Live data from Hacker News

Spain begins disciplinary proceedings against site for violating Cookie Law

translate.google.com

21–30 of 81 posts

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#21
I am surprised - isn't this what we want? Instead of secrecy, governments warn everyone they are being tracked online. And we moan about it. It wrecks the UI, it is annoying. Folks - this is the Snowden debate, but without the security services.

Yes they should have got into the RFC / IEEE debates (which are fast becoming laws of their own), yes they should be doing it better. Yes they should stop monitoring everyone.

But they are at least starting the debate. And not on an obscure tech forum, or in dusty volumes of proceedings, but right there, in everyone's face.

And until we find a way to make privacy and surveillance and technology triggers in every politician's Skinner box, then its probably the best start we can get.

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#23
Mentioned in the article: Spanish business using Facebook pages could be non compliant to this law. Same with others using wordpress, blogger, tumblr and so on since tracking cookies are been installed without a previous user acceptance. Also note that the business is liable for this, not the hosting service provider.

I wonder how far hosting provider definition goes. If twitter is used in a company marketing strats, is it liable for the cookies installed by twitter? I don't see it different from the facebook pages cited example.

The only practical option given this is to stop using those providers.

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#24

Yikes. I'm generally in favor of web privacy, but with unemployment numbers like theirs, that seems like the last thing Spain needs right now.

I'm from Spain and I've been running a webdev shop for 6 years now. Things are getting worse here and the government if anything is actually just making things more difficult for everyone. I agree with those trying to protect their privacy but for the sake of practicality they should look for a pragmatic approach. BTW, making individuals and companies responsible for tracking cookies installed by third party platform…

can you please explain a little bit more about this cookie law? the only one I heard about was the UK cookie law and it was abandoned months ago.

which websites does it apply to? websites hosted in Spain? websites of commercial businesses operating in Spain? any website with an address in Spain?

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#25
post #2

Sorry for submitting a Google Translate link. It's not doing a perfect job on a legal text but I didn't find any source in English. This is a blogpost of the lawyer taking this case, and the client name is unknown yet. Here's my summary of some facts (IANAL!): - The cookies being investigated are from Google Analytics, Google Maps, YouTube, Adsense and WordPress. - The website was setting the cookies in the browser a…

Please also note that according to the post if the sites are hosted in third party platforms like Facebook, Tumblr, that install tracking cookies the owner of the site can still be sued, even if it's without his control.

In practical terms this means that any individual or business hosting having a Facebook profile page or blog on Tumblr could be sued.

This is just Spanish law at it's best (I'm Spanish, too)

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#26

I am surprised - isn't this what we want? Instead of secrecy, governments warn everyone they are being tracked online. And we moan about it. It wrecks the UI, it is annoying. Folks - this is the Snowden debate, but without the security services. Yes they should have got into the RFC / IEEE debates (which are fast becoming laws of their own), yes they should be doing it better. Yes they should stop monitoring everyone…

I agree that the one good thing this law has done is start a debate.

On the downside it is negatively affecting how you interact with websites. Often before I can even determine if I am on the right website I get a pop up message before I can continue.

Recently I was on a shopping site and I clicked no to the cookies thinking it would only stop tracking cookies. Was surprised when my cart wouldn't save. It is silly that this breaks the site's basic functionality.

If anything browser vendors should be doing more. I do not think this can be done via legislation though. I also think prosecuting websites is silly. If these cookies are so toxic the companies running the services should be showing messages.

For example. Analytics. Why is it that I need to "opt in" to this on every site with a pop up? Why can't I just click YES and be done with it when it comes to this service?

You could then have non-tracking cookies essential to the running of the service exempt from this law.

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#27
post #13

Actually, most warning implementations punish those users that disable cookies in their browsers by forcing them to see the obnoxious warning every time they visit the site. This is arguably worse than the previous situation.

... This isn't some "punishment" this is how the internet works. If you opt out of being tracked and cookies... how would that be remembered? That is really a sign it's working. This is part of why this is such an amazingly defective law

Some pages (eg. all that use the consent.truste.com script) use localStorage to store the decision. That way the decision remains client-side and can still be persistent by hiding the question via javascript.

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#28

I am surprised - isn't this what we want? Instead of secrecy, governments warn everyone they are being tracked online. And we moan about it. It wrecks the UI, it is annoying. Folks - this is the Snowden debate, but without the security services. Yes they should have got into the RFC / IEEE debates (which are fast becoming laws of their own), yes they should be doing it better. Yes they should stop monitoring everyone…

It's not the Snowden debate, not by a long distance. Some cookies (like ad trackers) can be annoying/slightly disturbing, but even before the cookie law they were pretty obviously there and in most cases pretty easily opted out of already if you knew what you were doing.

I don't remember seeing the "opt out of NSA surveillance" option anywhere in my browser or email client.

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#29
post #24

Earlier quoted context omitted.

I'm from Spain and I've been running a webdev shop for 6 years now. Things are getting worse here and the government if anything is actually just making things more difficult for everyone. I agree with those trying to protect their privacy but for the sake of practicality they should look for a pragmatic approach. BTW, making individuals and companies responsible for tracking cookies installed by third party platform…

can you please explain a little bit more about this cookie law? the only one I heard about was the UK cookie law and it was abandoned months ago. which websites does it apply to? websites hosted in Spain? websites of commercial businesses operating in Spain? any website with an address in Spain?

I'm not him, but I can try to answer you.

It applies to any businesses, professionals with a web page, and anyone who offers a service as long as they a) are located in Spain, b) target their services to the Spanish market or c) if they have a (permanent or regular) workplace or facilities in Spain.

(It's a translation from Spanish legalese, so probably the language is muddled, sorry.)

Re: Spain begins disciplinary proceedings against site for violating Cookie Law

#30

I am surprised - isn't this what we want? Instead of secrecy, governments warn everyone they are being tracked online. And we moan about it. It wrecks the UI, it is annoying. Folks - this is the Snowden debate, but without the security services. Yes they should have got into the RFC / IEEE debates (which are fast becoming laws of their own), yes they should be doing it better. Yes they should stop monitoring everyone…

The problem is that there is no debate about how to deal this in pragmatic terms. Instead, they are just issuing fines on businesses that are probably already having a hard time keeping themselves alive.

The whole situation would be completely different it this would have been discussed in practical terms. They could have matured possible technical solutions for this and also made sure that big third party providers (Facebook, Tumblr, etc.) that host websites for EU businesses comply with this regulation, rather than making the business owner responsible.

If you get a fine of €30K I bet you wouldn't call that a debate, correct?

Post reply on HN