it's an example of malicious compliance by some, and herd mentality by others.

I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.

How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.

It's more like a cultural expectation that business do shady things and the "clown makeup" is a compromise that government found between making those shady things illegal (utopia) and don't intervene at all and let the corporations set their rules (dystopia).

It's like those warnings in cigarettes packages saying they will kill you. I know cigarettes are bad, but the warnings also make me believe there's at least "some" control in how bad they are. Now if I buy one without the warnings, I will worry those in particular are extra-shady and likely to kill me even faster.

The EU doesn't require banners.

Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX.

This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.

Banners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners.

This is misinformed.

As many have said before:

  it's basically malicious compliance. They're supposed to be super annoying ... Instead of complying, they choose this obnoxious practice so they could continue ... monitoring every action a visitor does.

  You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking. [1]

  Regulators didn't enforce cookie banners. Cookie banners are a form of malicious compliance. When you complain about them, you are doing the lobbying work of ad companies for free. The correct solution is to just not spy on people, and the problem is that the EU didn't go far enough and just ban the behavior altogether. [2]

  Cookie pops are malicious compliance to regulations that legitimately protect consumers. You’ve cherry picked one bad side effect to throw out all the ways the EU is way ahead of anyone else in protecting consumers [3]
[1] https://news.ycombinator.com/item?id=29529148

[2] https://news.ycombinator.com/item?id=38299135

[3] https://news.ycombinator.com/item?id=46552795

The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources.

The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.

I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.

You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.

That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).

When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.

Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.

But then you can't have tracking cookies.

You may float an idea to describe what you've just said in the banner, and have just a "close" button.

E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".

No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.

The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.

[deleted]

They're not covering their ass, they're making a deliberate tradeoff.

It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen.

And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one.

Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site.

Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time."

Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.

Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.

This website contains chemicals known to the State of California to cause cookies.

The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.

But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong?

Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.

I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.

I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.

In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.

> and he said "yeah, but it makes the site seem less legitimate.

He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.

Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.

I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.

Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.

Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.

So when someone says "you can't do that", sometimes you should make them prove it.

(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)

I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.

I did not anticipate where that sentence ended up :-).

Reminds me of the early days of the CANSPAM act.

One of the best indicators that something was not spam was the unsubscribe button.

> but it makes the site seem less legitimate

I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?

Not customers. Owners.

Although if you've ever worked retail, you'll know that plenty of customers are idiots.

Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.

>it's an example of malicious compliance

So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?

Don’t use a bunch of unnecessary tracking cookies?

Completely eliminates the need for a cookie permission bar.

The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)

Okay, but it doesn’t require notification for every user that hits your landing page.

If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.

Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.

No, it doesn't. If it's reasonably expected as part of the service, you don't need to gather consent. It's not even personal data.

The law does not say 'reasonably expected', it says 'strictly necessary'.

Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner.

What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API and the javascript on your page never puts that information into a request), like how this would normally be implemented nowadays, then these requirements don't apply at all (because a cookie according to the law is just something your server gives to the user's device and then the device gives back later).

OK, so don't do that. Web sites work fine without remembering anonymous users' preferences across sessions.

Nonsense.

You are correct that people keep stating such things. But it is incorrect.

That example would be an essential cookie, also known as a strictly necessary cookie.

A shame this FUD is still being spread.

That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk significant fines to trust it?

I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce.

Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.

At least for GDPR...

The only ways to actually track without a consent pop-up are:

(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or

(2) confine any device storage to what's strictly necessary for the service the user requested

This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.

you don’t need to track users by giving them an ID they send with every request.

in fact. you probably don’t need to track users.

tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much?

I don't exactly see how these two statements are contradictory. Policy is about conflicting interests.

Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.

CFO should be fired immediately.