I have mixed feelings. On one hand, the data harvesting targeted by cookie laws and associated privacy stuff is important and legislators/regulators are right to target it. OTOH, effectiveness is pretty marginal. There have been some (minor) gains on disclosure. Somewhat better progress on data selling/sharing/security. But, no real gains on consent, which is a big part of the regulatory effort and this specific case…
> no real gains on consent, which is a big part of the regulatory effort and this specific case Consent is regulated under the GDPR and the majority of consent banners/popups you see today are not compliant. For example, the regulation explicitly mandates that pre-ticked checkboxes are not compliant and that it must be as easy to accept than to decline. According to the article, this fine is for a breach of the ePriv…
Either way though, the concept of consent is similar in the GDPR. It is notable that GDPR makes more effort to define consent better, and implicitly deals with the fact that choice and such are important.
How that translates into enforcement/compliance... I guess we'll see. I think we both agree that none of these recent legislative changes (also in the US and elsewhere) have given us much improvement on consent, so far. You just might be more optimistic than me on prospects.
I think the problem is a hard one, at least within our current normative frames. A regulator has very few nearby examples to draw on, for an enforceable model of consent. They need a binary, but a broader concept of consent isn't very amenable to that.