Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

601–610 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#601
post #563
post #61

can you build a website nowadays with analytics without using cookies? or violating GDPR?

Best way is to self-host your analytics, the main thing about GDPR is not sending your data to third parties or using it for marketing/targeting purposes. By not sending the data to third-parties, you already comply to most of the GDPR policies.

Certainly one aspect of GDPR is about how you share data with third-parties. But self-hosted analytics are still subject to GDPR and/or ePrivacy restrictions if you process full (unredacted) IP addresses, any user-identifying tokens, or anything else deemed as PII (Personally Identifiable Information) for purposes such as analytics without seeking user consent.

Re: Dear Paul Graham, there is no cookie banner law

#602
post #454

Earlier quoted context omitted.

Yeah, but these are rather theoretical practicalities. In the majority of cases, consent is coaxed out of the consumer. If you show up for a MRI, and you get a piece of paper with the comment "It is for data protection", almost nobody has the time or nerve to actually read the text, and even less people have the inclination to decline to sign. After all, they (sometimes desperately) need the service. Let alone that t…

Under GDPR, your MRI example and your bank example do not qualify as consent. (For the MRI example, they might be able to claim basis b, but only if they're doing stuff that you could actually have requested.)

I don't feel confident a complaint would be easy to get through. After all, my MRI example is standard procedure, good luck making a case against that. Besides, layers cost money.

Re: Dear Paul Graham, there is no cookie banner law

#603
post #559

Earlier quoted context omitted.

It's so depressing. Many of the people who are pointing the finger at the regulators for the annoying cookie banners don't actually see the web site/app *as* a bad actor. The fact that they had been tracking tons of extra data via cookies without their consent or knowledge was totally fine to them as long as it wasn't inconveniencing them in any way. The cookie banner is an inconvenience to their mindless consumption…

> don't actually see the web site/app as a bad Some of these bad actors actors with annoying cookie banners: https://gdpr.eu/ https://european-union.europa.eu/ https://www.europarl.europa.eu/portal/en

I only got cookie banners on the first two links and they were extremely unobtrusive. You did not make the point you had hoped to make.

Re: Dear Paul Graham, there is no cookie banner law

#604

Paul Graham is right still. Eu bureaucrats could have expected that many companies _need_ tracking to survive. While most people do not actually care about tracking. Not to mention that behind most companies are the people who earn their living. By honest work (advertising is not guns smuggling you know). So eventually those stupid bureaucrats didn’t really solve anything, but made life slightly worse for everyone. W…

Or you could look at it like this: Big websites are tracking people, unknowingly to them, giving them lots of power, because information is power these days. And the sites that treat their customers fairly and honestly, ie they just want to offer you their product/service and are not interested in making a profit from your information, are not highlighted for their good intentions. This law makes the difference clear…

> unknowingly to them, giving them lots of power, because information is power these days

How much power exactly does a website get by saving a cookie with my data?

Re: Dear Paul Graham, there is no cookie banner law

#605

Paul Graham is right still. Eu bureaucrats could have expected that many companies _need_ tracking to survive. While most people do not actually care about tracking. Not to mention that behind most companies are the people who earn their living. By honest work (advertising is not guns smuggling you know). So eventually those stupid bureaucrats didn’t really solve anything, but made life slightly worse for everyone. W…

Or you could look at it like this: Big websites are tracking people, unknowingly to them, giving them lots of power, because information is power these days. And the sites that treat their customers fairly and honestly, ie they just want to offer you their product/service and are not interested in making a profit from your information, are not highlighted for their good intentions. This law makes the difference clear…

> And I understand that most people don't care because they are ignorant about the issues and consequences

No, people don’t care because there are no consequences. Except just better targeTed ads.

Most people on HN are hackers, they know exactly how this works.

If you were brainwashed to be scared - doesn’t mean I as a user must pay for it with my attention.

Re: Dear Paul Graham, there is no cookie banner law

#606
post #526

Earlier quoted context omitted.

> It’s an inconvenience to people who care about privacy and use browser configurations that don’t store state between visits. > > So now in an attempt to protect regular users, the law ended up hurting users that already cared. Fair point about the banners mostly "hurting" users who care about privacy (but, really though- how much does it really "hurt" you? I'm "hurt" more by the fact that I have to fold laundry sev…

> Companies are under no legal obligation to make those banners as obnoxious as they are Actually every single lawyer we asked about implementing GDPR advised us to have one of those obnoxious banners. Because the law is so ambiguous and the penalties so high that is better to play it safe. And we have no ads nor tracking at all on our product website. You can ignore your lawyer's advice if you want, but it's a bit l…

If you are using cookies for user preferences/settings, then they require consent. If you are only using cookies for session information (like a shopping cart), then you don't have to get consent. Your lawyers know this.

