"Companies could easily avoid any cookie banner. Just don’t track." It seems like a point dear to the author's heart, given the way he highlights this and puts it in bold at the top of the article. But while it sounds good on the surface, it doesn't take much digging to show it's silly. If you store any kind of data about a visitor to make their life more convenient, is that tracking? Shopping carts? Notification pre…
Shopping carts and notification preferences don't require a consent banner.
Dear Paul Graham, there is no cookie banner law
341–350 of 662 posts
Re: Dear Paul Graham, there is no cookie banner law
#342Earlier quoted context omitted.
Doesn't that argument work both ways? If you interpret the EU's regulation with the "lens of game theory", it is an unintended consequence of aggressive corporate data collection. Not sure why it makes sense to complain about the EU and not the companies.
No, it does not work both ways. The roles of governments and corporations are not symmetric. Good regulation is regulation that has good outcomes. If a law has bad outcomes it is a bad law. You can separately complain about what companies are doing but that doesn't change the fact that it's a bad law. It is of course debatable whether GDPR as a whole has bad outcomes, but if we're talking about cookie banners in isol…
Re: Dear Paul Graham, there is no cookie banner law
#343Earlier quoted context omitted.
I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…
We already have granular permissions for other things (like location queries) and it works out just fine. You allow things when they make sense and refuse when they don't. It could be resolved in a way that preserves usability, but still achieves a goal not tracking non-users via ads. I doubt that it would make PG particularly happy though.
Re: Dear Paul Graham, there is no cookie banner law
#344Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…
This kind of behavior reminds me of the book: "Language vs. Reality: Why Language Is Good for Lawyers and Bad for Scientists" - Nick Enfield, Linguistic Anthropologist [1]
[1] https://mitpress.mit.edu/9780262548465/language-vs-reality/
Re: Dear Paul Graham, there is no cookie banner law
#345Earlier quoted context omitted.
Doesn't that argument work both ways? If you interpret the EU's regulation with the "lens of game theory", it is an unintended consequence of aggressive corporate data collection. Not sure why it makes sense to complain about the EU and not the companies.
No, it does not work both ways. The roles of governments and corporations are not symmetric. Good regulation is regulation that has good outcomes. If a law has bad outcomes it is a bad law. You can separately complain about what companies are doing but that doesn't change the fact that it's a bad law. It is of course debatable whether GDPR as a whole has bad outcomes, but if we're talking about cookie banners in isol…
You don't seem to explain what the role of corporations is or what a good corporation looks like. If these things are not symmetric, you need to finish your explanation of why or how they aren't.
Corporations and the whole of property rights only exist because of government protection, so it would be pretty audacious--in my opinion--to assert that corporations have no duty to behave to the benefit of society. I'm not saying that's your claim, but I'm curious as to how close you're willing to get to that claim...
Re: Dear Paul Graham, there is no cookie banner law
#346Earlier quoted context omitted.
The problems with the current law are: - no fines for non-compliance (or malicious compliance) - no legal liability for data leaks of PPI When businesses believe (correctly or incorrectly) that the benefit of tracking outweighs the cost (annoying users, regulatory noncompliance) they will do it. The fix is to make tracking too costly for businesses.
> - no fines for non-compliance (or malicious compliance) "The Biggest GDPR Fines of 2023" 1. Meta – €1.2 billion (Ireland) 2. Meta – €390 million (Ireland) 3. TikTok – €345 million (Ireland) 4. Criteo – €40 million (France) 5. TikTok – €14.5 million (UK) 6. Axpo Italia Spa – €10 million (Italy) 7. Tim S.p.A. – €7.6 million (Italy) 8. WhatsApp – €5.5 million (Ireland) 9. EOS Matrix – €5.5 million (Croatia) 10. Clearv…
You just copy-pasted a list of GDPR fines.
Re: Dear Paul Graham, there is no cookie banner law
#347Earlier quoted context omitted.
Fun fact, they are illegal if they require more clicks to reject than accept; so this is not a consequence of the law anyway.
I wouldn't call it fun that so many big providers just ignore the law and are apparently getting through without consequences.
Re: Dear Paul Graham, there is no cookie banner law
#348Earlier quoted context omitted.
> The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". The only alternative to that binary logic is cookie banners. So to be clear, you are advocating for cookie banners. The reality is that the overwhelming majority of people do legitimately want option 1, which makes cookie banners redundant. The only reason that cookie banners exis…
The point is that you'd still get cookie banners even with option 1, because a site can always ask you if you're willing to override your default preference.
Re: Dear Paul Graham, there is no cookie banner law
#349Earlier quoted context omitted.
Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.
If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…
Re: Dear Paul Graham, there is no cookie banner law
#350Earlier quoted context omitted.
Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.
It's so depressing. Many of the people who are pointing the finger at the regulators for the annoying cookie banners don't actually see the web site/app *as* a bad actor. The fact that they had been tracking tons of extra data via cookies without their consent or knowledge was totally fine to them as long as it wasn't inconveniencing them in any way. The cookie banner is an inconvenience to their mindless consumption…
It’s an inconvenience to people who care about privacy and use browser configurations that don’t store state between visits.
So now in an attempt to protect regular users, the law ended up hurting users that already cared.
Additionally, the shadiest and incompetent sites still just track people with no cookie banner. So the law doesn’t really provide protection against uncooperative parties, whereas privacy technology does.