Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

51% Positive

Analyzed from 3831 words in the discussion.

Trending Topics

#data#gdpr#consent#banner#cookie#business#cookies#small#need#companies

Discussion (96 Comments)Read Original on HackerNews

blfrabout 1 hour ago
Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things.

It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.

With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.

At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.

veeti27 minutes ago
I think GDPR is more good than bad, but the author's example of surveillance capitalism is easily repeated on most EU news sites. Visit bild.de and watch the network inspector light up like a christmas tree. Do you really feel your privacy is being respected?

The 996 partners banner is just the piss take that supposedly makes this legal.

ezstabout 1 hour ago
> It is also definitely true that the regulations are largely written by people who do not understand the tech

I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".

nonethewiser42 minutes ago
You know GDPR is bad based on what it is
contubernio9 minutes ago
As a dual American-European (citizenship in both, lived in both) I celebrate the EU data privacy laws and lament the absolute lack of protection of data or privacy that prevails in the US. Because of US based websites the genealogical history of my extended family (to many degrees), my past US residence history, etc. are easily available online, while in the EU it is very difficult to obtain any information online whatsoever about me or my immediate family (based in the EU), where we live, or even what we do for a living.

Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.

All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.

varispeed44 minutes ago
The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense.

Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.

Semaphor43 minutes ago
I disagree with several points, but you already made clear that you are right and I'm wrong, and so there's no point in debating anything. Must be nice to know everything
mft_39 minutes ago
Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?
roenxi21 minutes ago
It's a social manoeuvre, the idea is basically like standing up and clapping to show support. For example, maybe someone wants to support/oppose a position but is genuinely not the sort of person who believes in making an argument. From that perspective a little public "I disagree and question your character" post is an obvious tactic. The idea isn't to make a point so there isn't normally much reason to respond.
blainm30 minutes ago
The reasoning treats a correlated characteristic as a causal mechanism.

successful person → unusual trait And infer: unusual trait → success

The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.

FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.

If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."

Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.

ahartmetz20 minutes ago
TFA talks exclusively about being hated by the right people. If you are only hated by the right people (yes, I made an adjustment there), it's probalby not because you are a jerk. Come on.
sourcecodeplzabout 1 hour ago
there is a whole campaign online about hating on the EU & its regulations.
unsupp0rted36 minutes ago
I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself.

I very much support their ideals and their people-centered mindset.

But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.

leokennisabout 1 hour ago
Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
whatsThisBtn4about 1 hour ago
I made a physical product and upon learning European regulations, I quickly decided I was going to spend 0 time designing it for Europe.

If I made millions, sure, pay someone to figure it out.

But I was not going to waste design time early on.

I can't imagine how much this affects small business in Europe.

foldrabout 1 hour ago
These are just general barriers to international trade, though. Small manufacturers in Europe may likewise decide not to design for US regulations.
mft_33 minutes ago
No (what I’m fairly sure is being referred to is that) there are (very recent) significant additional barriers to trade between EU member states, which disproportionately impact small businesses.
seydor28 minutes ago
Are you sure about it?

In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.

https://www.facebook.com/ads/library/report/?source=onboardi...

Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious

Sharlinabout 1 hour ago
There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
mft_35 minutes ago
Maybe it’s all a misinformation campaign… or maybe even people who live in, recognise and benefit from the good sides of the European experience, can also legitimately criticise bad aspects? It’s not binary - there are shades of grey.
gman8331 minutes ago
I mean this isn't some hidden agenda. The Heritage Foundation has an active plan to dismantle the EU from within.
marcleabout 1 hour ago
Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
nonethewiser40 minutes ago
Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.
samrus8 minutes ago
They dont want to kill the industry, they want consumers to be informed of the risks and stakes. If that makes consumers not want to consume tobacco then tough luck but the tobacco industry cant be allowed to operate based on lies and misdirection

Same goes for data harvesting in tech

bsian14 minutes ago
"You know x is good based on who hates it" is too generic an argument to be useful. It applies to so many things.
scott_wabout 1 hour ago
As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.

Was it a PITA? Sometimes, yes.

Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.

But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.

nraynaud22 minutes ago
Well, it's the cost of collecting data. A lot of businesses don't really need to collect data. It's only the cost of doing business if you are in the personal data business.