Frankly, I doubt the veracity of this anecdote. But even so, I'm willing to bet that the lawyers in this story did not tell you that the banners have to cover half the screen and have ambiguous wording to intentionally confuse visitors to your site. When I say "obnoxious banner" I'm not being redundant: not all banners or popovers are "obnoxious".

Re: Dear Paul Graham, there is no cookie banner law

#607
post #601
post #563

Earlier quoted context omitted.

Best way is to self-host your analytics, the main thing about GDPR is not sending your data to third parties or using it for marketing/targeting purposes. By not sending the data to third-parties, you already comply to most of the GDPR policies.

Certainly one aspect of GDPR is about how you share data with third-parties. But self-hosted analytics are still subject to GDPR and/or ePrivacy restrictions if you process full (unredacted) IP addresses, any user-identifying tokens, or anything else deemed as PII (Personally Identifiable Information) for purposes such as analytics without seeking user consent.

That's true, but the "analytics" purpose is ambiguous. It could be for security most servers already have access logs by default, that stores IP addresses anyway, and it's often used for DDOS protection for example or fail2ban login attempts.

Re: Dear Paul Graham, there is no cookie banner law

#608
post #538

Earlier quoted context omitted.

“ Selling my personal info to external companies” What? What are you even talking about? Google does not sell your personal info. You’re delusional

You attributed a medical diagnose to me for saying something that is possibly uninformed. That makes me not ever want to have a conversation with you again. Just food for thought... Turns out you were the uninformed one. From the context through parent posts you can clearly see this was about a website using google adsense and by that, the company sells my info to an external (google) which then tries to take advanta…

“ Turns out you were the uninformed one. From the context through parent posts you can clearly see this was about a website using google adsense and by that, the company sells my info to an external (google) which then tries to take advantage of me to extract money from me.”

This is not how it works. You might not be medically delusional but you are saying things that are not true.

Re: Dear Paul Graham, there is no cookie banner law

#609

Earlier quoted context omitted.

Or you could look at it like this: Big websites are tracking people, unknowingly to them, giving them lots of power, because information is power these days. And the sites that treat their customers fairly and honestly, ie they just want to offer you their product/service and are not interested in making a profit from your information, are not highlighted for their good intentions. This law makes the difference clear…

Maybe the next step would be that websites should adhere to the "Do not track" browser option, and not show the popup when people have that option on. I think that would make a lot of people very happy. The businesses that thrive on data collection not of course, but who cares about them really? People might say they pay our salaries, but if they don't thrive, other businesses will thrive, and they will pay our salar…

> if they don't thrive, other businesses will thrive

You know what else is true?

If dumb bueroucrats don’t spend time on a silly solutions to artificial problems - they would spend it on solving real meaningful issues.

I think we can at least agree on that.

Re: Dear Paul Graham, there is no cookie banner law

#610

Earlier quoted context omitted.

The EU isn't forcing me or you to do anything. The article elaborates on this point: There Is No Cookie Banner Law. Only bad website operators choosing to abuse their users with annoying consent dialogs. Nobody in Europe is issuing "diktats", meaning citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data. Just don't process EU citizen data and it's no…

I actually self-host all my web assets and use Matomo already. So I do actually agree with the premise. What I object to strenuously is someone dictating terms to the world from distant shores, especially since they seem not to get how the internet works (it’s all funded by ads, online sales, and ads for online sales, all of which involve metrics and tracking!) The diktats I mentioned include a ruling that Google Fon…

Please tone down the hyperbolic rhetoric and FUD. Consider how strongly you can make your point without them.

To the point: Nobody in Europe is "dictating terms to the world", or "issuing diktats", meaning passing citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data.

> The diktats I mentioned include a ruling that Google Fonts are illegal now. So if I’m using those, or I’m using Google Analytics, and a European happens across my site, I’m now a criminal?

No, because website operators have at least 4 more options:

1. Don't process EU citizen data (block them).

2. Don't track users, period (host the font on the site instead).

3. Don't track users until they log in (convert them).

4. Get users' informed consent (let them know that they'll be tracked on the site due to the choice of google fonts instead of hosting a font).

Wow, that wasn't scary at all! The general attitude I'm getting from some folks, though, is that they want to do anything they want to users without consequence and never change. This attitude is going lead to a lot of anguish. Others have rights, too, and they override our right to do whatever we want to them, in many cases.

Post reply on HN