Earlier quoted context omitted.
Mentioning user tracking in a TOS or privacy policy that is mandatory to accept in order to use the service is no longer legal. This article may help you understand what consent means under GDPR: https://www.privacypolicies.com/blog/gdpr-consent-examples/#...
GDPR has lots of issues and this is one of the major ones. It can be easily argued that companies cannot be forced to service users and there has been no real precedent or enforcement around this.
No Cookie for You
591–600 of 634 posts
Re: No Cookie for You
#592Earlier quoted context omitted.
> GitHub still sends the same personal data to their own analytics endpoint I see nothing wrong with that. Analysing your users on your own site is no problem for me. I should know what users do on my property. What's the problem you have with that?
It's not GDPR compliant without consent. It doesn't matter whether you are using cookies or something else.
It's perfectly possible for GitHub to process personal information without explicit consent while not violating the GDPR. Several options come to mind:
1) consider analytics part of the "contract legal" basis, arguing that analytics to improve the usability of the website is a fundamental part of running a website.
2) The "legitimate interest" lawful basis, which states:
> processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Arguing that improving the accessibility/usability is in the legitimate interest of both company and user.
I'm fairly confident that, depending on which and what detail of personal information, both of these justifications will be accepted by EU courts.
Re: No Cookie for You
#593(GitHub CEO) Hi everyone, thanks for all the enthusiasm about this change. We are happy to have removed cookie banners from GitHub, and not to participate in third-party tracking of user behavior. Our privacy policies and subprocessor list will be updated next week following our customary 30 day user notice period. We do this in the open in a pull request, so you can see the changes now: https://github.com/github/sit…
Hi! Please also look into the collector.githubapp.com analytics endpoint, the request does not seem to be compatible with GDPR in its current form. Either unique IDs tied to the user will have to be removed, or express consent will have to be requested. https://news.ycombinator.com/item?id=25461825
Why is it not GDPR compliant. You do not need consent under the GDPR. You need a (documented) "lawful basis for processing" personal information. Consent is just one of several lawful bases and honestly it's the most useless one, if you need consent your business model is screwed. It's perfectly possible for GitHub to process personal information without explicit consent while not violating the GDPR. Several options come to mind:
1) consider analytics part of the "contract legal" basis, arguing that analytics to improve the usability of the website is a fundamental part of running a website.
2) The "legitimate interest" lawful basis, which states:
> processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Arguing that improving the accessibility/usability is in the legitimate interest of both company and user.
I'm fairly confident that, depending on which and what detail of personal information, both of these justifications will be accepted by EU courts.
Re: No Cookie for You
#594Earlier quoted context omitted.
Back in the days there was the P3P protocol ( https://en.wikipedia.org/wiki/P3P ) supported by IE and Edge, but it didn't work out and was abandoned. There is also `Do Not Track` header but it is not respected by most of websites. You can also reject all cookies in any web browser, but then majority of web pages will not work properly.
I accept but don't save any cookies except certain whitelisted ones. So I get a lot of cookie policy banners and I always click the full 'accept all' option because at best it'll just eat into their database storage and I'll arrive with no stored cookies the next time I visit the site. The browser allows me to accept all cookies or non-third-party cookies automatically but I still get these stupid cookie policy banne…
Under GDPR, this requires a clear, unambiguous consent, freely given. How can you understand what you consent to if you blanket-accept everything? And thus the consent is invalid. And they need a new banner.
Re: No Cookie for You
#595Earlier quoted context omitted.
Not necessarily. Only if personal data is collected by the third party.
You need to notify users, and give them an opt-out, if the cookies are not strictly necessary for the provision of the service. Analytics cookies are not strictly necessary.
Re: No Cookie for You
#596Earlier quoted context omitted.
This is all detailed in our updated privacy policy: https://github.com/github/site-policy/pull/336
Thanks for responding Nat. My interpretation from the PR: You've stopped using cookies as a mechanism for marketing/tracking. But you're still doing it by other means. Rationale: 1. You are still tracking and may share the data with 3rd parties. Justification: privacy statement [0] line 147. It states that data are "aggregated, non-personally identified" which might mean it's GDPR compliant. OTOH: you're presumably h…
Re: No Cookie for You
#597Earlier quoted context omitted.
