Live data from Hacker News

Most websites don't need cookie consent banners

block81.com

81–90 of 103 posts

Re: Most websites don't need cookie consent banners

#81
post #64

Earlier quoted context omitted.

> I appreciate the firmness of your conviction I don’t understand how you could misread “firmness of conviction” in my comment. I made it as short, bland, and neutral as possible, on purpose. It’s just a statement of fact with a source.

A statement of fact in response to a thing I didn't say.

In fairness, I have worked for a company which did talk to a lawyer about this and ultimately we didn’t have a cookie banner nor a disclosure of the cookies used (cookies were minimal and without personal information, essentially site settings not even associated with accounts).

So I didn’t misinterpret what you said, it’s just that I have seen consent and disclosure always hand in hand.

It’s been years since I read the law in full myself, so it’s possible you’re right. I’m going by my own recollection (which can obviously be flawed) and the result of a lawyer’s interpretation (which is the thing you recommended) but I’m not one myself.

I still don’t understand (nor have you addressed) how you misread “firmness of conviction” in my words, especially when I purposefully did the opposite because I understand that these legal matters can get fuzzy.

Re: Most websites don't need cookie consent banners

#82
post #6

"Advertising or behavioral tracking cookies" Any real business needs to do behavioral tracking for campaign conversions, add-to-cart, customer acquisition, funneling, retention, personalization, etc. I love how we all hate cookie banners and say they are unnecessary, but are salaries are all paid by apps that do behavioral tracking. Only hobby blogs can get by without it.

There's no _need_ to use cookies for tracking purposes though, it's usually just easier/cheaper/quicker (or requested by the marketing department) to use off the shelf software than actually spend the time to implement these things.

But if you have a cart, you need a cookie banner regardless of any tracking you are doing.

Re: Most websites don't need cookie consent banners

#83
post #40

Earlier quoted context omitted.

No thats not true

Disagreed. You can absolutely do all analytics, personalization and marketing in-house on your properties. You only need data sharing if you want to influence advertising on other properties or if you display others' ads on yours. Whether you want to do so is a different matter. This obviously requires (potentially custom) software and infrastructure, vs throwing in GTM and calling it a day. If there is no regulatory…

1st party behavior tracking still requires consent. And nearly every business needs third party integrations. I’m still waiting for someone to give me a working example (a real business )

Re: Most websites don't need cookie consent banners

#84

Earlier quoted context omitted.

Unfortunately, DataGrail is a US-based company using Google Tag Manager to provide personal information about its website users to Facebook, Microsoft, Google, and other advertising companies. Per the Privacy Policy, the company seems to believe that pseudo-anonymization is sufficient to be allowed to keep and use personal data for any purpose, which it is not: per GDPR, data minimisation is necessary , but doesn't e…

I had realized, "l'esprit de l'escalier," that your ask wasn't in earnest and you were just looking to raise issues. Sorry to have bothered you, but I assure you that your Access or Deletion request will be processed when you submit it. I know that submitting an email in a form is so much different for you than sending an email (since you've characterized it as somehow acceptable). Are you suggesting that we should "…

I genuinely expected that you worked for some niche company I'd never heard of. I wasn't looking specifically to raise issues: this is how I engage with this topic in earnest (example: https://meta.stackexchange.com/a/370343/308065). My persnickety behaviour has been appreciated by at least one Stack Exchange employee; and I assumed from https://www.datagrail.io/solutions/datagrail-vs-onetrust/ that your company would appreciate such criticism as well.

I did tell you that I was going to have a look, so I don't think my request was deceptive.

> I assure you that your Access or Deletion request will be processed when you submit it.

No no, I never assumed otherwise! (the complaint about pseudonymisation notwithstanding.) And it's entirely reasonable that those require submitting a form.

My complaint was that, as a visitor to the company's website, my personal information is shipped off to third-parties and used in ways that I am not informed about, and I have to specifically request to be informed via email (or the form) despite having no business relationship with the company, when I'm entitled to be informed before any such data collection takes place. "Contact us, and we'll tell you all about how all your personal information is used" is a wonderful service to provide, but it really really shouldn't be the only way to find that information out.

(Technically, my complaint was more general than this, but it did not extend to expecting the company to magically know when I want the data indexed as associated with me deleted, without me informing them.)

> I know that submitting an email in a form is so much different for you than sending an email (since you've characterized it as somehow acceptable).

The difference is that the form requires that I provide my "First Name" and "Last Name", when these are not relevant to the request. GDPR requires that you don't require this, and an emailed request likewise does not require this. (When I told Stack Exchange about their instance of this issue, they thanked me for pointing it out, and then they fixed it, very promptly. They're using OneTrust, so assuming DataGrail is feature-complete with respect to OneTrust, and that DataGrail are using their own software, it shouldn't be hard for DataGrail to fix it too.)

> Had you communicated your consent preferences through GPC or DNT, all those scripts that you call out would have been blocked.

I noticed, and that's appreciated! However, that's not relevant to GDPR, whose obligations apply regardless of whether GPC or DNT is sent. The use of these scripts must be opt-in (unless the rare exceptions apply where you can use a basis other than consent), otherwise you're not complying with GDPR.

Again, not saying the company's atypically bad. The issues I've raised are fairly common in the industry. If forced to pick one of these services, I might go with DataGrail, because the selection of services the company offers is (in my estimation) very good. (Most smaller providers do not offer anything like that, and most larger providers are much less trustworthy.) I would certainly choose DataGrail over OneTrust.

