Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

251–260 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#251

Earlier quoted context omitted.

> When you clamp all those things together, this sounds like a great burden. Please tell me, how these poor small businesses comply with, you know, actual laws, rules and regulations that they have to comply with? By breaking them? Most of the time they don't. Ever wonder why food health and safety inspections discover serious issues in basically all restaurants they inspect? It's because people owning and operating…

> Most of the time they don't. Don't comply? Most of the time ? > Ever wonder why food health and safety inspections discover serious issues in basically all restaurants they inspect? As a person whose mother has worked at restaurants for over 40 years, and whose best friends owned a restaurant for close to 20, I can tell you that those "serious issues" and "all restaurants" are FUD. > Most restaurants stay in busine…

> As a person whose mother has worked at restaurants for over 40 years, and whose best friends owned a restaurant for close to 20, I can tell you that those "serious issues" and "all restaurants" are FUD.

"Among restaurant inspections with a total score of >80, at lease one critical violation was cited in 44% of those inspections"

Link: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3323064/

Now imagine which percent of restaurants would fail if we also included failures to comply in other subjects?

> It will be the same: they will get it wrong the first time, get issued a warning, fix it, and carry on.

No, they will most likely never be inspected because there are far too many businesses to control and thus will never implement or fix their practices.

> And yeah, small business (or any business for that matter) really has no business collecting my private data, and selling it to third-parties.

They have just as many rights to do it as large companies

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#252

Earlier quoted context omitted.

> Most of the time they don't. Don't comply? Most of the time ? > Ever wonder why food health and safety inspections discover serious issues in basically all restaurants they inspect? As a person whose mother has worked at restaurants for over 40 years, and whose best friends owned a restaurant for close to 20, I can tell you that those "serious issues" and "all restaurants" are FUD. > Most restaurants stay in busine…

> As a person whose mother has worked at restaurants for over 40 years, and whose best friends owned a restaurant for close to 20, I can tell you that those "serious issues" and "all restaurants" are FUD. "Among restaurant inspections with a total score of >80, at lease one critical violation was cited in 44% of those inspections" Link: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3323064/ Now imagine which percent o…

> Now imagine which percent of restaurants would fail if we also included failures to comply in other subjects?

And your point to all this is?

> No, they will most likely never be inspected because there are far too many businesses to control and thus will never implement or fix their practices.

Funny how it's not far too many for the heath inspectors, and tax agencies, and ...

> They have just as many rights to do it as large companies

Exactly: zero. Edit: that is, zero right to collect any personal data beyond what they need for the service. And definitely no right to siphon and sell it to others with reckless abandon.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#253

Earlier quoted context omitted.

I still don't get the argument. > And the alternative is to have to pay lawyers every time I want to start a business on the web? I thought it was pretty commonplace to hire a lawyer to draft various application, bylaws, policies and stuff like that when founding a company, online or not. > Yes because reading and interpreting an 11 chapter 99 section law is really simple… GDPR really is very simple at the core: you…

> I thought it was pretty commonplace to hire a lawyer to draft various application, bylaws, policies and stuff like that when founding a company, online or not. No it’s not. You can go to nolo.com and pay less than $300 to get incorporated https://www.nolo.com/legal-encyclopedia/forming-corporation Even if you choose to hire a lawyer to do it, it’s a relatively simple process and it would cost a lot more to hire a l…

I would say yes, all businesses looking to make money need to invest money into all sorts of things to do this, including a lawyer. Even the smallest business should consult with counsel during the product design phase to ensure what they are building is legal. This doesn't seem to me to be unreasonable. Every company I have ever worked for, large and small, has had at least one lawyer weigh in on the product. You'd be careless not to.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#254

Earlier quoted context omitted.

> As a person whose mother has worked at restaurants for over 40 years, and whose best friends owned a restaurant for close to 20, I can tell you that those "serious issues" and "all restaurants" are FUD. "Among restaurant inspections with a total score of >80, at lease one critical violation was cited in 44% of those inspections" Link: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3323064/ Now imagine which percent o…

> Now imagine which percent of restaurants would fail if we also included failures to comply in other subjects? And your point to all this is? > No, they will most likely never be inspected because there are far too many businesses to control and thus will never implement or fix their practices. Funny how it's not far too many for the heath inspectors, and tax agencies, and ... > They have just as many rights to do i…

> And your point to all this is?

