Remember when HN used to have somewhat informed users? The trite cookie popups have nothing to do with GDPR, this has been repeated ad nauseam...
Remember when HN used to have somewhat informed users? The trite cookie popups have nothing to do with GDPR, this has been repeated ad nauseam...
Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
https://gdpr.eu/cookies/
https://wp-gdpr.eu/gdpr-cookie-consent-2026/
https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...
> (i.e. popups, banners large enough to push users to interact with them, etc.).
"i.e." doing a lot of work there.
GDPR doesn't require pop-ups or banners for providing consent. It mentions "ticking a box when visiting an internet website" as an example implementation. But it's just there as an example.
https://gdpr.eu/Recital-32-Conditions-for-consent/
the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites. i've had to provide consent for things completely unrelated to websites.
you could add a line of text saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah" and this is perfectly in line with GDPR.
sure, it's more expensive and you'll get fewer people who you can track. but make no mistake, sites make a decision and choose pop-ups/banners as their implementation for gathering consent because they don't want to lose out. they're happy inflicting pop-ups/banners on their users instead so they can keep their precious tracking cookies going.
i.e. GDPR doesn't require pop-ups/banners, sites choose pop-ups/banners.
GDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface.
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
This being downvoted speaks saddens my heart... and proves the exact intent of the message.
It’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is
Is it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
When the city writes an ordinance saying chemical factories must have fire alarms I do not blame the city for the fire alarm noise.
I would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.
If the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.
I think we should make sure they're not allowed to do that, and actually enforce it.
So... Is your suggestion to ban tracking, marketing, analytics etc. non-essential cookies altogether?
That'd be nice, but we could stop short of that and just ban anything that seems coercive (which iiuc is already the case, it's just not enforced effectively).
I think so, and it's based.
> widely misunderstood
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
> I'm really trying not to assume the worst about you.
Well, you are. Maybe don't do that?
> a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
If you think I'm opposed to GRPR, you are mistaken.
Popups have nothing to do with GDPR. They are reaction to Privacy and Electronic Communications Directive which predates GDPR.
And yes, it is deliberate misinformation.
Cookie popups pre-date GRPR, but find it hard to believe the uptick in popups that happened around May 2018 was in response to legislation from 2003.
Cookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com".
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
This is heavily downvoted ... and still accurate.