Earlier quoted context omitted.
> Some websites, especially small ones operated outside of the EU, simply don't care about their obligations under European law. What about lobster.rs? Such as HN? Honest question, for all I know they're breaking EU law and nobody cares. Or maybe they don't. Anyway, pouet.net doesn't have one. It links to a ton of group sites, many European, try to count the ones that don't have a cookie banner. For fun, I did a quic…
HN used to be non-compliant, but does seem to have fixed it, I'm not seeing any cookies in a browser where I'm not logged in. pouet.net is tracking me. On my first visit they deposited a cookie named POUETSESS4 with a 1 year expiry and a persistent hash identifier in my browser. I checked a few outbound links from that site to European domains, and it does seem to be about 50/50 on whether they have similar problems,…
I'd say it's simply not in the spirit of the law. I.e. that cookie could be used to track you, but isn't. Sure, they could be secretly selling your info, but they could also be secretly storing your IP and anything else to fingerprint you. That would also be illegal, and no way you could know from the outside. So why are there not constant raids all over Europe, all the time?
As I said, I do think it's because that law isn't enforced to just waste time on BS. If I walk across a red light in the middle of the night [0], where there's a car every 5 minutes, and do it carefully after looking left, right, left again, and you run up to cops parked nearby who saw that, and insist they do something, they'll laugh at you. If you insist and freak out, you have a bigger chance to get in trouble than I do. But that's not some sinister law that everyone breaks and that is enforced selectively, it really is for what it says on the tin, what a reasonable person would abide by it for.
[0] Or put a session cookie I never use except for logged in users, and without any PII, because the site was written in 2000 and it's fine.