You Know GDPR Is Good Based on Who Hates It
Comments
blfr
ezst
> It is also definitely true that the regulations are largely written by people who do not understand the tech
I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".
veeti
I think GDPR is more good than bad, but the author's example of surveillance capitalism is easily repeated on most EU news sites. Visit bild.de and watch the network inspector light up like a christmas tree. Do you really feel your privacy is being respected?
The 996 partners banner is just the piss take that supposedly makes this legal.
dgellow
Bild doesn’t have one bit of respect for their readers, it’s no too surprising.
What people are missing is that before GDPR the threat of sharing data with 3rd party wasn’t seen as serious by most of the population. GDPR establishes clear rights people have, and a framework for companies to work in this new space, which changed the assumptions people have regarding their own data and privacy, in a positive way. People now in the EU have an explicit concept of consent for the use of personal data. That’s a really big deal
bko
So why is it good if it does nothing?
This is where you should apply eng principles. If something adds complexity without solving a problem, start by removing the complexity rather than tweaking
veeti
It did nothing for ad tech crap yet, but it gives you many easily exercised rights to access and erase your data. An American company "OpenAI" has released a very useful human-EU bureaucrat-translation tool for drafting such requests.
Timon3
I'd argue that it actually did one good thing regarding ad tech: I've seen many people - who generally aren't interested in privacy, or politics in general - being very surprised by the number of companies their data is being sold to.
For someone who isn't aware of the scale, seeing "we sell your data to >1000 companies" can be enough to build interest in advocating for privacy laws.
latexr
> Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe.
No one is surprised that anyone is annoyed by the banners. But it doesn’t make sense to be annoyed at the law¹ instead of the perpetrators. If someone is deliberately putting pebbles in your shoes you should get annoyed at the person doing it, not the pebble.
The GDPR doesn’t require websites to have those banners², nor do they require them to be annoying³. That’s a choice the websites make. Every time you are annoyed at the GDPR because of those banners, you have been manipulated by the website to be mad at the wrong thing.
Imagine restaurants are pissing in their soup. This has become so rampant that a law comes out saying that if you pee in soup, you must warn your customers and give them the option for a pee-free soup. Restaurant then start serving you soup but before letting you eat force you to unwrap hundreds of layers of cellophane. You get so mad at it, “I just want to eat my soup, I don’t care about the pee, what a stupid law”. You should instead be mad that they were pissing in your soup in the first place, and when you see a restaurant doing the cellophane shenanigan you should leave in search of another which doesn’t pee in your soup.
¹ Unless you are annoyed that it is too lenient and think there should’ve been no option at all and that data collection should’ve been outright forbidden, not given a “consent” option that is abused.
² You can choose to not disregard people’s privacy.
³ Quite the contrary, the law requires that rejection be as easy as acceptance.
jason_oster
Stop making sense! This is HN, for crying out loud.
blfr
If virtually all the websites operators make the same choice, then this is the result of GDPR. What's nonsensical is ignoring real-life results of regulation because it had some other intention. I don't live with its intention.
varispeed
The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense.
Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.
discreteevent
You're lying.
nonethewiser
You know GDPR is bad based on what it is
contubernio
As a dual American-European (citizenship in both, lived in both) I celebrate the EU data privacy laws and lament the absolute lack of protection of data or privacy that prevails in the US. Because of US based websites the genealogical history of my extended family (to many degrees), my past US residence history, etc. are easily available online, while in the EU it is very difficult to obtain any information online whatsoever about me or my immediate family (based in the EU), where we live, or even what we do for a living.
Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.
All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.
apexalpha
Watching the US go from laughing at "silly EU bureaucrats making regulations" to "oh shit there's a national, privately owned AI surveillance network already" in two years is interesting.
marcle
Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
nonethewiser
Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.
samrus
They dont want to kill the industry, they want consumers to be informed of the risks and stakes. If that makes consumers not want to consume tobacco then tough luck but the tobacco industry cant be allowed to operate based on lies and misdirection
Same goes for data harvesting in tech
yencabulator
Surveillance capitalism is not all of tech.
Surveillance capitalism might die or become unprofitable -- that sounds great.
sourcecodeplz
there is a whole campaign online about hating on the EU & its regulations.
ponector
People are hating it untill goes abroad to the countries where no such regulations exists.
Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship.
Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned.
Or mandatory USB-C charge socket. God bless EU regulations!
leokennis
Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
unsupp0rted
I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself.