For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.

sajithdilshanabout 1 hour ago
I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.

Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect

em-bee37 minutes ago
except the package law as it stands is going to force many small businesses to close because they can't afford the cost.
sajithdilshan28 minutes ago
I think there will be more small businesses that would be created to handle all the package regulations and they will provide it as a service to all those businesses. I agree that it’s another unnecessary layer of bureaucracy, but maybe that was the intention of the lawmakers
bryanrasmussenabout 1 hour ago
I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.

That said I am generally happy with GDPR.

nonethewiser38 minutes ago
It might have sounded clever but if you aren't concluding GDPR is good/bad based on what it is you are not reasonable.
stephantulabout 1 hour ago
Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.

The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.

Shame on the people making stuff like this.

ChrisSDabout 1 hour ago
Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
brainwadabout 1 hour ago
The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
maccardabout 1 hour ago
They do come from the ePrivacy directive but;

> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.

No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.

nraynaud19 minutes ago
in particular, if you store stuff in the browser, and don't send it to the server later (local storage or one of the other 1000 JS APIs), there is no reason to present a cookie banner.
brainwadabout 1 hour ago
No cookie is strictly necessary, you can encode it all into request tokens in the URL, so this is a meaningless exception.
snackbrokenabout 1 hour ago
You don't need explicit consent for functional cookies, e.g. a session cookie or to store what preferences the user has selected on your settings page. It is implicitly given by the user telling you to treat them a certain way. For that you just need a notice somewhere on the page that reads along the lines of "this website uses cookies". It can be an unobtrusive note in your footer.
brainwad34 minutes ago
You do need consent even for the necessary exemption in practice because of how that is defined; the user must have explicitly asked for the function that requires the cookie:

> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.

But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.

speedgooseabout 1 hour ago
No you don’t need a cookie banner or consent to store normal data in the user browser.

You do if you want to track your users. Very different thing.

amiga38638 minutes ago
The banner is not needed for the website to work, otherwise how would the "decline" button work? They can store cookies, otherwise how would they remember your choice? They can track a functional session just fine, full shopping cart and checkout if they want.

What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.

The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.

jampekkaabout 1 hour ago
The ePrivacy directive did/does not require the nag for "necessary cookies", i.e. most of the cookies that are serving the user's interests.
andaiabout 1 hour ago
So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal.

Because if it is, I also want to do it that way.

IanCalabout 1 hour ago
It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this.

If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.

Keep only what you need, for the time you need to keep it, in an appropriately secure way.

9devabout 1 hour ago
It was always possible to ask the user for permission when you actually want to store something on their device, ie. go for an opt-in model.
petcatabout 1 hour ago
Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?

https://european-union.europa.eu/

orwinabout 1 hour ago
Yes. Basically the shop they used to make their website are shit, with shit incentives.
maccardabout 1 hour ago
I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.

The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.

DarmokTanagraabout 1 hour ago
Everyone understands this, it doesn't matter.
jampekkaabout 1 hour ago
GDPR itself is quite a good law. It's implementation and enforcement are not.

E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.

EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.

foldr41 minutes ago
The do-not-track header is a nice idea but could never have worked. The GDPR is based on the idea that you can only store certain data about users if you have their consent to do so. Bearing in mind that most users have no idea what a header is and no idea how to configure their browsers, a user simply not sending a particular header does not imply consent to store information beyond that which is absolutely necessary for use of the site.
jampekka31 minutes ago
Lack of do-not-track header is not a consent to track of course. It's just signaling non-consent.
foldr25 minutes ago
I take your point. It would be nice to have a header that effectively just automatically canceled all the consent pop ups for you. But there are still some issues.

1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.

2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.

Advertisement
roenxiabout 1 hour ago
Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...

> If the rules are so terrible, why did nobody choose market exit?

Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.

The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.

EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.

bryanrasmussenabout 1 hour ago
>The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started

essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.

amriksohata40 minutes ago
If someone hates something doesnt mean that the other thing is good, thats a bizarre assumption. Im all for GDPR but has it helped stopped our data truly getting out? No just look at social media companies using subversive tactics.
Timon317 minutes ago
I have relevant personal experience here:

At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.

