Live data from Hacker News

Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

politico.eu

41–50 of 190 posts

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#41
post #28

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

>At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Cookie banners aren't a requirement unless you wish to store cookies that aren't strictly necessary (statistics, marketing, etc)[0]. Cookies that are essential for the user to browse the site (login tokens) don't require consent. It doesn't help the situation that a…

If your salary would drop 95% tomorrow if you didn't tell everyone at the office 'I may remember this conversation' every time you see them, what would you do?

Non targeted ads pay 90+% less than targeted. Sure it's not 'required', but the vast majority of businesses would fail overnight if their revenue dropped 90%.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#42
post #11

Quite apropos that this article was cookie-walled with a "We value your privacy. Customize/Agree" modal screen

Which is not compliant with GDPR if those were the only two prominent options.

Disagree must be as prominent as Agree.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#43
post #30
post #25

Earlier quoted context omitted.

> Not a GDPR thing, and the reason you see the banner is because companies refuse to understand the regulation correctly. Companies will never "understand the regulation correctly" because it's not in their interests. That is why the regulation should be bulletproof: as concise as possible while forcing the exact behaviour regulators intend.

> possible while forcing the exact behaviour regulators intend That's what I'm seeing happened? 1. Companies store personal data willy nilly 2. Regulators create directives that force companies to stop doing that, or at least be upfront about it 3. Companies who still want to do it, are at least up front about it, telling users what is happening 4. Users now complain about regulators that companies are letting them k…

[deleted]

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#44
post #26

Earlier quoted context omitted.

No. You really don't. Come on, burden of proof, show us where the GDPR says functional cookies require a banner?

How do you interpret this about strictly necessary cookies, from gdpr.eu? > While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.

Should is aspirational language, and is not legally binding or even coercing. It's like an encouraged practice.

Cookie banners where sites have to say "we're sharing your details with 287 partners" are okay because they should be shameful for the industry. Cookie banners where you're explaining basic technologies of the web -- "we store a cookie to create a stateful session with your browser" -- are obnoxious noise that do only harm.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#45
post #35

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

I don't see why small organizations should get to be more careless with my personal data than anybody else. The value of my privacy doesn't change just because of the size of the company.

They should not be careless, but they can be spared some paperwork as long as they stay compliant with the spirit of regulation.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#46

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

The cookie banners are largely a cargo cult and don't have to be nearly as annoying as they are. Websites just love to say "we have to do this" rather than improve their UX because the latter just means more work while the former gets people to be wrongfully upset at GDPR.

I think cookie banners are a not-so-subtle sabotage of the GDPR. The more annoyance they can associate with GDPR the more the customers will want to water it down. And bonus, it's completely deniable.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#47
post #2

Uh oh. I'm all for cutting the red tape, but (in my opinion) the GDPR is: 1) easy to comply with if you're not doing nasty stuff with people's data, 2) actually needed. Any opposing views?

Smaller entities should still be required to fix/delete your personal data on request, imho.

I'd also appreciate if the exception was conditional on not selling any data or using it for external advertising (i.e. "you might also like" suggestions would be okay, as long as they're part of the same service)

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#48
post #3

> The GDPR is seen as one of Europe's most complex pieces of legislation by the technology sector Really? Now I'm no bureaucrat, merely an engineer, but GDPR was relatively easy to read through, even the official document ( https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... ) is only 88 pages long, this cannot realistically be "one of Europe's most complex pieces of legislation". A lot of privacy-conscio…

Eh, you can see in this thread how all sorts of things are confusing. What, exactly, requires a cookie banner? Does an IP address in a log count as personal information on its own? And so on.

I can see why it was intended to be generic, but the lack of clear guidance and especially the lack of de minimis exemptions (one of the things mentioned to be addressed!) are a very real problem.

"What tests do I have to perform before asserting that I am CE compliant" is a similar, even vaguer question.

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#49

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

There is no such requirement, unless you want to steal peoples data or track them, and why would you want to do that?

Re: Europe's GDPR privacy law is headed for red tape bonfire within 'weeks'

#50

At the minimum I'd hope they a) do away with the worthless cookie banners requirement b) cut some generous but reasonable slack to small organizations. Interesting timing with the digital sovereignty movement.

The cookie banners aren't worthless. The websites presenting cookie banners either don't know the law, or are engaged in spyware shit. You don't need a cookie banner if you need it to provide a service that the user expects (e.g., saving settings, login).

As an EU citizen, I'm not concerned about your need to observe my behaviour or to prevent ad-click fraud. What I care about is websites sharing my navigation history with Google or the rest of the advertising industry, so yes, I'd like to be informed of it.

Personally, instead of having banners, I'd just ban the practices altogether (e.g., targeted advertising, 3rd party analytics), which would certainly simplify business.

Post reply on HN