I very much support their ideals and their people-centered mindset.
But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.
haizhung
Does the slowly landing rocket in any way improve live for ordinary people?
apexalpha
Yeah: https://nl.wikipedia.org/wiki/Starlink
Billions of people are getting access to information through it.
M95D
Good for them! We, europeans, already have fiber everywhere and unlimited 5G mobile internet for 2 euro/month.
latexr
> But in execution it’s that meme: (…)
If you agree with that meme, you’ve fallen for the manipulative narrative of lobbyists¹. Bottle caps are a massive problem (as is plastic in general) on the environment (you know, the thing we all live in) and the regulation is already having an impact. There will be more regulating the uses of plastic. If you don’t know why the bottle caps are so problematic, you live a privileged life and are being shielded from the reality your fellow human beings have to endure (but will eventually feel the effects just the same).
We don’t fucking need rockets right now, what we need is to stop poisoning ourselves. True progress is not inventing new technology, it’s understanding how to properly use what we have and reject what is harmful.
¹ Which is not a dig on you; we’re all susceptible to be tricked by these massive corporations whose only goal is to extract value from us. I’m on your side.
unsupp0rted
I've had the bottle cap in my nose multiple times... nobody's tricking me into not liking it.
Yes: I have the privilege of living in a developed 21st century world where I don't need to deal with stuff like this. Proud of it.
I'm well past being told to eat my vegetables because children in Africa are starving.
The solution is to expand the pie for everybody, not to throw our arms up and return to living in caves in harmony with "nature". Technology and progress solve this.
torlok
Nobody's forcing you to buy products in plastic bottles. It would actually be better if you didn't. "Technology and progress" are so far producing mountains of trash and pollution that you're privileged to not have to see, unlike those children in Africa, and other impoverished places where your garbage washes up. You're proud of winning the lottery. Have some self-awareness.
seba_dos1
> I've had the bottle cap in my nose multiple times...
Are you unfamiliar with the concept of rotating an object?
whatsThisBtn4
I made a physical product and upon learning European regulations, I quickly decided I was going to spend 0 time designing it for Europe.
If I made millions, sure, pay someone to figure it out.
But I was not going to waste design time early on.
I can't imagine how much this affects small business in Europe.
foldr
These are just general barriers to international trade, though. Small manufacturers in Europe may likewise decide not to design for US regulations.
mft_
No (what I’m fairly sure is being referred to is that) there are (very recent) significant additional barriers to trade between EU member states, which disproportionately impact small businesses.
foldr
I don't think so. The most natural reading of OP's post is that they are outside Europe. You wouldn't say "I can't imagine how much this affects small business in Europe" if you were yourself running a small business in Europe.
setsewerd
Unless you were in Europe and didn't run a small business
foldr
Ok, but their post talks about making a product in small volumes. It doesn't explicitly say that it's a small business, but together with the first person singular language, that's definitely the impression given.
Also, their other posts suggest they are in the US: https://news.ycombinator.com/item?id=49477186
seydor
Are you sure about it?
In fact,eu commission and parliament are Meta's biggest political spenders in most EU countries.
https://www.facebook.com/ads/library/report/?source=onboardi...
Personally i find this type of knee-jerk reaction to any discussion about the EU suspicious
Sharlin
There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
mft_
Maybe it’s all a misinformation campaign… or maybe even people who live in, recognise and benefit from the good sides of the European experience, can also legitimately criticise bad aspects? It’s not binary - there are shades of grey.
on_the_train
I'm a European citizen. I hate the EU.
torlok
Europeans were blowing each other up 80 years ago. Now we have complete freedom of movement and trade. You're missing the forest for the trees. The EU is the greatest achievement of our parents' generation.
gman83
I mean this isn't some hidden agenda. The Heritage Foundation has an active plan to dismantle the EU from within.
scott_w
As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.
Was it a PITA? Sometimes, yes.
Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.
But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.
nraynaud
Well, it's the cost of collecting data. A lot of businesses don't really need to collect data. It's only the cost of doing business if you are in the personal data business.
For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.
ChrisSD
Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
petcat
Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?
latexr
This again… I quote, with emphasis:
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
https://commission.europa.eu/resources/europa-web-guide/desi...
orwin
Yes. Basically the shop they used to make their website are shit, with shit incentives.
xg15
I remember, during the german Heat Pump Saga (the Ampel government passing legislation that effectively outlawed installation of new oil and gas heaters and tried to move everyone to heat pumps), there was a minor subplot where journalists found out that the Green party themselves couldn't successfully install a heat pump in their headquarters.
