Live data from Hacker News

Most websites don't need cookie consent banners

block81.com

31–40 of 103 posts

Re: Most websites don't need cookie consent banners

#31
post #15

"You DON’T need consent for: First-party cookies used just for your own analytics (in most cases)" They claim that, but the page they link to as the source says "You must...Receive users’ consent before you use any cookies except strictly necessary cookies.". So what exactly makes them think that first-party analytics cookies are "strictly necessary"? The Mastodon link in the at the start of page doesn't seem to work…

Exactly. Analytics is one of the types of data for which permission is explicitly required. Session auth cookies are the only ones the EU considers strictly necessary.

> Session auth cookies are the only ones the EU considers strictly necessary.

There are several others which are permissible. The EU has six examples.

https://commission.europa.eu/resources/europa-web-guide/desi...

Re: Most websites don't need cookie consent banners

#32

I consider all those pop-ups to be illegal. The use case in my opinion does not warrant pissing off users by distracting them via such pop-ups. Here I classify slide-ins the same as pop-ups. I don't even read what is written there since I already don't care. I kind of have to use extensions to workaround this spam. The EU bureaucrats are very confused here - they cost a lot of money and don't really improve much at a…

Why would pissing off users be illegal? Websites can do whatever they want, I don't like those popups and just leave the page when they show up.

Re: Most websites don't need cookie consent banners

#33

Earlier quoted context omitted.

Considering that for most banners the "consent" is the easy option I assume a lot. People want to get rid of the banners. However I claim the point of the bad UX is to make users angry and then have them complain about EU etc. "demanding" those. In order to weaken the regulation of tracking. If they are successful (and they are making progress) "no more cookie banners" is a lot better headlines than "more tracking"

Those are technically in violation of the GDPR since the opt out is required to be just as easy as the opt in.

How is ease of opt out versus opt in objectively measured?

Most of the time both options are presented clearly and within a few pixels from each other, but opt-in is usually slightly more eye catching and/or more appealing. But the effort in terms of distance for mouse movement or number of clicks is the same. While that’s a design trick that will improve % of opt-in, how can it be argued that the opt-out was not as “easy”?

Re: Most websites don't need cookie consent banners

#34

Disclaimer: I work on a consent product. If you're in any way something beyond a hobbyist, you should probably get legal advice about whether you need to get affirmative or implicit consent, whether you need to handle universal opt-out signals (in California, Global Privacy Control signals are now legally required to be respected), etc. Simply saying "oh I'm only tracking local cookies" might not even be enough in GD…

> the act of writing any cookie is actually covered under the law (because you're storing something on the user's computer). You're required to disclose that these cookies are in use.

The page describing the law has more examples of cases where you do not need consent than the ones you do.

https://commission.europa.eu/resources/europa-web-guide/desi...

Re: Most websites don't need cookie consent banners

#35
post #15

"You DON’T need consent for: First-party cookies used just for your own analytics (in most cases)" They claim that, but the page they link to as the source says "You must...Receive users’ consent before you use any cookies except strictly necessary cookies.". So what exactly makes them think that first-party analytics cookies are "strictly necessary"? The Mastodon link in the at the start of page doesn't seem to work…

[deleted]

Re: Most websites don't need cookie consent banners

#36
post #33

Earlier quoted context omitted.

Those are technically in violation of the GDPR since the opt out is required to be just as easy as the opt in.

How is ease of opt out versus opt in objectively measured? Most of the time both options are presented clearly and within a few pixels from each other, but opt-in is usually slightly more eye catching and/or more appealing. But the effort in terms of distance for mouse movement or number of clicks is the same. While that’s a design trick that will improve % of opt-in, how can it be argued that the opt-out was not as…

It is very common for there to be "accept all" and "more options" buttons where rejecting all requires multiple clicks via the latter. The sites which havea "Reject all" button right next to the "Accept all" one that's the same size and such aren't flagrantly violating the law.

Re: Most websites don't need cookie consent banners

#38
post #6

"Advertising or behavioral tracking cookies" Any real business needs to do behavioral tracking for campaign conversions, add-to-cart, customer acquisition, funneling, retention, personalization, etc. I love how we all hate cookie banners and say they are unnecessary, but are salaries are all paid by apps that do behavioral tracking. Only hobby blogs can get by without it.

It's a shame this is downvoted. It doesn't make it right, but it is true.

Until the regulation actually gets enforced so that everyone is on a level playing field and does not do such things, you will be at a disadvantage if you're the only one to comply, so the winning strategy is to not comply and engage in such practices just like your competitors do.

Re: Most websites don't need cookie consent banners

#39
post #31

Earlier quoted context omitted.

Exactly. Analytics is one of the types of data for which permission is explicitly required. Session auth cookies are the only ones the EU considers strictly necessary.

> Session auth cookies are the only ones the EU considers strictly necessary. There are several others which are permissible. The EU has six examples. https://commission.europa.eu/resources/europa-web-guide/desi...

This is what European Commission has determined to be acceptable for them. One very important distinction here is, as far as I understand, that EC is not bound by ePrivacy Directive as directives bound member states and require them to include them on their national law.

The text on that website does state that some DPAs have found some first-party analytics acceptable, but that's not something that is confirmed by CJEU. And ePD does not have single-stop shop so you need to follow every DPAs directions if you are offering services to that DPA's country.

Re: Most websites don't need cookie consent banners

#40
post #23
post #10

Earlier quoted context omitted.

can you give examples of serious online businesses that are not doing those things? Here are the industries that I've worked in that all did behavioral tracking for the above applications * gaming * music industry * healthcare * social media * news * internet search * online retail

You don't seem to understand that one can do behavioral tracking without sharing all personal data with Facebook and Google. GDPR is mainly focused on who you share the data with. Performance tracking of core business processess including traffic sources can be done without involvement of Facebook and Google. It's totally legit to spend a career helping the folks at Facebook and Google to soak up more private informa…

No thats not true
Post reply on HN