Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

31–40 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#31

For me personally - all these popup banners and modal walls for websites about cookies and stuff just really make the internet a worse place. I suspect that empirically, they don't accomplish what the GDPR intended to - and they make the internet less enjoyable. Thanks GDPR.

The problem is that the GDPR is not being enforced properly. The GDPR explicitly bans annoying/misleading consent prompts, so this shouldn't be an issue if the law was enforced. It explicitly learned from the earlier "cookie law" which merely enforced disclosure and led to stupid & useless cookie banners with no easy way for the user to actually act on them.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#33
post #19

I recently purchased something from the official UK Nintendo Store [1]. I did not opt-in, and was not asked to opt-in, to marketing emails. Several days after purchase I received a marketing email with an Unsubscribe link. I submitted a GDPR enquiry and after a few weeks I get: Having investigated this matter fully, we can see that you were opted in as a result of a small technical difficulty which we are now fixing.…

> How Nintendo can have such a formalised GDPR enquiry process but such sloppy controls is beyond me.

Probably because only 1% of 1% of their customers even bother to notice. I'd be willing to bet money that you were the first person to discover this implementation error.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#34
post #14

For me personally - all these popup banners and modal walls for websites about cookies and stuff just really make the internet a worse place. I suspect that empirically, they don't accomplish what the GDPR intended to - and they make the internet less enjoyable. Thanks GDPR.

Same here. I would be interested to know from people outside the GDPR area - do you ever see cookie banners? Do you know what they are? Sometimes I hit a USA based news website which simply denies access, because I'm in the UK, on GDPR grounds. Which seems an overreaction.

US companies started implementing it as a result of CCPA. So it's everywhere now

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#35
post #4

Who came up with the term dark patterns? It's psychological manipulation and fraud, pure and simple

> fraud then take them to court and make a killing.

Precisely why the new term was devised: dark patterns are not, in general, technically fraud.

They are playing completely within the rules but taking advantage of human psychology to tilt the outcome in the direction the website owner wants (and, it is assumed, against what the average user wants).

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#36
post #3

This is the PDF: https://arxiv.org/pdf/2001.02479.pdf I couldn't understand how to find it on the linked site. Maybe the submission URL should be changed?

If you click "Get Access" you'll be asked to lot into a university account or such

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#37

GDPR consent buttons and statements are as worthless as the California Proposition 65 cancer warning that gets slapped on every consumer product. Any plugins to strip them out or automatically consent?

It's different from the Prop 65 warnings. Unlike those, the GDPR explicitly bans annoying/misleading consent prompts. Merely disclosing tracking isn't enough to comply, consent needs to be:

* explicitly opt-in, so no action from the user means they shouldn't be tracked - pre-ticked checkboxes are not allowed

* it should be as easy to opt-in as to opt-out, so approaches like a big "accept tracking" button but a "learn more" or putting the deny option in the fine print isn't allowed

* needs to be "informed consent", so the user should be made fully aware of what data will be collected and how it will be used

* needs to be granular, so the user should be allowed to decide what data to provide and for what purpose

* optional - you are not allowed to deny/degrade the service if the user does not consent to tracking

The problem is that the GDPR is not being enforced properly. The annoyances you are facing would not be a thing if the law was enforced. It explicitly learned from the earlier "cookie law" which merely enforced disclosure and led to stupid & useless cookie banners with no easy way for the user to actually act on them.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#38
My favorite deceptive pattern I encountered is "double click the checkbox to disable". Literally a checkbox but it wouldn't do anything. I got a little frustrated and started clicking furiously just to discover that a double click would reliably disable the items...

(I don't remember if this was on desktop or mobile, on mobile s/click/tap/g)

Also, I personally lean towards being in favor of GDPR and cookie law (wish there were some improvements though); I'd like to say it just because every opinion you find is "GDPR useless", "cookie law bad"

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#39
post #18
post #14

Earlier quoted context omitted.

Same here. I would be interested to know from people outside the GDPR area - do you ever see cookie banners? Do you know what they are? Sometimes I hit a USA based news website which simply denies access, because I'm in the UK, on GDPR grounds. Which seems an overreaction.

EVERY WEBSITE I visit from my location in the USA seems to have these stupid cookie popups. We added one to OUR WEBSITE even though nothing is hosted in the EU - simple cargo-culting "everyone is doing it so we must do it also". I doubt it actually does a @#$@$ darn thing.

We've had them up long enough for somebody to have generated some hard numbers by now. I wonder what the numbers look like on percentage of users that modify the settings from the default?

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#40
post #19

I recently purchased something from the official UK Nintendo Store [1]. I did not opt-in, and was not asked to opt-in, to marketing emails. Several days after purchase I received a marketing email with an Unsubscribe link. I submitted a GDPR enquiry and after a few weeks I get: Having investigated this matter fully, we can see that you were opted in as a result of a small technical difficulty which we are now fixing.…

Is the UK still subject to the GDPR now after Brexit?

Yes, part of the Brexit agreement was the UK "domesticating" some parts of EU law by passing them as UK legislation. There is now a law called UK-GDPR, which is literally a copy-paste of GDPR, with names of EU institutions find-and-replaced with their UK equivalents.

There are still some operational differences, around the fact that the UK regulators will not participate the cooperation mechanisms that the other regulators will. This ends up mattering for businesses: a significant aspect of GDPR was that a company only ever had to deal with one regulator, but now they need to interface with one for the EU and a second for the UK.

Post reply on HN