However, my programming ability is such that it'd be easier to roll my own than audit the services of a company who I have reason to believe will make mistakes. I don't have reason to believe that the mistake-making is limited to whoever maintains the company's website (probably the marketing department), because I'd expect responsible higher-ups to tell a non-compliant marketing department to cut it out. I'm sure this means little, except that I am not your company's target market – nor the target market of most of the B2B privacy-tech industry.

Re: Most websites don't need cookie consent banners

#85
post #72
post #71

Earlier quoted context omitted.

Most of the sites use dark patterns in the banners, from not presenting decline option to hiding and renaming it to be unrecognizable. For example I make an effort in always picking Decline All option if available and the practice shows that I click on Allow All in about 20-30% of all banners, because it was impossible to avoid. So I safely assume that general population clicks Allow All even more.

From what I understood—but I think it's been added more recently—declining all optional cookies must be as easy as accepting all cookies.

Exactly, it is defined in the GDPR law that declining should be as easy and accessible as accepting. So all of those companies with dark patterns are breaking the law.

Re: Most websites don't need cookie consent banners

#86

Earlier quoted context omitted.

> Disclaimer: I work on a consent product. Forgive me for immediately untrusting you on the matter because the reality distortion field must be strong. Cookie banners are an absolute crystal clear evil and there is absolutely no leeway for a different opinion here. (Tracking is also an undisputed evil) > Consent banners don't have to be awful, I promise. False. They absolutely have to be awful because that's the whol…

Why are you tracking when it's an undisputed evil? Reality distortion indeed. Is getting consent interruptive? yes. Is that worse than not getting consent? Also yes. Since you don't appear to want to give up the undisputed evil of tracking, then consent is what's left to you. You've made the same choice as everyone else. I'd encourage you to respect GPC and DNT, so the (roughly 20%, depending on audience) of users th…

> Why are you tracking when it's an undisputed evil?

Not that tracking. You know what I mean: tracking by ad networks and international corporations.

We are tracking events (users clicked on the button) in an anonymous fashion. We do not collect PII. We do not store IPs. We do not correlate behaviors with user ids. We simply track how many people clicked the button and on what page. This is hardly privacy invasive at all.

> Is getting consent interruptive? yes. Is that worse than not getting consent? Also yes.

I'm not entirely sure about the latter. First of all, I don't believe in the slightest that the site will respect my choice. Second, even if the site itself does, the ad network present on the site, definitely will track me no matter what.

In other words, consent banners are cargo cult, do not work in practice and are a net negative for the world.

> DNT

It was an obvious idea but didn't work, unfortunately due to the fact that ad network absolutely have to look down users' ass and they will not cease this practice.

> users that have it enabled can automatically opt out of your tracking

They can install adblock and wholesale opt out of all the bullshit, including insane cookie consent banners.

> Remember that in California you need

My business is not California or US based and thus I don't have to implement the vast variety of of cargo cult laws in existence.

Re: Most websites don't need cookie consent banners

#87
post #81

Earlier quoted context omitted.

A statement of fact in response to a thing I didn't say.

In fairness, I have worked for a company which did talk to a lawyer about this and ultimately we didn’t have a cookie banner nor a disclosure of the cookies used (cookies were minimal and without personal information, essentially site settings not even associated with accounts). So I didn’t misinterpret what you said, it’s just that I have seen consent and disclosure always hand in hand. It’s been years since I read…

> I have worked for a company which did talk to a lawyer about this

We have also retained lawyers in UK for the same matter and they could not come to an ultimate conclusion what constitutes tracking and what does not.

The whole matter is that brain damaged.

Re: Most websites don't need cookie consent banners

#88
post #83

Earlier quoted context omitted.

Disagreed. You can absolutely do all analytics, personalization and marketing in-house on your properties. You only need data sharing if you want to influence advertising on other properties or if you display others' ads on yours. Whether you want to do so is a different matter. This obviously requires (potentially custom) software and infrastructure, vs throwing in GTM and calling it a day. If there is no regulatory…

1st party behavior tracking still requires consent. And nearly every business needs third party integrations. I’m still waiting for someone to give me a working example (a real business )

You are confidently incorrect. Consent is not needed if you only track for your own business and do not send the data to other businesses. One of the big GDPR-compliant website analytics tools, matomo, even has a dedicated page on this topic: https://matomo.org/blog/2021/10/matomo-exempt-from-tracking-...

"Matomo has also been approved by the French Data Protection Authority (CNIL) as one of the select few web analytics tools that can be used to collect data without tracking consent."

more info: https://matomo.org/gdpr-analytics/

Re: Most websites don't need cookie consent banners

#89
post #88
post #83

Earlier quoted context omitted.

1st party behavior tracking still requires consent. And nearly every business needs third party integrations. I’m still waiting for someone to give me a working example (a real business )

You are confidently incorrect. Consent is not needed if you only track for your own business and do not send the data to other businesses. One of the big GDPR-compliant website analytics tools, matomo, even has a dedicated page on this topic: https://matomo.org/blog/2021/10/matomo-exempt-from-tracking-... "Matomo has also been approved by the French Data Protection Authority (CNIL) as one of the select few web analyt…

You linked the wrong page

Re: Most websites don't need cookie consent banners

#90
post #10

Earlier quoted context omitted.

I appreciate the list of reasons to cookies are useful. Despite having worked in technology for 25 years, I couldn't have articulated that list off the top of my head. I have never worked for a website that made money that way. I think that means not ALL websites need invasive tracking.

can you give examples of serious online businesses that are not doing those things? Here are the industries that I've worked in that all did behavioral tracking for the above applications * gaming * music industry * healthcare * social media * news * internet search * online retail

B2B SaaS
Post reply on HN