So in the interest of legitimacy, the EU institutions should really fix that and remove the banners from their sites.
brainwad
The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
maccard
They do come from the ePrivacy directive but;
> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
nraynaud
in particular, if you store stuff in the browser, and don't send it to the server later (local storage or one of the other 1000 JS APIs), there is no reason to present a cookie banner.
beej71
Do you have an example of a maliciously-complying website? Virtually all remotely popular websites deliberately use unnecessary cookies.
yencabulator
Wanting to use unnecessary cookies is their choice, not something a law forced on them.
Non-malicious compliance with privacy laws would mean respecting people's privacy.
brainwad
No cookie is strictly necessary, you can encode it all into request tokens in the URL, so this is a meaningless exception.
jampekka
The law is not about cookies specifically, it's technology neutral. The law doesn't even include the word cookie anywhere.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
ninkendo
So you’re saying if I log into HN, every intra-site link should be rendered with “?token=<secret>” and if I send a link to a friend it will let them be logged in as me?
No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.
rcxdude
The ePrivacy directive basically defines it as 'any data your site gives to the user's terminal that the terminal then passes back to your site'. Request tokens in the URL would qualify, but notably storing something in localStorage with javascript that is never sent back would not.
bryanrasmussen
let me guess: you're some sort of programmer?!
For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.
I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.
If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.
If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.
As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.
snackbroken
You don't need explicit consent for functional cookies, e.g. a session cookie or to store what preferences the user has selected on your settings page. It is implicitly given by the user telling you to treat them a certain way. For that you just need a notice somewhere on the page that reads along the lines of "this website uses cookies". It can be an unobtrusive note in your footer.
brainwad
You do need consent even for the necessary exemption in practice because of how that is defined; the user must have explicitly asked for the function that requires the cookie:
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
amiga386
If you're in a shopping site and "add to basket" -- explicity requested.
If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested.
If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested.
No consent needed.
On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed.
Javascript measuring which sub-parts of the page they lingered on -- consent needed.
Tracking how often they come back without buying anything -- consent needed.
Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED.
See the difference?
brainwad
Dropping permanent cookies for any of this stuff is not strictly necessary; session cookies would be sufficient, so then to do anything convenient (e.g. persistent cart, Amazon-style) but not necessary you still need to request consent.
GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.
amiga386
That sounds like a wheeze that I've heard before.
Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.
The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.
The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"
https://web.archive.org/web/20190627174442/http://www.hse.go...
https://web.archive.org/web/20200131200512/https://blogs.ec....
speedgoose
No you don’t need a cookie banner or consent to store normal data in the user browser.
You do if you want to track your users. Very different thing.
amiga386
The banner is not needed for the website to work, otherwise how would the "decline" button work? They can store cookies, otherwise how would they remember your choice? They can track a functional session just fine, full shopping cart and checkout if they want.
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
jampekka
The ePrivacy directive did/does not require the nag for "necessary cookies", i.e. most of the cookies that are serving the user's interests.
andai
So I've seen some companies do it in a way that's not a pain in the ass. I'm wondering if that's legal.
Because if it is, I also want to do it that way.
IanCal
It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
jampekka
I don't understand why this was downvoted. It's informative and factual.
latexr
Not only is it legal, it’s expected by the law. It specifically mentions that rejecting consent must be at least as easy as giving it. Websites just choose to make it hard to reject, going against the law.
You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB).
9dev
It was always possible to ask the user for permission when you actually want to store something on their device, ie. go for an opt-in model.
DarmokTanagra
Everyone understands this, it doesn't matter.
maccard
I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.
The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.
stephantul
Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.
The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.
Shame on the people making stuff like this.
bsian
"You know x is good based on who hates it" is too generic an argument to be useful. It applies to so many things.
summermusic
It’s more specific than that: “You know x is good based on if the worst people hate it” which I agree with the author is an extremely useful argument.
xboxnolifes
It does apply to many things. That doesn't make it a bad argument, it means its a very useful argument in many contexts.
blainm
The reasoning treats a correlated characteristic as a causal mechanism.
successful person → unusual trait And infer: unusual trait → success
The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.
FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.
If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."
Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.
ahartmetz
TFA talks exclusively about being hated by the right people. If you are only hated by the right people (yes, I made an adjustment there), it's probalby not because you are a jerk. Come on.
blainm
Steve Jobs was against the "status quo" of Windows users, hated by "the right people", people that wanted to keep the OS monopoly. So why are you against his management style, do you not want people to succeed? Do you see how the caveat actually does nothing? I steered away from it because "the right people" is highly subjective, especially in a political context.
yencabulator
Steve Jobs was not only hated by Microsoft.
He was an asshole who did rich person bullshit to park in handicap parking spaces without consequences, he was also hated by people who were not his competition.
em-bee
google naggs you exactly once.
grebc
Mandatory USB-C chargers & cookie dickovers. EU Progress at it’s finest.
bryanrasmussen
I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.
That said I am generally happy with GDPR.
nonethewiser
It might have sounded clever but if you aren't concluding GDPR is good/bad based on what it is you are not reasonable.
mstaoru
I don't quite understand GDPR though as it theoretically let's me remove my personal data from benign websites, but doesn't let me remove my data where I would really want it removed, e.g. (my personal nemesis) SCHUFA, CRIF, Boniversum - which are all private companies.
SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.
scott_w
While you might hate them, you don’t want your data to be removed from their systems. If you’re having a hard time accessing credit with them, imagine what happens when you try to access credit as a ghost.
mstaoru
Right. The problem is, I do not need credit, but in Germany most landlords ask for this SCHUFA report to consider a rental application. They get 100s of applications (there is housing shortage), so not having any report is not working. And if you are a new expat without a permanent address, or you didn't know and tried to check how much something would be with installments (which triggers the application procedure and the rejection - all in one click often), or you just didn't like your first apartment and moved, or you didn't like your first bank, didn't close your credit card, and opened another bank with another credit card - your score is going to go down the drain. Thankfully now at least they have a report on "why" you have a low score. Before Sep 2025 it was just "low" and no explanation. You can check here https://www.schufa.de/en/scoring-data/new-score/index.jsp
roenxi
Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...
> If the rules are so terrible, why did nobody choose market exit?
Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.
The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.
EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.
bryanrasmussen
>The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started
essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.
jampekka
GDPR itself is quite a good law. It's implementation and enforcement are not.
E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.
EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.
latexr
> the nag problem would have been solved simply and effectively with something like do-not-track header
You’ll be glad to know that the EU is working on a proposal to do just that. Look for EU Digital Omnibus article 88b.
You’ll also be unsurprised to know that companies like Google are already lobbying hard to prevent it.
foldr
The do-not-track header is a nice idea but could never have worked. The GDPR is based on the idea that you can only store certain data about users if you have their consent to do so. Bearing in mind that most users have no idea what a header is and no idea how to configure their browsers, a user simply not sending a particular header does not imply consent to store information beyond that which is absolutely necessary for use of the site.
jampekka
Lack of do-not-track header is not a consent to track of course. It's just signaling non-consent.
foldr
I take your point. It would be nice to have a header that effectively just automatically canceled all the consent pop ups for you. But there are still some issues.
1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.
2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.
jampekka
1) is not a problem. This is actually already defined technology neutrally in GDPR: "the data subject may exercise his or her right to object by automated means using technical specifications". For specific implementations the law can defer to e.g. standards, as is also very common in legislation.
In general defining laws technology neutrally is bread and butter of legislation, there are just a lot of misconceptions that laws are about specific techniques.
2) you can easily make a non-intrusive UI for that.
foldr
Yes, you can make a non-intrusive UI for that. Indeed, website creators can do that right now, with existing technology and compliant with the GDPR as-is.
The question is how do you prevent the annoying UX without making overly technology-specific rules. Just adding a do-not-track header does not stop websites from ignoring the header and showing a pop up to ask you if you want to override your default settings.
sajithdilshan
I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.
Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect
johneth
> She had to go to Berlin data authority periodically and report status.
That seems more of a German bureaucracy thing rather than GDPR specifically.
The UK, which does still implement GDPR from its time as a member state, does not require this level of officiousness.
em-bee
except the package law as it stands is going to force many small businesses to close because they can't afford the cost.
sajithdilshan
I think there will be more small businesses that would be created to handle all the package regulations and they will provide it as a service to all those businesses. I agree that it’s another unnecessary layer of bureaucracy, but maybe that was the intention of the lawmakers
amriksohata
If someone hates something doesnt mean that the other thing is good, thats a bizarre assumption. Im all for GDPR but has it helped stopped our data truly getting out? No just look at social media companies using subversive tactics.
