Live data from Hacker News

Where did all the “reject” buttons come from?

noyb.eu

101–110 of 127 posts

Re: Where did all the “reject” buttons come from?

#101
post #84
post #72

Earlier quoted context omitted.

No, it is just client storage. The law is explicitly only about client storage: >Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 9…

It is GDPR and not PECR that sites responded to with the cookie banners that we deal with today, and GDPR covers a much broader surface area ("processing of personal data")

Sort of, but it's still the ePD, really. The ePD was always there, but largely ignored by both companies and regulators.

What happened when the GDPR came in was twofold:

1. Everyone became acutely aware of data protection legislation, because the GDPR actually had teeth when it came to enforcement.

2. The ePD referenced the Data Protection Directive, and when the GDPR came in to force all references to the DPD became references to the GDPR.

The consequence of #2 is that the hand-wavy "implicit consent" that sites relied on to avoid cookie banners (why show a banner asking for consent if you can just assert you do have consent?) went away - the GDPR made it clear that consent must be explicit.

Re: Where did all the “reject” buttons come from?

#102
post #63

Earlier quoted context omitted.

Is it possible to 'object' to these legitimate interest? Is it possible for a website to say, if you object to these, just don't use our website/service?

Some sites certainly do present the only options "accept or go away", it slightly more subtle "by continuing..."¹. IIRC this is against both the meaning and the letter of the law, but that is not practical to properly enforce so they get away with it.

the worst are accept or pay. i found it especially annoying to see that on a site like heise.de who should really know better.

Re: Where did all the “reject” buttons come from?

#103
post #54

Earlier quoted context omitted.

My layman's understanding of the GDPR was that it was the primary website (i.e. the website you are actually and intentionally visiting) that could store your data on the basis of a legitimate business interest -- for example because they need that information to deliver some stuff you ordered from them. However someone seems to have found a legal loophole whereby third parties ostensibly are able to track you on the…

> Tracking is not, and will never be, a legitimate business. The problem is, the way the Internet and its services are financed, it is pretty much a requirement. A lot of services absolutely depend on advertising revenue because affordable micro-transactions still are not a thing, not to mention 20 years of cultural ingrainment that services on the Internet have to be free when they are aimed at the general public. T…

Personalized tracking is not a requirement for ads.

Ad agencies were making plenty of money for many years before the internet made this kind of tracking possible.

There's very little evidence that personalized tracking actually makes advertising more effective in terms of ROI.

Let ad companies sell ads, and websites sell their ad space, based on the content of what's posted there. The same way ads were sold in newspapers and magazines for decades.

And ad fraud on the part of any of the business parties involved in the ad transactions are not sufficient justification for tracking every person's entire life online. Let them deal with the fraudsters directly, in ways that don't involve incredibly invasive and privacy-eroding surveillance on a massive scale.

If they can't figure out how to do that, that's not my problem. It's their business model, not mine.

Re: Where did all the “reject” buttons come from?

#104
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

> It's something that could've been built in to the browser. It was; nobody cared (due to lack of any legislation/enforcement); it died. https://en.wikipedia.org/wiki/P3P

My favourite part of P3P was when Google started returning a P3P header that just had the string "This is not a P3P policy", intentionally letting browsers consider its presence a declaration of P3P compliance while declaring non-compliance in English. Real, refined, stylish evil. I couldn't help but be impressed.

Re: Where did all the “reject” buttons come from?

#105

Earlier quoted context omitted.

> Either GDPR should be updated to ban consent pop-ups and simply make “REJECT” the default everywhere That is literally in the law. Article 7.3 https://gdpr.eu/article-7-how-to-get-consent-to-collect-pers... --- start quote, emphasis mine --- The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent befor…

> "That is literally in the law." No, the law does the opposite. It effectively requires the use of pop-ups to "gain consent", it doesn't ban them. At least, that's how it's been interpreted in practice. > "And also. GDPR isn't just about browsers or cookies. It's about data in general. Which includes all other situations, including offline interactions, gaming, and communication with governments." Absolutely. In gen…

> It effectively requires the use of pop-ups to "gain consent", it doesn't ban them.

Once again: the law isn't about cookie banners. The law is about user data.

That is: if you want to collect more data that is strictly required for the functioning of your business, then you must ask user for consent. Note: the law doesn't care if your business is online, or offline, or a combination thereof. If you set up a corner shop selling bread, and start asking customers for their name and address, you will be subject to the same GDPR provisions as a website.

How difficult is that?

Literally nothing in the law requires cookie banners. The only reason these obnoxious cookie banners exist is because the greedy leeches in our industry cannot live without siphoning your data en masse and selling it to the highest bidder, consequences be damned.

Now. Here's what you said: "Either GDPR should be updated to ban consent pop-ups and simply make “REJECT” the default everywhere"

The law already clearly states: REJECT has to be as simple as giving consent. And the entire industry said: yes, of course, here's a default "accept" with hundreds of pre-checked boxes, and you have to go through every single one of them one by one to reject.

How is that the law's fault?

They cannot ban people from asking users for consent to collect data. However, the law is rather explicit: any person has the right to reject this, the rejecton has to be as easy and clear as accepting, and people cannot be denied service just because they rejected collection of non-necessary data.

