Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

71–80 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#72
post #21

Part of what it means to be "good at regulation" is to anticipate the likely consequences of regulations. So a regulation that says that "businesses must now give away their products for free, unless they honk each customer's nose" will result in a lot of sore noses. Which is basically the case here. Almost all websites make money through ads, or at least keep logs of user activity to help them optimize their website…

> Almost all websites make money through ads,

Doesn't require tracking of individuals.

> or at least keep logs of user activity to help them optimize their website

Doesn't require tracking of individuals.

Re: Dear Paul Graham, there is no cookie banner law

#73

Yes there is. More specifically, it’s the Privacy and Electronic Communications Directive 2002/58/EC, which each member state adjusts their own laws to follow. It’s published here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... The relevant part: > Article 5 > Confidentiality of the communications > 3. Member States shall ensure that the storing of information, or the gaining of access to information…

But this is exactly what the article is saying.

Re: Dear Paul Graham, there is no cookie banner law

#75
post #11

The funny thing about legislation is that you're responsible for the unintended consequences of your laws too.

In this case, it is just showing that most companies are collecting more data than they need. You don’t need a banner for the data that is necessary for the service to work at minimum level. There is no role for the consent since the site won’t work otherwise.

This is something a lot of people seem to misunderstand about GDPR. At its core it says you should only process people’s personal data within a lawful basis. There are 6, and consent is only one.

(a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.

(b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.

(c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations).

(d) Vital interests: the processing is necessary to protect someone’s life.

(e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.

(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

Re: Dear Paul Graham, there is no cookie banner law

#77

I wonder - why didn't the the EU put the burden on user agents a.k.a. web browsers to handle the cookie notices? When I visit a site, before saving any cookies, have my user agent ask me if I want to allow cookies for that site. Could have a default "no cookies" option with a whitelist, or default "yes" with a blacklist. It would have been so much easier, with a far more consistent UX, wouldn't it have? Now we have t…

Because it's not about cookies. It's a much broader statement than that about how the company is allowed to handle your data.

Re: Dear Paul Graham, there is no cookie banner law

#78
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

Using your analogy, I think what ends up happening is that even companies that don't collect hidden fees will put up a banner just in case.

Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.

Re: Dear Paul Graham, there is no cookie banner law

#79

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

This is 100% what PG means IMO and the most sane take on this. Either write the law correctly so it's not easily bypassed or just don't touch anything because you will only make it worse.
Post reply on HN