Live data from Hacker News

GDPR – No reject option – what to do?

twitter.com

31–40 of 74 posts

Re: GDPR – No reject option – what to do?

#31

The best reject option is to disable cookies completely for casual browsing.

Or destroy the whole virtual machine used for casual browsing. Except tracking includes browser fingerprint, which will not be reset even in this way.

Unless we all share the same VM image...

Re: GDPR – No reject option – what to do?

#32
post #15
post #2

If I ignore privacy banners (or click the 'x') do the websites I visit go about their business as if I had clicked accept?

Some do some don't. The GDPR strictly requires an explicit opt-in. So it's reasonable to assume that clicking on 'X' is a rejection. But some website do not accept that as a rejection.

This particular web site states openly that they do take clicking on the "X" as acceptance of tracking.

Re: GDPR – No reject option – what to do?

#34

It's not illegal to just cookie-wall your whole site without options, or is it? This site here e.g. does it: https://www.spiegel.de/ imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.

It is illegal, they cannot offer free but tracked vs paid and untracked service. I guess GDPR enforcement didn't reach them yet.

Yes you can, you can provide an add supported service with tracking and a paid one without.

Both via legitimate interest and consent.

Re: GDPR – No reject option – what to do?

#35
post #24

It's not illegal to just cookie-wall your whole site without options, or is it? This site here e.g. does it: https://www.spiegel.de/ imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.

The DPA (Lower Saxony) says it's not. German link: https://lfd.niedersachsen.de/startseite/themen/internet/date... They call it Nudging. I might translate this to a proper blog post in English.

I noticed that too. A lot of German media started doing this ("pur" subscription vs "full" subscription which also gives access to additional paywalled articles). I would be surprised if these huge publishers didn't do their legal legwork - or they are doing it just waiting for a test lawsuit to clarify the reading of the law.

Re: GDPR – No reject option – what to do?

#36
post #29

It's not illegal to just cookie-wall your whole site without options, or is it? This site here e.g. does it: https://www.spiegel.de/ imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.

A big part of GDPR is that you can't just say "by using our site you agree to forgo your GDPR rights" or "click here to agree not to invoke your GDPR rights" or anything like that.

[dead]

Re: GDPR – No reject option – what to do?

#38

Earlier quoted context omitted.

Or destroy the whole virtual machine used for casual browsing. Except tracking includes browser fingerprint, which will not be reset even in this way.

Unless we all share the same VM image...

I assume it would be a performance disaster, but transparently running the browsing process in identical VM's would probably make fingerprinting much harder. I like the idea!

Re: GDPR – No reject option – what to do?

#39
post #25
post #17

Earlier quoted context omitted.

I filled 2 years ago a few complaints. It took over 1 year for an answer. Basically nothing happened. The Data Protection Authority are underfunded and understaffed. They try the best with their resources.

Can't we fund these authorities with the fines they generate? Not the best way, I know, but better than nothing.

That would create a perverse incentive inevitably leading to corruption.

Re: GDPR – No reject option – what to do?

#40
Either a site has the opt out choice clear, marked by default (the bigger/more visible button), or it should be reported.

Obviously authorities can’t follow up on every small player here, so the key is to make an example by imposing some extremely large fines on some large companies.

Anyone who sees it should think “whatever we risk losing by losing 99% ad revenue is better than THAT”. Preferably sanctions should include personal sanctions on decisionmakers but I’m not sure if that’s possible as the regulation works now.

It needs to be made a proper criminal offense so that investigators have the tools they need. An efficient way to go about this could be to find one of the companies that supplies these dark pattern services (sells cookie gateway services), demand lists of their customers and verify that they indeed used that product - and fine all off them off the face of the internet.

Post reply on HN