Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

511–520 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#511
post #223

Earlier quoted context omitted.

The actual outcome is, from my experience, that tracking has reduced, a lot. When this law was enacted, *we all removed "like on Facebook"* buttons. Remember those? Yeah, we don't see them anymore. Google Analytics also was forced to change, at least a little. Is there still tracking? Sure. But it's not so blatant anymore. There are hoops one needs to jump through. And that was the point - to make tracking a harder.…

It’s not the difficulty level that people object to. It’s a combination of two things: 1) the law comes to the rest of the world from Europe. We (rest of the world) didn’t vote in the people who brought it. We’ve had quite enough of Europeans making rules for the rest of the world in the past few centuries thank you very much. 2) GDPR encodes an expectation that may or may not be common in the EU, but certainly isn’t…

So, I get your point. I can see how (1) can be aggravating. Can't really say anything to defend it, that's the Brussels effect for you. From the point of view of your own sovereignty, it's a bad thing, period. From the point of view of an effect on the lives of average people, I'm not so sure, it's so cut and dry.

Now, point (2) is, unfortunately, in the same vein as smoking, pollution, seat belts etc. Uninformed people (uninformed because they have better things to do) are not protected from their lack of knowledge. They suffer the consequences just the same.

And while I agree that and informed person, making a self-destructive choice has (in most cases) the right to do so, there is something to be said about the very, very powerful exploiting the uninformed. And this is where GDPR comes into play. It's protecting normal people, from a very, very big threat, that is not that obvious and is being wielded by the powerful.

GDPR is one of those laws restraining western corporations from going full dystopian future on us all. I said restraining, to be honest, I think it's just slowing them down.

And as far as surveys go - it used to be the same here. Europeans didn't care and said exactly the same things (i.e. the famous "i didn't do anything wrong, so I have nothing to hide") and then activists worked for years to educate them that, at the very least, it's leading them to buy things at higher prices. Now most people are extremely sensitive to their data.

Re: Dear Paul Graham, there is no cookie banner law

#512
post #89

"Companies could easily avoid any cookie banner. Just don’t track." It seems like a point dear to the author's heart, given the way he highlights this and puts it in bold at the top of the article. But while it sounds good on the surface, it doesn't take much digging to show it's silly. If you store any kind of data about a visitor to make their life more convenient, is that tracking? Shopping carts? Notification pre…

Shopping carts and notification preferences don't require a consent banner.

It is not that simple. In "Opinion 04/2012 on Cookie Consent Exemption" [1] the the EU Parliament's Working Party On The Protection Of Individuals With Regard To The Processing Of Personal Data said:

> A cookie that is exempted from consent should have a lifespan that is in direct relation to the purpose it is used for, and must be set to expire once it is not needed, taking into account the reasonable expectations of the average user or subscriber. This suggests that cookies that match CRITERION A and B will likely be cookies that are set to expire when the browser session ends or even earlier. However, this is not always the case. For example, in the shopping basket scenario presented in the following section, a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours in the future to take into account the fact that the user may accidentally close his browser and could have a reasonable expectation to recover the contents of his shopping basket when he returns to the merchant’s website in the following minutes. In other cases, the user may explicitly ask the service to remember some information from one session to another, which requires the use of persistent cookies to fulfil that purpose.

(Criterion A is cookies that are user “for the sole purpose of carrying out the transmission of a communication over an electronic communications network” and criterion B is cookies that are “strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service”).

If your shopping cart cookie has a lifetime longer than the "reasonable expectations of the average user or subscriber" you may need to obtain consent. That a sufficiently vague criteria that it may not be clear if your particular shopping cart cookie requires consent or not.

[1] https://ec.europa.eu/justice/article-29/documentation/opinio...

Re: Dear Paul Graham, there is no cookie banner law

#513

Earlier quoted context omitted.

well, if you respect the do not track setting and therefore DO NOT TRACK, then just remove the banner. You have not obligation to tell people that you do not track because you do not track.

Are you 100% confident that you don’t do anything which could be construed as tracking by a hostile regulator? Even the official EU sites that host the relevant regulations have cookie banners, explaining ( https://eur-lex.europa.eu/content/legal-notice/legal-notice.... ) that they can’t otherwise do basic analytics or interface persistence.

Better safe than sorry... Absolutely. If you work with a company, where you cannot guarantee that no tracking will be injected into their users computers, then you better add the disclaimer.

Also, if you feel certain, and a ready to defend in court, that practices you have on your website does not constitute tracking. Then you don't have to show the banner either.

