Live data from Hacker News

Most websites don't need cookie consent banners

block81.com

71–80 of 103 posts

Re: Most websites don't need cookie consent banners

#71

I wonder how many people provide consent through these banners. Is it frequent enough to be worth the terrible user experience? I know some sites use dark patterns in their cookie banners, which I consider to be a helpful hint that the company doesn't respect the users.

Most of the sites use dark patterns in the banners, from not presenting decline option to hiding and renaming it to be unrecognizable. For example I make an effort in always picking Decline All option if available and the practice shows that I click on Allow All in about 20-30% of all banners, because it was impossible to avoid. So I safely assume that general population clicks Allow All even more.

Re: Most websites don't need cookie consent banners

#72
post #71

I wonder how many people provide consent through these banners. Is it frequent enough to be worth the terrible user experience? I know some sites use dark patterns in their cookie banners, which I consider to be a helpful hint that the company doesn't respect the users.

Most of the sites use dark patterns in the banners, from not presenting decline option to hiding and renaming it to be unrecognizable. For example I make an effort in always picking Decline All option if available and the practice shows that I click on Allow All in about 20-30% of all banners, because it was impossible to avoid. So I safely assume that general population clicks Allow All even more.

From what I understood—but I think it's been added more recently—declining all optional cookies must be as easy as accepting all cookies.

Re: Most websites don't need cookie consent banners

#73
post #8

Earlier quoted context omitted.

You can track conversions exactly without using analytics or cookies, by using promotion codes.

"you can" and no one does.

It's not that uncommon. It's a completely reliable solution to the problem of attributing sales and knowing how much each advertising channel generate individually in sales.

But taking into account that almost all jobs in advertising depend on keeping it "a mystery", it's no surprise that relatively few companies do it.

After all, it looks better if you tell your boss or your customer that they had 40 000 "impressions" thanks to your campaign, rather than 400 definite sales.

Re: Most websites don't need cookie consent banners

#74

Earlier quoted context omitted.

Those are technically in violation of the GDPR since the opt out is required to be just as easy as the opt in.

Except there are plenty of websites that are: accept cookies (yes) (no - you must pay), which is an extreme breach of GDPR. But GDPR is toothless and ill thought out.

The effectiveness will vary with how well it will enforce, which is up to EU states to decide at the national level.

Re: Most websites don't need cookie consent banners

#75
post #33

Earlier quoted context omitted.

Those are technically in violation of the GDPR since the opt out is required to be just as easy as the opt in.

How is ease of opt out versus opt in objectively measured? Most of the time both options are presented clearly and within a few pixels from each other, but opt-in is usually slightly more eye catching and/or more appealing. But the effort in terms of distance for mouse movement or number of clicks is the same. While that’s a design trick that will improve % of opt-in, how can it be argued that the opt-out was not as…

The wording is such [0]:

> If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.

> ... It shall be as easy to withdraw as to give consent.

Your example does appear muddy, but I also doubt any enforcement targetting such sites.

What however is extremely common is an "Accept all" vs "Manage settings" which opens up another panel, where there is still no "Reject all" option, and only various settings where you can "Save choices" which might or might not default to what you want. Such cases are obviously blatant rule violations, both in amount of clicks and obfuscation of consent.

[0] https://gdpr.eu/article-7-how-to-get-consent-to-collect-pers...

Re: Most websites don't need cookie consent banners

#76
post #64

Earlier quoted context omitted.

Covered under the law: they are, they really are. You're required to disclose. I didn't say consent. This is precisely why I say talk to a lawyer. I appreciate the firmness of your conviction, but not reading what was explicitly stated, well.

> I appreciate the firmness of your conviction I don’t understand how you could misread “firmness of conviction” in my comment. I made it as short, bland, and neutral as possible, on purpose. It’s just a statement of fact with a source.

A statement of fact in response to a thing I didn't say.

Re: Most websites don't need cookie consent banners

#77

Earlier quoted context omitted.

This response sounds suspiciously like competence. Do you mind disclosing which consent provider you work for, so I can have a look? (I only ever found one consent product I was really happy with, and it shut down a few months after I discovered it.)

It's DataGrail. I don't mind disclosing it, but I was kinda hoping not to because I'm really not here to advertise... I guess I won't say I know the subject, but do have some experience. lol. I'd be happy to discuss directly if you want. Not sure how to exchange details if you're interested but we can figure something out I guess.

