. The same laws are then wielded as a baton against whomever the state wishes to punish at the time.

What makes you forced to ignore them? By default, your business is likely in compliance. It's only once you start collecting user data that you have to be careful with it.

Re: French watchdog fines Google, Amazon for breaching cookies rules

#120
post #5

Earlier quoted context omitted.

Typical Google. Let us not even get started with the impossibility of loading Google in private mode without needing to agree to everything. Rejecting all is a dance that takes more time and mental resources than the amount i want to spend for the few times I want to turn on private mode and search something. My colleagues have also declared defeat and just accept everything. Hope the fine bites.

And after Google, everyone else. I am so annoyed by sites making it a real struggle rejecting cookies. Most of the time, I just don't use those anymore. Not sure if that helps, so.

I suspect that is the goal:

1) To get people to quickly simply accept all cookies because time is money and its too complex.

2) To get scare them away. If you don't wanna be the product, at least save us money.

3) To make them waste their time (= money) on their privacy.

Boss won't like #3, neither does the wife. So its like #1. Sure, whatever. Or, those who stick to their principle and can refrain their curiosity or need for information to go for #2.

The advertising industry (I almost wrote undustry, go figure) is so rotten, that I will gladly just shell out some money to buy something of quality instead. I just gotta be sure it isn't money wasted ie. that I (or whoever I buy it for) will use it. With advertising services which are free, the real product is also the demo, but their model is to get you hooked.

Post reply on HN