Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

331–340 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#331
post #121

Earlier quoted context omitted.

The law is not bypassed, the annoying banners with no simple option to reject are illegal . The issue is that enforcement is slow, not that the law is badly written. GDPR's Article 7 [0] is very clear: > 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving con…

Yes, that very much is an example of the law being badly written. "Prior to giving consent, the data subject shall be informed thereof." Means there must be some sort of a cookie notification (which could of course take a small space of the screen, but still). The existence of this notification makes it easier to initially give consent. If withdrawing later is to be as easy, the notification must never disappear.

So you want users to be tracked without consent? I don't.

Re: Dear Paul Graham, there is no cookie banner law

#332
post #238
post #50

Earlier quoted context omitted.

Since this is around the 5th time this sentiment has been expressed in this thread, I have to ask... are cookie banners really so frustrating? Oh no, gotta click one, maybe 2, more buttons...

Fun fact, they are illegal if they require more clicks to reject than accept; so this is not a consequence of the law anyway.

I wouldn't call it fun that so many big providers just ignore the law and are apparently getting through without consequences.

Re: Dear Paul Graham, there is no cookie banner law

#334
post #240
post #110

Earlier quoted context omitted.

It would be 100% ok for it to be a browser setting. It isn't though, because that would make too many people opt out. That's what the article is about.

I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…

We already have granular permissions for other things (like location queries) and it works out just fine. You allow things when they make sense and refuse when they don't. It could be resolved in a way that preserves usability, but still achieves a goal not tracking non-users via ads. I doubt that it would make PG particularly happy though.

Re: Dear Paul Graham, there is no cookie banner law

#335
post #120

Earlier quoted context omitted.

This is actually in violation of the rules. Withholding consent is supposed to be as easy as giving consent.

Yes, I know. It’s infuriating but understandable that the regulations aren’t enforced properly.

Why is it understandable that the regulations aren’t enforced properly?

Re: Dear Paul Graham, there is no cookie banner law

#336
post #91

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

The law isn't that bad actually, just that the courts have been very slow. The dark UI patterns are actually illegal and have been judged so in court now. This realization just has to trickle down to the companies writing these cookie banners.

My take is that law tries to dictate UX more than just set groundrules which good laws do. They pre-emptively set the law such that it prevents any use when the focus is on misuse. The law is about 1st party and 3rd party cookies, not just 3rd party.

In an ideal case, if it was just a law, a simpler wording could be "you are allowed to collect anonymized data, but not monetize/share it without permission from users. We may ask you to furnish proof that you havent been doing that at times, failing which you would face massive fines (as %age of revenue whatever)."

Problem is collecting basic anonymized usage data[1] is needed by companies to improve the product, provide a better experience, detect misuse. They bundled those use cases with everything else meaning the law was too broad and we got cookie banners given every site needs basic analytics. On flipside, worst is that most websites use Google Analytics, so they might have had to display the banners anyway.

[1] Moreover, it's vaguely worded so we companies do not know if they have committed a GDPR offence. By general understanding IP addresses are under GDPR. You can get that via request headers. So, to be on the safe side, even anonymized analytics tracking is considered under GDPR

Re: Dear Paul Graham, there is no cookie banner law

#337
I have what I think is a somewhat clear perspective on the issue of tracking cookies, because I have been on both sides of this issue “in the trenches.” My observation has been that companies really cannot choose to not track as a larger entity, because systemically they do not trust their own employees to make good decisions.

What I mean by this is that tracking in web properties is a joint decision (in most tech companies anyway) between Marketing, Legal, and Product as functions and executive leadership overall. This is actually a “big” decision, because it’s a binary decision that guides future trajectory.

Companies can choose to:

A. Make decisions about where to expend resources on ads, product feature development, localization, accessibility, et al on web properties based entirely on the “gut check” of their employees in each function and trust the outcomes.

B. Carefully measure and track everything so that decisions are supported by data and results are tracked, simplifying decision making and reducing the potential bias of employees and eliminating the need to trust employees to make good decisions and being able to validate outcomes.

If your product /is/ a web-app, the impact becomes even more pronounced.

At the end of the day, the only way to get an organization to give up tracking is to directly force the issue in the law or solve the underlying issues that create a trust gap and competency gap within large organizations. I think the latter is likely impossible to solve, so the former is the only option. In line with the banality of evil, companies are not maliciously deciding to track you, if there is any malice here its towards their own employees down the line, who aren’t or can’t be trusted to do their jobs without tracking.

Because Option B is the only likely option here, the net effect of the law as it stands today is to have a cookie banner everywhere. There’s literally a SaaS called Cookie Law that helps companies comply with these rules.

Re: Dear Paul Graham, there is no cookie banner law

#338
post #240

Earlier quoted context omitted.

I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…

> The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". The only alternative to that binary logic is cookie banners. So to be clear, you are advocating for cookie banners. The reality is that the overwhelming majority of people do legitimately want option 1, which makes cookie banners redundant. The only reason that cookie banners exis…

The point is that you'd still get cookie banners even with option 1, because a site can always ask you if you're willing to override your default preference.

Re: Dear Paul Graham, there is no cookie banner law

#339

Earlier quoted context omitted.

Shopping carts and notification preferences don't require a consent banner.

Our lawyers told us otherwise. Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?

Your lawyers are playing it safe. Their job is to make sure your company is not getting into lawsuits, and having a cookie banner that is not needed won't get you into a lawsuit, so that's what they suggest. They don't care about annoying your users.

If you really care about not annoying your users and don't intend to track them more than what's absolutely required for the service to work, then talk with your lawyers more. Of course, it is not free as it requires extra work, and it may carry some risk (which your lawyers should minimize) but it may be worth it, many people press the "back" button as soon as they see a cookie banner and try their luck elsewhere.

Re: Dear Paul Graham, there is no cookie banner law

#340
post #244

Earlier quoted context omitted.

Just been in Europe last week (I live in US): you have no idea what a nightmare internet is in Europe. You are only seeing a side effect here.

It's crazy how censored the internet is too, you need a VPN to access even piracy adjacent sites in Germany. Unheard of that an ISP would block a website in the US without the FBI itself taking it down.

You don't need a VPN, just a different DNS server.
Post reply on HN