Live data from Hacker News

GDPR – No reject option – what to do?

twitter.com

11–20 of 74 posts

Re: GDPR – No reject option – what to do?

#11
Most websites, made by low budget webdevs which are thriving thanks to companies asking for low budget websites[1], do not consider - even in the EU - the reject option.

In the large majority of websites, Google Analytics fires even before the cookie banner, and the banner is only used to inform you that by continuing navigation you are accepting to be tracked.

Yes, this is illegal. But not enforceable.

[1]: there are devs selling websites for 500 dollars/euros.

Re: GDPR – No reject option – what to do?

#13
post #4

As a European I encounter a lot dark patterns to circumvent privacy laws. Some just ignore your choice and track you. Some don't give you a reject option. Some make it really really annoying (or slow) to reject. Do you think it's possible to politely ask them on twitter to change? Maybe as a group?

I thought there was an official governmental point of contact that handled such complaints, and had teeth?

Re: GDPR – No reject option – what to do?

#14
post #9
post #5

Earlier quoted context omitted.

Quoting the banner: "You can consent to the use of such technologies by closing this notice"

Well the implication of that sentence is therefore that if you click "Accept" you're simply accepting that you can consent by closing the notice. Therefore clicking the X is consenting, and clicking "Accept" is choosing not to consent.

I really wish the above reasoning could stand up in court!

Re: GDPR – No reject option – what to do?

#15
post #2

If I ignore privacy banners (or click the 'x') do the websites I visit go about their business as if I had clicked accept?

Some do some don't.

The GDPR strictly requires an explicit opt-in. So it's reasonable to assume that clicking on 'X' is a rejection. But some website do not accept that as a rejection.

Re: GDPR – No reject option – what to do?

#16
post #13
post #4

As a European I encounter a lot dark patterns to circumvent privacy laws. Some just ignore your choice and track you. Some don't give you a reject option. Some make it really really annoying (or slow) to reject. Do you think it's possible to politely ask them on twitter to change? Maybe as a group?

I thought there was an official governmental point of contact that handled such complaints, and had teeth?

In France there is CNIL (https://www.cnil.fr/) and they seem to try to follow-up on reports, at least for french located companies/websites I think.

Re: GDPR – No reject option – what to do?

#17
post #13
post #4

As a European I encounter a lot dark patterns to circumvent privacy laws. Some just ignore your choice and track you. Some don't give you a reject option. Some make it really really annoying (or slow) to reject. Do you think it's possible to politely ask them on twitter to change? Maybe as a group?

I thought there was an official governmental point of contact that handled such complaints, and had teeth?

I filled 2 years ago a few complaints. It took over 1 year for an answer. Basically nothing happened.

The Data Protection Authority are underfunded and understaffed. They try the best with their resources.

Re: GDPR – No reject option – what to do?

#18

The reject option would be leaving the banner up wouldn't it? Does that break the law?

In this case the footer banner is not accessible with an open cookie banner. E.g. German law requires the website owner to have a legal link to the website representative.

In this case, only by consenting to the cookies I could have access to those links.

Re: GDPR – No reject option – what to do?

#19
Checking whether cookie banners are compliant should be mostly straightforward for regulatory bodies. In 90% of cases it’s clear if there’s opt in or not.

Why can’t regulatory bodies set up automated flows and tools to handle this at scale? Don’t need to catch every case but they should be able to massively scale the complaints process for this.

Post reply on HN