Live data from Hacker News

Automating cookie consent and GDPR violation detection

usenix.org

51–60 of 252 posts

Re: Automating cookie consent and GDPR violation detection

#51
post #8

Oh the irony of this site itself having a "we use cookies, got it?" banner while lamenting this exact perceived lack of choice. I always laugh a little when I see those anyway, knowing that my browser's settings and privacy extensions are blocking the cookies and tracking connections either way. Did we consider that if everyone is breaking the law, the law itself might need a rework?

> Did we consider that if everyone is breaking the law, the law itself might need a rework?

I think GDPR assumed companies would like to do right by their visitors. I guess the only way to do that is to increase the severity of the consequences for violating user trust. GDPR itself offers a guideline that many seem to misunderstand... you don't need a popup for every kind of cookie.

I'm not against enforcing minimal tracking as default, and opting into cookies should be similar to going through a purchase flow... because it is one, just using "data" as a currency. So yes, convince me to click the "Buy cookies" button.

Re: Automating cookie consent and GDPR violation detection

#52

I wonder what is the GDP cost of millions if not billions of people dismissing a cookie pop-up every day, often multiple times a day.

That cost should be paid by the companies forcing pop-ups onto users. Popups in no way GDPR's fault. The law does not mandates them. Instead, it's a form of malicious compliance. Companies pester visitors with popup banners that are almost always unnecessary. E.g. GDPR allows essential cookies e.g. a login cookie containing an encrypted token without any popup. If you want to notify users about it for extra safety yo…

I'm not sure it's malicious compliance. When you are threatened with massive fines for non-compliance but you aren't told explicitly about how to solve it other than, "A cookie notice would be a way of complying", everyone will use a cookie notice.

Re: Automating cookie consent and GDPR violation detection

#53
post #35

Earlier quoted context omitted.

What's the definition of minimum cookies?

Necessary site functionality, without the spyware. Unfortunately, most websites sites are funded by spyware, so the minimum cookies to keep the internet economy running would have to include the spyware.

[deleted]

Re: Automating cookie consent and GDPR violation detection

#54
post #38

Earlier quoted context omitted.

> Did we consider that if everyone is breaking the law, the law itself might need a rework? No, GDPR is doing tons of good works. The whole web is a privacy and security nightmare and we've been tolerating this mess long enough. Many companies are engaging in malicious compliance by annoying users with popups and push the blame onto GDPR. The reality is that 99% of websites need zero cookies, zero popups and no loggi…

Sure, but you have to also accept that there are aspects that have made the internet a worse experience without actually improving the situation from a privacy point of view.

To be fair, the GDPR does outlaw all the things we find annoying with the cookie banners (or rather, data processing consent flows, as they cover more than just cookies).

The problem is continuous lack of enforcement and distinct lack of billion-dollar fines everyone was fear mongering about, which allows companies to passively-aggressively pretend to comply by making their banners annoying on purpose to mislead people into hating the GDPR.

This problem would be resolved overnight (and everyone's privacy increased by orders of magnitude, since spyware would become illegal again) if those fines actually started coming down.

Re: Automating cookie consent and GDPR violation detection

#56

Isn't there insane money to make just suing everybody in breach of gdpr? I always thought there were laywers scouring the internet in search of a quick buck.

I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. Basically I don't think there's any money for the lawyers to pick up here.

> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case.

You can.

Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

Article 82 also states that "any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered."

Re: Automating cookie consent and GDPR violation detection

#57
post #37

Earlier quoted context omitted.

What's the definition of minimum cookies?

As close to none as possible.

And, to make it even more precise, I would call cookies, which are for login, also as non-essential, unless a visitor really wants to log in, meaning they navigate to the login page.

This means, that be default, I don't need any cookies, because I don't want to log in to most websites I visit. Only if I want to log in, I have need for such cookies.

Re: Automating cookie consent and GDPR violation detection

#59
post #39
post #8

Oh the irony of this site itself having a "we use cookies, got it?" banner while lamenting this exact perceived lack of choice. I always laugh a little when I see those anyway, knowing that my browser's settings and privacy extensions are blocking the cookies and tracking connections either way. Did we consider that if everyone is breaking the law, the law itself might need a rework?

The law is fine. Great even. It is just that most websites don’t comply and developers misunderstand it. You can freely use cookies like we used to do, for session id’s, shopping carts etc. Once you add stuff to your shopping cart, you have a business relationship with the site, and they can store cookies necessary basic functionality. You can not use them to track users on third party sites, or store personally iden…

> developers misunderstand it.

Then maybe the law needs some adjusting to make compliance more manageable.

Re: Automating cookie consent and GDPR violation detection

#60

Isn't there insane money to make just suing everybody in breach of gdpr? I always thought there were laywers scouring the internet in search of a quick buck.

Wouldn't that just end up in the hands of whatever government is relevant? I believe the fines you pay for GDPR violations are paid to governments, not users or suers.

Administrative penalties (those levelled by the supervisory authorities) do go to the state, but one can receive compensation for damages caused by infringement of rights under the Regulation.
Post reply on HN