I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...

varispeedabout 1 hour ago
GDPR is good for corporations because it legitimises data trade. Population trained to agree to cookies now also agree to data processing just to get the banner go away and corporations have legal basis to process and sell the data.

It is all working as intended.

The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.

Razenganabout 1 hour ago
Same as with Apple's In App Purchases and low-friction refund process, that scummy companies like Match.com (the parent of Tinder etc) loudly opposed.
DarmokTanagraabout 1 hour ago
I hate the banners, and I am a major privacy advocate.

The web has gotten so much uglier as a result of GDPR.

Symbioteabout 1 hour ago
My employer's site has no banners, since we decided not to use any tracking.

We measure our success based on enquiries, orders and so on, not the number of hits to the website.

DarmokTanagraabout 1 hour ago
so you don't track your bounce rate or effectiveness of your advertising?
gruturoabout 1 hour ago
Shaka, when the walls fell.

I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.

GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.

DarmokTanagraabout 1 hour ago
I also read the post, and have handled multiple GPDR adjacent migrations in Asia.

The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.

The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.

intothemildabout 1 hour ago
The cookie banner isn't actually specified in gdpr, it was just how everyone else tried to build the solution to the problem at the last minute.

I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"

Nope

gmercabout 1 hour ago
It's a case of industry malicious compliance
sourcecodeplzabout 1 hour ago
i was thinking the same thing. it could be like an actual element of your page.
brainwadabout 1 hour ago
Browsers already had a way to consent to cookies, since the invention of cookies themselves. But the EU didn't consider that _real_ consent.
9devabout 1 hour ago
Treating the browser's "disable cookies" feature as a way to reject consent is not real consent. That cripples many legitimate use cases outright; it's neither accessible nor understandable by normal users; it's a technical defence measure, not a way to consciously reject contractual consent.

In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.

There is clearly a difference here, and IMHO the EU is quite correct here.

throw8484949iiabout 1 hour ago
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!

Try to do marketing ad campaign as small eshop owner in EU!

9devabout 1 hour ago
I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
throw8484949iiabout 1 hour ago
I am trying to run profitable business, not to "do the right think"! My shop had 5% profit margin and fimal net profit was bellow minimal salary! I do not have a money to hire "ethical compliance officer!"

GDPR is easy to implement once, but it is constantly changing every year. Keeping up with regulations is constant energy drain. And small mistakes are punished by heavy fines (thousands of EUR). If you compare fines Meta is getting by revenue, small business should get maybe 10 euro fine for violations (not thousands).

9dev11 minutes ago
You don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?

You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.

We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.

If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .

contubernio5 minutes ago
Part of running a profitable business is doing the right thing. Following socially obligated rules is a cost just like buying drywall.

The profits at all cost mentality is a criminal mentality. Maybe it gets away with not being formally criminal because laws or enforcement are weak (as is the case in the USA) but that doesn't justify the mentality.

scott_wabout 1 hour ago
As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
Barrin92about 1 hour ago
>US companies like Meta or Google __LOVE__ GDPR

If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.

This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.

throw8484949iiabout 1 hour ago
Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.

As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.

All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.

larodiabout 1 hour ago
GDPR has one single goal - to allow aggregated presumably anonymous data markets. Period. Everything else surrounding it is diversion in a plain sight.
9devabout 1 hour ago
Sure buddy. And it's all orchestrated by the Rothschilds, right?
seydorabout 1 hour ago
Cookie banners are already obsolete in the age of AI. Who is wasting time defending it? People don't even care to hate GDPR these days, it's an anacrhonistic regulation from a different era that some EUrocrats like to boast about
dgellowabout 1 hour ago
> Who is wasting time defending it?

I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules

IanCalabout 1 hour ago
Often complaints about it boil down to either not understanding what’s in it, or annoyances that would be solved if sites stopped doing all this shady stuff. “We value your data, our 1644 partners…” yeah you definitely have a value you assign to my data.
bgarbiakabout 1 hour ago
The point of the article is not that banners are good; it’s that they would not be needed at all if websites didn’t share all the possible data about their users with hundreds of vendors.

Fun fact: the OP blog doesn’t display a GPDR banner.

whatsThisBtn4about 1 hour ago
But did it do anything? I get fingerprinted anyway. I'm geolocated anyway.

I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".

Reminds me of 9/11 security theater