Live data from Hacker News

Analysis of economic and productivity losses caused by cookie banners in Europe

legiscope.com

111–120 of 395 posts

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#111

People blame the cookie banners themselves or the legislation that "made them necessary" but somehow never seem to blame the web companies for doing the naughty things on their websites that make them subject to the law. The "cookie banner problem" exists because it's primarily end users that are shouldering the burden of them, and not the companies. For the company, it's a one time JIRA ticket for a junior software…

They don't technically even need a banner per se, just respect the user's "do not track" browser setting, or put it in a settings screen, or don't use any 3rd party trackers. But a lot of businesses assume they need to ask permission for placing any cookies, which is simply not correct. Local analytics tracking is fine, it's only when the user can be tracked across multiple separate websites that they need explicit p…

>But a lot of businesses assume they need to ask permission for placing any cookies, which is simply not correct.

Partly because of laziness, partly because of pessimistic legal compliance.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#112
> actively tracking a user beyond their visit to a website is difficult or borderline impossible for website owners, as it would require a court order.

I am skeptical of this claim. Partially due to the existence of trackers, beacons, 3rd party cookies and fingerprinting methods.

> Identifying users typically requires a court order to process IP addresses

And this one as well.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#113
post #59
post #18

Earlier quoted context omitted.

So use Firefox.

tell that to the billion internet users who suffer from cookie banners. I'm talking about the network effect.

I do tell them that. I can't help everyone, but I can help some.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#114
post #5

Correct URL: https://legiscope.com/blog/hidden-productivity-drain-cookie-... > This situation calls for an urgent revision of the ePrivacy Directive Shame companies cannot live without tracking cookies, and shame that the blame somehow end up on the regulation, rather than the companies who are the ones who introduce this cookie banner and "massive productivity loss". You know the best way of not having to put up coo…

> You know the best way of not having to care about GDPR? Don't store PII. I hear this a lot. As an American that hosts casual personal websites, I can't help but worry that I'm in violation of the GDPR. For example, my router logs connections for debugging. And my NGinx server maintains server logs for debugging. These contain IP addresses. I'm pretty sure those are considered PII under GDPR. And there are a lot of…

Actually, all the cases you mentioned does not necessitate any consent from European users as long as you don't send these data to any third party. The only thing is, if you plan to store logs over time, it should be anonymized after 25 months. It's not that bad.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#115
post #60

Earlier quoted context omitted.

> for websites requiring a login They don't need consent for that. > reliant on ads Yes. For me, this has been eye-opening about how many different ad agencies there are snooping on my browsing history. It was bad enough when it was just the (UK) government passing a law to do that, now I've got websites with more "trusted partners" monitoring my every move than my high school had students. > This is a nothing to hid…

Saying you don’t need to worry about GDPR if you don’t keep PII is the “nothing to hide” argument. There is still a cost to demonstrating compliance that goes beyond complying.

Maybe an analogy will make it click: If you have marijuana on you in a country where marijuana is illegal, then finding marijuana on you is illegal. If you don't have marijuana on you, you're not doing anything illegal.

Replace marijuana with "personal data" and imagine it is about websites with visitors within EU. If they're not storing, processing and/or transmitting personal data, there is no compliance requirements (from GDPR at least).

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#116

People blame the cookie banners themselves or the legislation that "made them necessary" but somehow never seem to blame the web companies for doing the naughty things on their websites that make them subject to the law. The "cookie banner problem" exists because it's primarily end users that are shouldering the burden of them, and not the companies. For the company, it's a one time JIRA ticket for a junior software…

They don't technically even need a banner per se, just respect the user's "do not track" browser setting, or put it in a settings screen, or don't use any 3rd party trackers. But a lot of businesses assume they need to ask permission for placing any cookies, which is simply not correct. Local analytics tracking is fine, it's only when the user can be tracked across multiple separate websites that they need explicit p…

This seems like the best way to go. Companies should have to respect "do not track" and browsers should have to enforce it to the extent that it is technically possible. And "do not track" should be per-domain at least.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#117

People blame the cookie banners themselves or the legislation that "made them necessary" but somehow never seem to blame the web companies for doing the naughty things on their websites that make them subject to the law. The "cookie banner problem" exists because it's primarily end users that are shouldering the burden of them, and not the companies. For the company, it's a one time JIRA ticket for a junior software…

Scummy companies won't magically disappear or stop scummy practices. We can and should blame them, but it's pretty much obvious that the legislation (despite good intents!) resulted in a de-facto shitshow that failed to recognize basic social/behavior sciences, technical details, or anything else.

It should've been an user-agent centered feature rather than individual website gimmick - that's the only way it could've possibly worked. After that, companies can try to continue doing whatever shit they want to try, but none of their identifiers would be persisted unless user agent allows it. (This does not account for fingerprinting, but that's a whole other story.)

Instead, legislators made some weird decisions that failed to account for human and corporate nature (greed), and we ended up with more popups and banners than ever.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#118

The whole thing is a colossal waste too, it was a law written by people who don't understand tech for special interest groups who don't want to actually make things better. If you don't want a website doing something on your computer, you start with the browser, not the website.

That's why they created DoNotTrack initially. Then browsers turned that on by default, ad revenue lowered, and sites/adcompanies decided to ignore it because it was turned on by default.

Maybe the legislation simply should have required DoNotTrack to be honored.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#120
post #69

Earlier quoted context omitted.

Link does not support claim "Stupidly high fines happen weekly." I've worked with two firms that have faced GDPR complaints. It's "up to", not "immediately on your first offence".

> I've worked with two firms that have faced GDPR complaints. It's "up to", not "immediately on your first offence". It's not specifically GDPR - it's the degree of overregulation in every sector, for almost every aspect of doing business. I was also speaking facetiously about large companies in particular - for example, just 12 hours ago, Facebook got hit with another $700 million fine. You don't have to be Facebook…

> for example, just 12 hours ago, Facebook got hit with another $700 million fine. You don't have to be Facebook for the chilling effect

This one?

"The EU fined online giant Meta almost 800 million euros on Thursday for breaching antitrust rules by giving users of its Facebook social network automatic access to classified ads service Facebook Marketplace." - https://fortune.com/europe/2024/11/14/eu-fines-meta-840-mill...

Because if so, that's going to have the opposite of a chilling effect, as it is anti-trust.

Likewise, what Apple got with Ireland, while Apple has to pay, it's something Ireland did wrong by illegally giving Apple a tax dodge to encourage it to base itself in Ireland rather than anywhere else in Europe — if that's "chilling": good. We don't want tax-dodgers. If Apple can't be profitable in Europe without dodging taxes, something's gone very badly wrong for them.

Now, I'm not saying the EU doesn't over-regulate, as that kind of claim about any government is like saying that a software project contains zero functions that are never invoked by a user. But I am saying the scope of your rhetoric is not sufficiently supported by the evidence provided.

Post reply on HN