Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

31–40 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#31
post #19

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

The plug-in is called Consent-o-Matic and was built by students at Aarhus University, Denmark.

You can read more about it and how to set it up here: https://consentomatic.au.dk/

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#32
post #19

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

Can it auto-reject them?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#33
If the GDPR is simplified, the fines should be drastically raised. (At least for companies) E.g. to minimum 20% of the global last years revenue, for bigger companies (FAANG-Scale) to minimum 70% of the revenue. The GDPR must make companies afraid of breaking the law.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#34
post #18

Cookie consent banners might be one of the most frustrating aspects of modern web browsing. A better solution could have been a thoughtful extension or fork of HTTP, specifically for EU implementations, something that handles consent through HTTP headers instead. That would allow users to easily opt in or out, either globally or per tab, without the clutter. Ideally, technical regulations like these should be designe…

It would have been easy to write in generic wording that the "do not track" header must be respected by websites. I'be been wondering for ages why this wasn't implemented.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#35

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#36
post #26

Earlier quoted context omitted.

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

No. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?

How do you interpret this about strictly necessary cookies, from gdpr.eu?

> While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.

To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#37
post #32
post #19

Earlier quoted context omitted.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

Can it auto-reject them?

> Consent-O-Matic is a browser extension that recognizes CMP (Consent Management Provider) pop-ups that have become ubiquitous on the web and automatically fills them out based on your preferences – even if you meet a dark pattern design. Sometimes a website might not use standard categories, and in that case, Consent-O-Matic will always try to submit the most privacy preserving settings.

https://consentomatic.au.dk/

So sounds like that should be somewhat supported.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#38
post #32
post #19

Earlier quoted context omitted.

> a) do away with the worthless cookie banners requirement i recommend everyone gets the chrome plugin that auto accepts these banners so you never have to see them again

Can it auto-reject them?

It can.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#39
post #27

Earlier quoted context omitted.

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

> You are required to have a cookie banner if you use cookies Feel free to (re)read the regulation, there is no such requirement at all. > you must serve a cookie banner even if you are only using functional cookies Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.

I spent months implementing GDPR compliance with a set of EU-based lawyers.

Most businesses are not actually GDPR compliant, even to this day. I assume this is a big reason the EU is willing to take another look at what is required for compliance.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#40
post #16

Earlier quoted context omitted.

> do away with the worthless cookie banners requirement There is no such requirement. You're free to make a website that doesn't require cookies. This very website on which we're discussing doesn't have a cookie banner, and isn't required to have one. (I'm not saying HN is GDPR compliant though, it's missing a DPO mail address to allow edit/deletion of older PII messages and a privacy policy even though said policy w…

You are required to have a cookie banner if you use cookies, and you have to use cookies or an equivalent technology to persist state in a logged-in website (like HN). To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.

This is simply not correct. You absolutely DO NOT need to obtain consent for strictly necessary first-party session cookies (such as would be used by an online shopping cart, for example, or to maintain a persistent login) [1].

[1] https://gdpr.eu/cookies/

Post reply on HN