Live data from Hacker News

People who press on cookie banners anything except “agree” – why do you do that?

news.ycombinator.com

201–210 of 265 posts

Re: People who press on cookie banners anything except “agree” – why do you do that?

#201
post #190

Earlier quoted context omitted.

why do you dislike targeted advertising?

People see "targeted advertising" as "I was thinking about buying a bike and it shows me ads for bikes", ie. it's showing me what I want to see . That is not targeted advertising. Targeted advertising is showing you what they want you to see when they want you to see it, or showing you the same products in a light that makes you more likely to buy them. For example, showing you unlikely or imagined bike-related probl…

you have quite a low view of people's ability to make decisions for themselves if you think being shown ads is manipulation. And I struggle to see how targeted ads are somehow worse than the same sort of 'manipulation' inherent in using an algorithmic feed like HackerNews or Twitter. Both are exposing you to things they want you to see. Yet you don't seem to have such strong opposition to those as you do targeted ads.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#203

Earlier quoted context omitted.

why can't consumers critically assess ads the way they critically assess things like this post? what makes ads uniquely menacing?

Most ads have no content that can be subjected to critical assessment. Geico's terrible comedy sketches are not designed to convince you that they have a good product – they're designed to rattle around in your mind and influence you subconsciously. To the extent that they succeed in that, they make people behave less rationally, and are of negative social utility. And if they don't succeed, then they're just a point…

I certainly can critically assess Geico's ads - just like you did in your analysis above

So your real issue is that people are spending their time and energy on something you don't like

Re: People who press on cookie banners anything except “agree” – why do you do that?

#204

Earlier quoted context omitted.

> The easiest way to avoid having a banner on your site is to... just not have an analytics package on your site. What if there's back-end only analytics? Does that require a banner?

If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)

No.

You only need consent if there is absolutely no reason for you to have that data. Consent is the emergency hatch, only to be used in exceptional circumstances.

"But what gives?!", I hear you think. As a law professor said (roughly): it was truly amazing to see how an entire industry colluded so swiftly and completely to undermine legislation.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#205
post #199

Earlier quoted context omitted.

My understanding; ip adresses are considered personal information. You are allowed to store them in your log for security purposes, without consent (legitimate interest). But if you use that log for analytics, you need consent.

Are you sure about this? Parsing the logs stored for legitimate interest and then aggregating from that data for another purpose without storing PII seems to me like fair game.

You can't process personal data "for legitimate interest" per se. This is the biggest lie the adtech industry keeps telling themselves. The LI exception is that you can process personal data to do X with fewer restrictions, if you have a legitimate interest in X. For example, all companies have a legitimate interest in certain employee data e.g. legal names / tax identification. More complex, if you run an insurance company, you have some legitimate interest in a broad swath of your customer's demographic data.

The case for legitimate interest in parsing logs is extremely weak. There are situations where you could claim it but it still must be with a clear purpose. E.g. a Spanish company considering opening a branch in France might collect IPs to make a heatmap of where its French customers are. But they would not be able to use those IPs generally, to the extent e.g. they might be expected to delete the IP and only store aggregated by department.

You also said PII, not PD - note that some PII is sensitive data, which cannot be collected under LI provisions at all.

(This is not legal advice. If you think you can collect personal data with the LI exception, godspeed and I hope you have a good lawyer.)

Re: People who press on cookie banners anything except “agree” – why do you do that?

#207
post #194

As others have said, I usually click "refuse" or accept the very minimum possible, if it doesn't look fishy. If there's too much work, like I have to uncheck every one of a zillion boxes, or if there's the trustarc or what's-it-called that needs to "work on it" for 10 minutes, I just leave the site. I do this in the hopes that someone in marketing looks at the stats of people specifically refusing, takes note, and ma…

Funnily enough, "accept tracking or pay subscription" is very much illegal under GDPR. Lack of consent to tracking may not alter functionality of the site. In other words, service providers are not allowed to discriminate against users based on their tracking preference.

Which is so messed up, since ads based off tracking pay so much more than ads with no tracking, many sites would be forced to provide content while losing money doing so.

The argument 'for' this is that people think it's better that those sites just don't exist at all, which I would hate to see. Forcing companies to lose money will just lead to the big tech companies, that can simply tank the losses, will grow even larger, now with a moat built by the EU to protect them (good luck getting started making 90% less off your no tracking ads).

Re: People who press on cookie banners anything except “agree” – why do you do that?

#208
post #204

Earlier quoted context omitted.

If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)

No. You only need consent if there is absolutely no reason for you to have that data. Consent is the emergency hatch, only to be used in exceptional circumstances. "But what gives?!", I hear you think. As a law professor said (roughly): it was truly amazing to see how an entire industry colluded so swiftly and completely to undermine legislation.

[deleted]

Re: People who press on cookie banners anything except “agree” – why do you do that?

#209
post #204

Earlier quoted context omitted.

If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)

No. You only need consent if there is absolutely no reason for you to have that data. Consent is the emergency hatch, only to be used in exceptional circumstances. "But what gives?!", I hear you think. As a law professor said (roughly): it was truly amazing to see how an entire industry colluded so swiftly and completely to undermine legislation.

> You only need consent if there is absolutely no reason for you to have that data.

Also no.

There are specific acceptable reasons to have the data. LI is a weak one and does not apply in many situations (there are a lot of balancing factors applied, including a "reasonable person" standard on the data subject). As you say, consent is a very strong one, if received it can virtually always apply. The ones in-between only apply in limited situations genuinely necessary for business (company management of employee data, addresses of customers you need to ship to) or to a small set of companies (hospital management of health data, AML/KYC for banks), and rarely to general web / app analytics.

"I would like that data to serve ads better" (or "to sell to someone who wants to serve ads better") is not "absolutely no reason", but it is also rarely one of the other reasons. And conversely, even if in some case if you have a legitimate business interest i.e. would go bankrupt without it, it is not LI in the sense of GDPR if it cannot meet other factors. The modern adtech ecosystem more or less requires "consent-strength" allowances.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#210
wordy wordy writeup I'm not even sure what you're asking, it's not the same question as your title.

Except for the odd one like some retails sites and maybe just being in a bad mood and I'll click 'decline', I'll click Accept All for most sites just to get it away. The point is to get it off the screen as fast as possible and carry on with whatever content I'm trying to see without distraction.

For the most part tend not to visit that many sites that have tons of ads or large cookie popups so it's not an issue and I'm not a paranoid ad-blocker user.

Post reply on HN