A GitHub spokesperson has issued this statement [1] about a request to api.github.com: "That endpoint tracks aggregate performance metrics, and does not rely on cookies or other unique identifiers". GitHub is still sending our usernames and other unique IDs, our device data, and the pages we visit to the collector.githubapp.com endpoint. GitHub's claims about not tracking users are false, they do identify users in tr…
this isn't about tracking users, it's about cookies. no cookies doesn't mean no tracking. it's just a workaround to improve UX. "visiting our website does not send any information to third-party analytics services" - but presumably third parties are still able to access this data on request. their privacy policy probably reflects this. if you visit a website and don't want to be tracked, make it as hard as possible f…
Except the GDPR and cookie directive, obviously, undeniably, unmistakably, weren't intended to give websites a "bad UX" obstacle to work around.
It's not even about cookies. It's about letting users AGREE to being tracked and then track them, OR (with the same amount of effort and without denying them service vs tracked people) DISAGREE and then not track them.
If they're still tracking me and keeping data about me that they can match to the PI that is my github account, then this "no cookie" thing is just more "letter of the law" bullshit.
I think it's pretty damn clear to Github and MS what the intention of these EU laws are. They can't just say "oh it's worded in a way that gives us wiggle room, so fuck your intentions". Well they can but they'll find out whose faces they told "fuck your intentions" to.
We're trying to protect consumers from tracking bullshit, here. Not throwing up obstacles for large corporations to work around.
Re: No Cookie for You
#598Earlier quoted context omitted.
I accept but don't save any cookies except certain whitelisted ones. So I get a lot of cookie policy banners and I always click the full 'accept all' option because at best it'll just eat into their database storage and I'll arrive with no stored cookies the next time I visit the site. The browser allows me to accept all cookies or non-third-party cookies automatically but I still get these stupid cookie policy banne…
Quite a lot of "cookie banners" are really banners to allow third parties to track you. Under GDPR, this requires a clear, unambiguous consent, freely given. How can you understand what you consent to if you blanket-accept everything? And thus the consent is invalid. And they need a new banner.
Re: No Cookie for You
#599Earlier quoted context omitted.
Yes, they can do anything with the user's data, if the user has consented, or if they are willing to break the law. The tracking request you see above requires informed consent under GDPR, and GitHub does not ask for consent before collecting browsing and device data that is tied to GitHub usernames.
consent is simple to gain, who reads the entire ToS and privacy policy? the law is simple to break and appear as if you're not. they're a big company and will have this covered if needed the bottom line is, do you place more trust in your local lawmakers and the website you are visiting than you do in yourself
nobody because they are pretty much meaningless in the EU
we got laws to protect consumers, not laws for businesses to trick users into making some meaningless gesture
> the bottom line is, do you place more trust in your local lawmakers and the website you are visiting than you do in yourself
what do you mean by "local lawmakers"? these laws are EU-wide. or did you mean "local" to mean, "non-US"
anyway, these lawmakers are fighting the shitty corporations that pull this tracking stuff
and your bottom line is not really a choice one way or the other. I can use blockers and other plugins to protect myself, AND cheer on the people fighting the fuckfaces that think it's in any way honourable to make a profit by merely following the letter of our laws
but we got some really good consumer protections in the EU. and we try to keep it that way. we're not going to simply roll over because some US corporations are used to being able to track the hell out of US customers
Re: No Cookie for You
#600Earlier quoted context omitted.
> Tracking cookies have little value for GitHub when they can collect data about users that have already been authenticated This is true to every advertiser or data seller, Including obvious ones like Google, FB, Amazon... and less obvious ones like your ISP, Apple, etc. The industry call it persistent ID (as opposed to cookie, which are transient ID): https://digiday.com/marketing/wtf-persistent-id/ (random result,…
History, ZIP and DNA already are personally identifiable information (PII). Pseudonymisation is in general not enough to avoid the GDPR and similar laws. And pseudonymisation would require the removal or obfuscation of all PII to the point that it is impossible to reconstruct the identity of the user. There's no specific list of information regarded as PII, it's PII if it can be used to identify the user, even if onl…
fortunately, "undermining the spirit of the law in order to continue to make a profit" is generally frowned upon in the EU, and lawmakers don't take too kindly to it. sometimes I get the feeling that in the US it's almost acceptable to publicly brag about doing this, like it's even more "socially" acceptable.