Live data from Hacker News

GDPR – No reject option – what to do?

twitter.com

41–50 of 74 posts

Re: GDPR – No reject option – what to do?

#41

Earlier quoted context omitted.

My experience is that customers don't even want a reject option, and that pricing is not really part of the question.

pricing correlates to 0.95 with poorly managed cookies in my anecdotal experience. Customers don't even know what all that means, they just want a cheap, functioning website.

Yes, and most consumers outside the tech space just want to access the content. 95% of my friends have no clue what a cookie is - they just press the green button and get on with their shopping. It's not an education issue either - they just don't particularly care.

Re: GDPR – No reject option – what to do?

#42

Earlier quoted context omitted.

Unless we all share the same VM image...

I assume it would be a performance disaster, but transparently running the browsing process in identical VM's would probably make fingerprinting much harder. I like the idea!

Unfortunately this is not so simple. I am using Qubes OS with disposable virtual machines and my fingerprint is always unique. Have a look at the corresponding discussion if you are interested: https://qubes-os.discourse.group/t/is-your-browser-fingerpri....

Re: GDPR – No reject option – what to do?

#43

Earlier quoted context omitted.

It is illegal, they cannot offer free but tracked vs paid and untracked service. I guess GDPR enforcement didn't reach them yet.

Yes you can, you can provide an add supported service with tracking and a paid one without. Both via legitimate interest and consent.

The service cannot be dependent on the acceptance of third party cookies, no. That is, the service provided to those that reject third party cookies cannot be worse (slower or incomplete, for example) compared to the visitors who accept cookies.

So you can supply an ad supported version and a paid version without ads, but you cannot require that those that choose the ad supported version must accept tracking ads.

Re: GDPR – No reject option – what to do?

#44
post #4

As a European I encounter a lot dark patterns to circumvent privacy laws. Some just ignore your choice and track you. Some don't give you a reject option. Some make it really really annoying (or slow) to reject. Do you think it's possible to politely ask them on twitter to change? Maybe as a group?

Maybe don't use services that are abusing you?

There are way too many people that tolerate absolutely pathological software vendors for trivial reasons. Don't be part of the problem.

Re: GDPR – No reject option – what to do?

#45
post #29

It's not illegal to just cookie-wall your whole site without options, or is it? This site here e.g. does it: https://www.spiegel.de/ imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.

A big part of GDPR is that you can't just say "by using our site you agree to forgo your GDPR rights" or "click here to agree not to invoke your GDPR rights" or anything like that.

And you are allowed to give data to any other party if they sign to agree with gdpr and you want their services...

Re: GDPR – No reject option – what to do?

#46
post #41

Earlier quoted context omitted.

pricing correlates to 0.95 with poorly managed cookies in my anecdotal experience. Customers don't even know what all that means, they just want a cheap, functioning website.

Yes, and most consumers outside the tech space just want to access the content. 95% of my friends have no clue what a cookie is - they just press the green button and get on with their shopping. It's not an education issue either - they just don't particularly care.

Exactly - and the regulators thought of this. The obvious/simple/default option MUST be the one that protects the users information the most, or the GDPR is violated.

The law is written understanding that users are lazy/ignorant/non-technical. Anything else would have been useless.

Re: GDPR – No reject option – what to do?

#47
post #39
post #25

Earlier quoted context omitted.

Can't we fund these authorities with the fines they generate? Not the best way, I know, but better than nothing.

That would create a perverse incentive inevitably leading to corruption.

It creates an incentive (to identify entities breaking the law), but I don't see how this is perverse. It's the desired result.

Re: GDPR – No reject option – what to do?

#49
post #2

If I ignore privacy banners (or click the 'x') do the websites I visit go about their business as if I had clicked accept?

I use uBlock Origin to delete the GDPR banner, clicking neither "accept" nor "reject". I just hide it. I have no idea whether this makes any legal difference, and I am sure the assholes responsible don't care either way, but it makes me feel better to circumvent the silliness.

Re: GDPR – No reject option – what to do?

#50

Earlier quoted context omitted.

Yes you can, you can provide an add supported service with tracking and a paid one without. Both via legitimate interest and consent.

The service cannot be dependent on the acceptance of third party cookies, no. That is, the service provided to those that reject third party cookies cannot be worse (slower or incomplete, for example) compared to the visitors who accept cookies. So you can supply an ad supported version and a paid version without ads, but you cannot require that those that choose the ad supported version must accept tracking ads.

I have gotten confirmation from several DPAs that state a very different interpretation.

You can’t segregate the same service, two distinct services one that is provided with ads that include 3rd party cookies and a separate paid service that does not is perfectly fine.

What you cannot do is to create multiple tiers in a free service based on different levels of tracking.

Post reply on HN