Earlier quoted context omitted.
The law isn't that bad actually, just that the courts have been very slow. The dark UI patterns are actually illegal and have been judged so in court now. This realization just has to trickle down to the companies writing these cookie banners.
My take is that law tries to dictate UX more than just set groundrules which good laws do. They pre-emptively set the law such that it prevents any use when the focus is on misuse. The law is about 1st party and 3rd party cookies, not just 3rd party. In an ideal case, if it was just a law, a simpler wording could be "you are allowed to collect anonymized data, but not monetize/share it without permission from users.…
Dear Paul Graham, there is no cookie banner law
391–400 of 662 posts
Re: Dear Paul Graham, there is no cookie banner law
#392Earlier quoted context omitted.
> - no fines for non-compliance (or malicious compliance) "The Biggest GDPR Fines of 2023" 1. Meta – €1.2 billion (Ireland) 2. Meta – €390 million (Ireland) 3. TikTok – €345 million (Ireland) 4. Criteo – €40 million (France) 5. TikTok – €14.5 million (UK) 6. Axpo Italia Spa – €10 million (Italy) 7. Tim S.p.A. – €7.6 million (Italy) 8. WhatsApp – €5.5 million (Ireland) 9. EOS Matrix – €5.5 million (Croatia) 10. Clearv…
Which ones of those fines were because of inappropriate use of cookie consent popups? You just copy-pasted a list of GDPR fines.
see: "8 companies that faced cookie consent fines"
https://www.cookieyes.com/blog/cookie-consent-fines/
"In January 2023, France’s data protection watchdog, CNIL, fined TikTok €5 million ($5.4 million) for making it difficult to refuse cookies on its website. The CNIL found that TikTok manipulated consent by discouraging users from rejecting cookies. They required multiple clicks to refuse cookies, but only one click to accept them. TikTok resolved the issue by adding a “Refuse all” button to its site."
Re: Dear Paul Graham, there is no cookie banner law
#393Re: Dear Paul Graham, there is no cookie banner law
#394Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…
It has even been implemented in Internet Explorer when it had 90%+ market share.
And then Google intentionally sent malformed P3P header to bypass user preferences in IE.
When Safari added a heuristic rejecting Google's 3rd party cookies, Google has found a technical workaround to bypass it (and has been fined for doing this).
When IE and P3P were totally dead, browsers have tried to give adtech the simplest to implement bare minimum setting - the DNT header. The adtech has completely ignored it.
There are trillion-dollar businesses relying on tracking, and they will do whatever they can to undermine any technology and lobby against any law that would harm their business.
Re: Dear Paul Graham, there is no cookie banner law
#395Earlier quoted context omitted.
If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…
I kinda hate saying this, but Microsoft (or at least github) got it right in a week. Some OSS publishers also got it right, like nexedi, and some i'm sightly upset with (gitlab) but it is true that for the commercial internet it seems to be invasive. I do not use the commercial internet much, and like any person with greasemonkey, i took a rainy afternoon to remove the most annoying banners (i think now i use a plugi…
Re: Dear Paul Graham, there is no cookie banner law
#396Re: Dear Paul Graham, there is no cookie banner law
#397Earlier quoted context omitted.
Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.
If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…
Re: Dear Paul Graham, there is no cookie banner law
#398Earlier quoted context omitted.
In this case, it is just showing that most companies are collecting more data than they need. You don’t need a banner for the data that is necessary for the service to work at minimum level. There is no role for the consent since the site won’t work otherwise.
This is something a lot of people seem to misunderstand about GDPR. At its core it says you should only process people’s personal data within a lawful basis. There are 6, and consent is only one. (a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose. (b) Contract: the processing is necessary for a contract you have with the individual, or because they have a…
The maximum fine is 20 million euros or 4% of revenue, whichever is higher. Sure, it probably won't be imposed on a first time violation, but why take the chance?
Could you imagine any lawyer advising a company against requiring consent, even if they have some cover because of a legal obligation? Isn't it much safer to deny service to those that refuse to consent?
Sure, it'll annoy the customer, but right now the customer is used to minor annoyances.
Re: Dear Paul Graham, there is no cookie banner law
#399Earlier quoted context omitted.
The reality is that most people don't want to be tracked: https://arstechnica.com/tech-policy/2021/07/facebook-adverti...
The problem is that most people don't want to pay for any of the internet services they use either.
Re: Dear Paul Graham, there is no cookie banner law
#400Earlier quoted context omitted.
It would be 100% ok for it to be a browser setting. It isn't though, because that would make too many people opt out. That's what the article is about.
I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…
The adtech will absolutely freak out and destroy any attempt to make such setting as soon as there's a risk of it working.