Small businesses are already not able to comply to core business regulations so obviously they won't have the time and resources to comply with the GDPR compared to large companies that have specialised in-house talent and financial means to do so.

> Funny how it's not far too many for the heath inspectors, and tax agencies, and ...

It absolutely is. Taxes are basically based on people voluntarily complying because there are absolutely not enough inspectors to detect most frauds.

> Exactly: zero. Edit: that is, zero right to collect any personal data beyond what they need for the service. And definitely no right to siphon and sell it to others with reckless abandon.

That is your opinion and it doesn't match what the law allows for.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#255

Earlier quoted context omitted.

> I thought it was pretty commonplace to hire a lawyer to draft various application, bylaws, policies and stuff like that when founding a company, online or not. No it’s not. You can go to nolo.com and pay less than $300 to get incorporated https://www.nolo.com/legal-encyclopedia/forming-corporation Even if you choose to hire a lawyer to do it, it’s a relatively simple process and it would cost a lot more to hire a l…

I would say yes, all businesses looking to make money need to invest money into all sorts of things to do this, including a lawyer. Even the smallest business should consult with counsel during the product design phase to ensure what they are building is legal. This doesn't seem to me to be unreasonable. Every company I have ever worked for, large and small, has had at least one lawyer weigh in on the product. You'd…

No all businesses that want to make money do not hire a lawyer to vet their businesses and especially not their website design. Neither do they need to.

And you really don’t see why all of the ridiculous regulation in the EU might be part of the reason that no meaningful tech company comes out of the EU.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#256

Earlier quoted context omitted.

> has one of these annoying pop-ups You mean a footer. With a 'Only essential cookies' option. A bit annoying, yes, and other commenters have mentioned the reason for it. So nothing in your face like "We care about (selling) your privacy"

It is still in your face. It takes a large part of a mobile screen. If they care enough about privacy they would only use “essential cookies” and get rid of the others.

Yes that's the joke. The law was meant to discourage the use of "non essential" cookies on the assumption that people would rather stop using them than put up annoying banners, but even the EU org itself thinks that YouTube embeds are essential.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#258
> A 1st party cookie for tracking a session that stays on the site doesn't need consent/popups. All cookie laws, including GDPR and CCPA, allow essential first-party cookies to be exempt from collecting user consent before performing their actions

I'd love to hear some legal or DPA opinion on this. From what I know, per the ePrivacy Directive in the version from 2009, any access or storage to information on the end user's device needs consent unless that access/storage is strictly necessary for a service explicitly requested by the user. This is known as the “cookie law”, but is not technology-specific and will also apply to equivalent client-side approaches such as LocalStorage, tracking IDs in URLs, or fingerprinting. The consent requirement is also independent of the question of whether the stored information qualifies as personal data.

The GDPR didn't change anything with these rules. It only changed the definition of consent, invalidating “implied consent” approaches like “by continuing to use this site, you consent to …”. Consent means opt-in. Consent must be easy to decline and withdraw, and users must understand what precisely they are consenting to. This has led to a decrease in the percentage of people who consent to the storage of analytics IDs.

So the question is whether we can be considered as a strictly necessary for a service

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#259

Earlier quoted context omitted.

Are mastadon posts really called toots or is this a joke?

They are. It's not a joke.

They were and it was a joke.

Now it sticks, and'll probably be used forever. But mastodon, the project, has long stopped calling it a toot, removed it from all UI and docs and explained why it changed.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#260

No one likes these consent modals, not the EU, not the companies, not the end users. But they're good. They're making the negative externality visible. We had developed an ecosystem where as soon as you clicked on a webpage it would spaff your personal data to third party brokers and infest you with tracking across the entire internet. All driven by marketing and sales departments. All driven by a capitalist free mar…

No, they are not good in any way. Imagine you have to press buttons whenever you start your car and have to give promises you are not going to go above the speed limit... It's just plain NONSENSE. This consent madness should be implemented in the browser. You set it once, and then you just forget about it. Poof, problem gone. If

It was in the browser (still is?) called DNT, and it didn't work because the industry ignored, circumvented and even actively opposed it. Your idea has been tried and was found to not work.
Post reply on HN