Unfortunately, DataGrail is a US-based company using Google Tag Manager to provide personal information about its website users to Facebook, Microsoft, Google, and other advertising companies. Per the Privacy Policy, the company seems to believe that pseudo-anonymization is sufficient to be allowed to keep and use personal data for any purpose, which it is not: per GDPR, data minimisation is necessary, but doesn't exempt you from properly fulfilling deletion requests. I can't find out how they actually use personal information collected from users: the best I can find is:

> If you have any questions about the lawful bases upon which we collect and use your personal data, please submit a request through the DataGrail’s Privacy Request Form or email DataGrail at privacy@datagrail.io.

Informing me of my "right to obtain" certain information without actually providing it is not okay; and the rather selective descriptions of the rights of the data subject feel like a GDPR Article 12 violation. (For example, it partially discusses Article 15(1), but omits Article 15(2).) Having investigated the Privacy Request Form (https://preferences.datagrail.io/form/access), it's requesting I identify myself in order to learn how my personal information's being used. I can't remember the exact reference, but I'm pretty sure this is explicitly forbidden by GDPR: something about not gathering or storing information with "it's needed to satisfy GDPR's bureaucratic requirements" as justification. (Yes, I know I can email instead: that's not the point.)

I could go on, but… it doesn't really matter how good a company's services are (and those services do look pretty good!) if I can't trust the company to begin with. DataGrail appears typical for the industry, rather than exemplary (as I had hoped it would be).

Re: Most websites don't need cookie consent banners

#78

Disclaimer: I work on a consent product. If you're in any way something beyond a hobbyist, you should probably get legal advice about whether you need to get affirmative or implicit consent, whether you need to handle universal opt-out signals (in California, Global Privacy Control signals are now legally required to be respected), etc. Simply saying "oh I'm only tracking local cookies" might not even be enough in GD…

> Disclaimer: I work on a consent product. Forgive me for immediately untrusting you on the matter because the reality distortion field must be strong. Cookie banners are an absolute crystal clear evil and there is absolutely no leeway for a different opinion here. (Tracking is also an undisputed evil) > Consent banners don't have to be awful, I promise. False. They absolutely have to be awful because that's the whol…

Why are you tracking when it's an undisputed evil? Reality distortion indeed.

Is getting consent interruptive? yes. Is that worse than not getting consent? Also yes.

Since you don't appear to want to give up the undisputed evil of tracking, then consent is what's left to you. You've made the same choice as everyone else.

I'd encourage you to respect GPC and DNT, so the (roughly 20%, depending on audience) of users that have it enabled can automatically opt out of your tracking without the "crystal clear evil" of a consent banner. Remember that in California you need to show some display that their consent choices have been observed.

Re: Most websites don't need cookie consent banners

#79

Earlier quoted context omitted.

It's DataGrail. I don't mind disclosing it, but I was kinda hoping not to because I'm really not here to advertise... I guess I won't say I know the subject, but do have some experience. lol. I'd be happy to discuss directly if you want. Not sure how to exchange details if you're interested but we can figure something out I guess.

Unfortunately, DataGrail is a US-based company using Google Tag Manager to provide personal information about its website users to Facebook, Microsoft, Google, and other advertising companies. Per the Privacy Policy, the company seems to believe that pseudo-anonymization is sufficient to be allowed to keep and use personal data for any purpose, which it is not: per GDPR, data minimisation is necessary , but doesn't e…

I had realized, "l'esprit de l'escalier," that your ask wasn't in earnest and you were just looking to raise issues.

Sorry to have bothered you, but I assure you that your Access or Deletion request will be processed when you submit it. I know that submitting an email in a form is so much different for you than sending an email (since you've characterized it as somehow acceptable).

Are you suggesting that we should "provide the information from your GDPR access request without you actually asking for us to do so, without any commercially reasonable verification?"

Note I won't be responding further: you're not in earnest. But I do assure you that any requests will be properly processed.

Had you communicated your consent preferences through GPC or DNT, all those scripts that you call out would have been blocked. Just for your awareness.

Re: Most websites don't need cookie consent banners

#80

Disclaimer: I work on a consent product. If you're in any way something beyond a hobbyist, you should probably get legal advice about whether you need to get affirmative or implicit consent, whether you need to handle universal opt-out signals (in California, Global Privacy Control signals are now legally required to be respected), etc. Simply saying "oh I'm only tracking local cookies" might not even be enough in GD…

> proper consent banner It is also quite complex to integrate a third-party consent management platform in a compliant way; the tool itself is a script, but it somehow needs to preempt loading of any other scripts until the right consent is given (there's also an argument whether the CMP being third-party is itself a breach of "data minimization" when such functionality can trivially be done in-house, or at least sel…

CMPs generally don't do well with this. Admittedly.
Post reply on HN