As the article above states: once the law started to be enforced, sites started obeying the law, and not flaunting it. Well, they still flaunt it with their "legitimate uses" bullshit, but the tide is ever so slowly turning.

Too bad, even developers are so gullible as to have been tricked into parroting the "law is bad" and "law requires obnoxious cookie banners" nonsense. No, it isn't. No, it doesn't.

Re: Where did all the “reject” buttons come from?

#106
post #54

Earlier quoted context omitted.

My layman's understanding of the GDPR was that it was the primary website (i.e. the website you are actually and intentionally visiting) that could store your data on the basis of a legitimate business interest -- for example because they need that information to deliver some stuff you ordered from them. However someone seems to have found a legal loophole whereby third parties ostensibly are able to track you on the…

> Tracking is not, and will never be, a legitimate business. The problem is, the way the Internet and its services are financed, it is pretty much a requirement. A lot of services absolutely depend on advertising revenue because affordable micro-transactions still are not a thing, not to mention 20 years of cultural ingrainment that services on the Internet have to be free when they are aimed at the general public. T…

> The problem is, the way the Internet and its services are financed, it is pretty much a requirement.

It's not. Advertisement can and has worked very well without wholesale collection and trading of private user information.

The next time you feel like presenting the "we require tracking for financing services" bullshit as fact, please provide proof.

Re: Where did all the “reject” buttons come from?

#107

Earlier quoted context omitted.

> "That is literally in the law." No, the law does the opposite. It effectively requires the use of pop-ups to "gain consent", it doesn't ban them. At least, that's how it's been interpreted in practice. > "And also. GDPR isn't just about browsers or cookies. It's about data in general. Which includes all other situations, including offline interactions, gaming, and communication with governments." Absolutely. In gen…

> It effectively requires the use of pop-ups to "gain consent", it doesn't ban them. Once again: the law isn't about cookie banners . The law is about user data . That is: if you want to collect more data that is strictly required for the functioning of your business, then you must ask user for consent . Note: the law doesn't care if your business is online, or offline, or a combination thereof. If you set up a corne…

> ”They cannot ban people from asking users for consent to collect data.”

Why not? This is exactly what needs to happen. Either that, or allow cookie consent to be granted/declined globally in the browser settings, not with a bespoke, intrusive UI on every. single. damn. website.

Let’s ban cookie pop ups!

Re: Where did all the “reject” buttons come from?

#108

Earlier quoted context omitted.

> It effectively requires the use of pop-ups to "gain consent", it doesn't ban them. Once again: the law isn't about cookie banners . The law is about user data . That is: if you want to collect more data that is strictly required for the functioning of your business, then you must ask user for consent . Note: the law doesn't care if your business is online, or offline, or a combination thereof. If you set up a corne…

> ”They cannot ban people from asking users for consent to collect data.” Why not? This is exactly what needs to happen. Either that, or allow cookie consent to be granted/declined globally in the browser settings, not with a bespoke, intrusive UI on every. single. damn. website. Let’s ban cookie pop ups!

> Why not? This is exactly what needs to happen.

No, it's not. Because there are actual legitimate reasons for organisations and businesses to ask for user's consent.

> Either that, or allow cookie consent

You keep missing the simple fact that GDPR is not about cookie consents. How many times do I have to repeat this?

> not with a bespoke, intrusive UI on every. single. damn. website.

Again. In as simple terms as I possibly can:

- GDPR is about user data everywhere, not just in the browsers

- GDPR does not mandate cookie pop ups. This is entirely the work of a greedy industry

- GDPR cannot ban asking for user consent. Because that is a) over-reaching, and b) makes legitimate cases for asking for user consent illegal

- And again. GDPR is not about browsers. GDPR is not about websites. GDPR is not about cookies. GDPR is not about cookie popups

Note: if websites actually respected the law and user privacy, you wouldn't even see those popups. But sure. Tell me how it's the law that is responsible for them.

Re: Where did all the “reject” buttons come from?

#109
post #68

Earlier quoted context omitted.

> The problem is, the way the Internet and its services are financed, it is pretty much a requirement. A bad business model doesn't mean you get to ignore the law.

A key part is that, while the GDPR undoubtedly is a good piece of law, it got introduced without a public debate on how the Internet should actually work and be funded. Basically, GDPR kneecapped the entire business model of everyone but Wikipedia, and almost no thought was spared on how to replace that and make the Internet a better place for everyone.

> Basically, GDPR kneecapped the entire business model of everyone but Wikipedia

GDPR did no such thing. There are thousands, if not millions, of businesses operating online that _actually sell goods and services for money_ and GDPR did nothing to stop those.

On top of all that, you can still show ads while being GDPR compliant. Just not slurp-every-piece-of-data type ads.

Re: Where did all the “reject” buttons come from?

#110
post #71

"Reject" being now an options is an improvement of sorts but honestly, the cookie laws in the current form are terrible long-term for privacy. Like recycling plastic, it's a red herring that benefits the big companies, and where everyone else loses. The burden being on the user to manage everything reminds me more of the dysfunctional US healthcare pricing system, where the uninsured have no negotiating power and are…

The issue isn't isn't the law. The issue is every single website tracking you in a privacy invading way. The annoying cookie banners are a side effect of these companies rightfully having to now inform us of when they're invading our privacy.
Post reply on HN