Timon3
I have relevant personal experience here:
At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.
I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...
varispeed
GDPR is good for corporations because it legitimises data trade. Population trained to agree to cookies now also agree to data processing just to get the banner go away and corporations have legal basis to process and sell the data.
It is all working as intended.
The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.
Razengan
Same as with Apple's In App Purchases and low-friction refund process, that scummy companies like Match.com (the parent of Tinder etc) loudly opposed.
DarmokTanagra
I hate the banners, and I am a major privacy advocate.
The web has gotten so much uglier as a result of GDPR.
Symbiote
My employer's site has no banners, since we decided not to use any tracking.
We measure our success based on enquiries, orders and so on, not the number of hits to the website.
DarmokTanagra
so you don't track your bounce rate or effectiveness of your advertising?
gruturo
Shaka, when the walls fell.
I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.
GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.
DarmokTanagra
I also read the post, and have handled multiple GPDR adjacent migrations in Asia.
The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.
The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.
intothemild
The cookie banner isn't actually specified in gdpr, it was just how everyone else tried to build the solution to the problem at the last minute.
I remember thinking "ok once this hits an actual web spec, we should see this built into browsers, and sent as headers or something"
Nope
gmerc
It's a case of industry malicious compliance
sourcecodeplz
i was thinking the same thing. it could be like an actual element of your page.
brainwad
Browsers already had a way to consent to cookies, since the invention of cookies themselves. But the EU didn't consider that _real_ consent.
9dev
Treating the browser's "disable cookies" feature as a way to reject consent is not real consent. That cripples many legitimate use cases outright; it's neither accessible nor understandable by normal users; it's a technical defence measure, not a way to consciously reject contractual consent.
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
intothemild
Correct.. the gdpr isn't the anti cookie law. It's the data privacy law.
If it wasn't cookies it would be something else.
DarmokTanagra
Correct in principle, completely ineffectual and annoying in practice.
brainwad
Most browsers in the 00s had a "always ask" option for cookies. Nobody used it, because it's as annoying as gdpr dialogs now are. But it existed.
M95D
I tried to use it, but it didn't remember the "no" answer. Every time I loaded a page, the same confirmation for the same cookie was presented again and again.
9dev
Yeah, but that's still way too narrow to capture what the law is about. The GDPR doesn't really care about cookies, or storing data on clients in some way. Instead, it's about end-users giving informed consent to processing their data. Not just by hand-waving away some disclaimer, but actually conscious of the consequences of that action, and why it is necessary to do so.
I know this sounds all lofty and Brussels ivory-tower-ish, but I'm absolutely convinced it's the only sensible way to deal with personal information - even if American companies insist on forcing a new normal of lacking privacy on all of us.
brainwad
Yeah, I was more talking about ePrivacy cookie banners, which really are about storing data on user devices. The whole thing exists because the already implemented technical solution was deemed inadequate.
throw8484949ii
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!
Try to do marketing ad campaign as small eshop owner in EU!
scott_w
As someone who worked on GDPR compliance just last year, in a company that is deeply affected by it, no, it’s not that complicated.
9dev
I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
Barrin92
>US companies like Meta or Google __LOVE__ GDPR
If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.
This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
throw8484949ii
Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.
As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.
All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
larodi
GDPR has one single goal - to allow aggregated presumably anonymous data markets. Period. Everything else surrounding it is diversion in a plain sight.
9dev
Sure buddy. And it's all orchestrated by the Rothschilds, right?
seydor
Cookie banners are already obsolete in the age of AI. Who is wasting time defending it? People don't even care to hate GDPR these days, it's an anacrhonistic regulation from a different era that some EUrocrats like to boast about
dgellow
> Who is wasting time defending it?
I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules
IanCal
Often complaints about it boil down to either not understanding what’s in it, or annoyances that would be solved if sites stopped doing all this shady stuff. “We value your data, our 1644 partners…” yeah you definitely have a value you assign to my data.
bgarbiak
The point of the article is not that banners are good; it’s that they would not be needed at all if websites didn’t share all the possible data about their users with hundreds of vendors.
Fun fact: the OP blog doesn’t display a GPDR banner.
whatsThisBtn4
But did it do anything? I get fingerprinted anyway. I'm geolocated anyway.
I'm a "deny all cookies" if it's an option, but I won't waste time on "customize".
Reminds me of 9/11 security theater
Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things.
It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.