Personally, I am much more pragmatic about these regulations - with good reason. I still have to hear about some small innocent company hit with a massive fine. Empirically speaking, it is mostly huge multinational companies with plenty of resources to manage these things down into details who have gotten fines after repeat offences.

All in all. If you assume malicious regulators, then it is going to be stressful to work in a market. From US influence, I also do understand the sentiment, though it is rarely mirrored with EU citizens who generally don't assume hostile regulation.

Re: Dear Paul Graham, there is no cookie banner law

#514
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

I think this is a good analogy and I agree that the intent of the law was not to force websites to have a cookie banner, it was just the side effect.

What I think we are missing is a browser option/API that lets the user choose the acceptable tracking level. Similar to the do not track header but more fine grained.

As we are missing that, extensions are doing a good job ATM

https://chromewebstore.google.com/detail/consent-o-matic/mdj...

https://addons.mozilla.org/ro/firefox/addon/consent-o-matic/

I found pretty late about Consent-o matic and it saved me a ton of time handling banners. It's exactly what we should have built-in the browser.

Re: Dear Paul Graham, there is no cookie banner law

#515
post #422
post #72

Earlier quoted context omitted.

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

> Doesn't require tracking of individuals. Only if you maintain your own ad inventory, instead of using Google/Facebook ads like 90% of online advertisers do. And neither of those platforms work without installing their scripts on your site.

Sure, lots of people want to sell my data. That's a choice. You don't need to do that for advertising - it's a pretty recent invention having fully personalised adverts.

Re: Dear Paul Graham, there is no cookie banner law

#516
post #422

Earlier quoted context omitted.

> Doesn't require tracking of individuals. Only if you maintain your own ad inventory, instead of using Google/Facebook ads like 90% of online advertisers do. And neither of those platforms work without installing their scripts on your site.

And they did it that way because they could. It could be done a different way.

It would be like opening an independent video store when the entire market has moved to streaming. Yeah you could try it, but there are good reasons not to.

Re: Dear Paul Graham, there is no cookie banner law

#517

Europe's parliament's site has cookie banner[1]. People saying you don't need cookie banner either haven't worked in companies or are purely driven by ideology. [1]: https://www.europarl.europa.eu/portal/en

The site also shows how simple it could be, though - it respects the DNT flag: no cookie banner, no tracking in this case.

It's a case of moving goalposts. The thing claimed is that sites don't need cookie banner and a simple parliament site needs it.

Re: Dear Paul Graham, there is no cookie banner law

#518
post #511

Earlier quoted context omitted.

It’s not the difficulty level that people object to. It’s a combination of two things: 1) the law comes to the rest of the world from Europe. We (rest of the world) didn’t vote in the people who brought it. We’ve had quite enough of Europeans making rules for the rest of the world in the past few centuries thank you very much. 2) GDPR encodes an expectation that may or may not be common in the EU, but certainly isn’t…

So, I get your point. I can see how (1) can be aggravating. Can't really say anything to defend it, that's the Brussels effect for you. From the point of view of your own sovereignty, it's a bad thing, period. From the point of view of an effect on the lives of average people, I'm not so sure, it's so cut and dry. Now, point (2) is, unfortunately, in the same vein as smoking, pollution, seat belts etc. Uninformed peo…

I get it - what you're saying is a very common-sense regulation. Reasonable people can disagree about this.

But different societies prefer a different balance here.

Americans are used to a more caveat emptor situation. Europeans want more regulation. Which one to choose is a political choice.

What's happening is that the political choice that the EU went with is being forced on the rest of us, whether we like it or not.

Re: Dear Paul Graham, there is no cookie banner law

#519
post #431

Earlier quoted context omitted.

Your legal team is holding the door open for the day they decide to start tracking. They probably won't tell you that, tho.

Our legal team is following the checklist that they have that they know is pre-approved

Which was probably written (even if not by the legal team, but someone they consulted) with an eye towards keeping more data than legitimate interest allows under GDPR.

Re: Dear Paul Graham, there is no cookie banner law

#520

Earlier quoted context omitted.

Thanks for this, it seems a lot of cookie popups are there just due to cargo culting

I don't quite think Cargo Culting is the right label for it. It's not just because everyone's doing it. My experience when legal meets code is that common sense, intent and what is actually allowed go out the window, and cover-your-ass wins. My experience with Legal has been that they default to no "just in case" for every question you come to them with. It's a battle to get them onboard to not taking the safest poss…

The funny thing is that most of the CYA cookie banners... are in themselves GDPR violations
Post reply on HN