Live data from Hacker News

Automating cookie consent and GDPR violation detection

usenix.org

131–140 of 252 posts

Re: Automating cookie consent and GDPR violation detection

#131

Earlier quoted context omitted.

If the law is right, but not possible to enforce, some fixing may be needed

IMO, the problem with GDPR is the same problem we have with a lot of European laws. There's nobody who's incentivized to enforce compliance. If you were able to sue for GDPR violations, either on your own or in a class lawsuit, you would have an incentive to prove that the violation has indeed occurred. As long as your lawyer was working on commission, they would share that incentive. As it stands, all you can do is…

> Enforcement was partially privatized, and the free market, as it often does, found a better and more efficient way of enforcing the law than the government could dream of.

I'm not a fan of this. You're replacing one kind of dark-pattern wielding, stain-on-underpants-of-society, predator with another!

You will spawn industries of failed lawyers going after the easy money, i.e. clueless everyday people who inadvertently misconfigured wordpress and can't afford a lawyer when they get threatened with court cases if they don't pay the extortion fees.

Just like asshole copyright lawyers under Germany's shitty jurisdiction extending their disgusting and threatening attacks on everyday citizens around Europe who dare to have a personal webpage without being experts in copyright law. As with ad-tech, also not the kind of enterprises we need to have in our society. Also wouldn't shed a tear for that industry to just die.

If you do this kind of thing you need to directly target the companies enabling the illegal behavior, not the website owners.

Re: Automating cookie consent and GDPR violation detection

#132
post #56

Earlier quoted context omitted.

> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. You can. Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Reg…

As to the theory, I stand corrected! As to the practicality of suing for violations, how would you quantify "damaged suffered" from saving a cookie in my browser?

>As to the practicality of suing for violations, how would you quantify "damaged suffered" from saving a cookie in my browser?

The GDPR does not regulate cookies at all, at least unless they are a form of processing of personal data, so you wouldn't be able to sue for that.

It's the ePrivacy Directive that deals with cookies (and storing/accessing other data on your devices), and that lacks any sort of private cause of action, at least at the EU level. Directives (unlike Regulations) have to be transposed in to domestic law in EU member states, so depending on where you are there might be a private enforcement mechanism, but I doubt it.

Re: Automating cookie consent and GDPR violation detection

#133
Brave has an option to block cookie notices - you need to enable the "Filter obtrusive cookie notices" list in brave://adblock. https://twitter.com/shivan_kaul/status/1488989740690853888

We're experimenting with blocking cookie notices by default in Nightly. There's webcompat risk - some websites just break if you block the cookie notice. "Works on 90% of websites" is just not good enough when deploying to 50 million Web users.

Re: Automating cookie consent and GDPR violation detection

#134

Earlier quoted context omitted.

If the law is right, but not possible to enforce, some fixing may be needed

IMO, the problem with GDPR is the same problem we have with a lot of European laws. There's nobody who's incentivized to enforce compliance. If you were able to sue for GDPR violations, either on your own or in a class lawsuit, you would have an incentive to prove that the violation has indeed occurred. As long as your lawyer was working on commission, they would share that incentive. As it stands, all you can do is…

You can actually sue under the GDPR and get compensation.

Article 79 explicitly gives data subjects "the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation"

Article 82 states that if someone has "suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered".

Re: Automating cookie consent and GDPR violation detection

#135

It's pretty well known that cookie-walls are rife with anti-consumer patterns. Going to something like formula1.com requires me to click more than a 100 times to object to the 'legitimate interests' of as many companies. Which is a pretty terrible anti-pattern when I don't want to be tracked at all... After reading the abstract, it seems the authors try to classify cookies using a special browser extension called "Co…

> Going to something like formula1.com r

Not sure if this is because i'm in the states, but 'manage settings' has a 'reject all' button for me[0] and it seems to work.

0: https://i.judge.sh/0vCJB/q_nQ34wtjO.png

Re: Automating cookie consent and GDPR violation detection

#136

Earlier quoted context omitted.

I agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism). My thinking goes like this: 1. The law explicitly talks of requesting consent. 2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc) 3. People get constant intrusions wasting ou…

The most common use of “tracking” cookies is just to be able to count unique views for your site, which I think is a perfectly reasonable thing to want to do. Knowing the impact of your site is something pretty much every website producer (including governments, individuals, and businesses) wants to do. Other examples of where cross-site tracking is useful is for preventing online payments fraud. You have a similar I…

> The most common use of “tracking” cookies is just to be able to count unique views for your site, which I think is a perfectly reasonable thing to want to do.

Sure, and I don't remember if this is currently legal without need to notify/ask, but I think it should be.

As long as the tracking data is legally and technically isolated to only domains/apps/devices controlled by the same entity... Most people have the expectation that a website/business will be able to remember them across visits from the same browser.

But people will not necessarily have this expectation of being recognized across domains or different devices - indeed most people won't know it's even possible - so anything facilitating such identify/profile correlation should be considered illegal tracking by default. The specific technical method of creating the correlation should not matter. Honestly this could extend to non-web profile building as well.

The exception, of course, is if the user has self-identified by logging in.

> Other examples of where cross-site tracking is useful is for preventing online payments fraud. You have a similar IRL version of this where your bank will freeze your card if it sees purchases being made in different countries simultaneously.

True, completely agree. There are already blanket exemptions for certain uses in the GDPR and those should be extended as needed for use cases that have legitimate value. Cookie law should be changed so no need to ask/inform the user about these use cases other than in the website's privacy statement, where such tracking should be stated.

Industries handling such tracking data should be regulated and audited to ensure proper handling and use of the data. Again I think this should be applied as a broader principle, and I think for example loyalty programs should be also audited to ensure compliance with legal uses of the collected data.

Re: Automating cookie consent and GDPR violation detection

#137

Earlier quoted context omitted.

I don't think "enforce" means what you think it means. If you are contacted about a GDPR matter usually you have time to fix it before it's "a violation" that incurs penalties.

It's "squishy" terms in law, like "usually" that I find bothersome. Granted, I haven't read the complete specifics of all of the minutia when it comes to the GDPR, I'll admit. I do keep cookies by default though, as a habit, which seems to be in violation of GDPR rules. Should I start publishing a blog or some such which was antithetical to the prevailing party doctrine, that happened to gain traction with the public…

Enforcement action must be "proportionate", so even if you are pulled up by a supervisory authority it's unlikely they're going to give you a massive fine straight off the bat - especially if you are trying to comply and can demonstrate that.

Re: Automating cookie consent and GDPR violation detection

#138

I run a website with a few hundred thousand monthly active users. I get tons of mails from users telling me how much they love it. One unintrusive, smallish Adsense banner pays for everything. For years now, everyone was happy. Now Google sent me an email that they want me to gather user consent before showing Adsense. They offer an automatic consent modal. But the problem with that one is that it not only displays t…

> And of course loading the consent script from Google before getting consent is not in line with GDPR in the first place.

Only if Google uses that information whatsoever. They'd be on the hook if they run afoul of GDPR by collecting information when it's obtained before consent happens, and I'm sure the enforcement agency isn't going to fault the web admin for taking Google's word on compliance.

Re: Automating cookie consent and GDPR violation detection

#140
post #35

Earlier quoted context omitted.

Necessary site functionality, without the spyware. Unfortunately, most websites sites are funded by spyware, so the minimum cookies to keep the internet economy running would have to include the spyware.

Disagree. Let it burn, it's the only way. (change my mind?) This made me think of the Ukraine war, and how the sanctions may turn out to be a bigger help to climate crisis than any political entity could muster on the basis of the impeding climate snafu. Sometimes radical action is the right course of action; for democracy-(pre)serving reasons our governance systems often inhibit change unless most of the population…

"This made me think of the Ukraine war, and how the sanctions may turn out to be a bigger help to climate crisis than any political entity could muster on the basis of the impeding climate snafu."

Huh? Here in germany there is talk by politicians that climate policies have to stand back now and we need to rely more on the coal plants and not close them, as it was planned.

I really hope, that the actual solutions will be more renewables and nuclear, but I am a bit pessimistic about it.

Post reply on HN