Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe. Yeah, you care about these little things.
It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.
> It is also definitely true that the regulations are largely written by people who do not understand the tech
I kind of switched side on this after the silicon valley made it clear that they are in the king making business, and the kings they want are of the fascistic and not benevolent kind. Also, a big aspect of the "tech culture" (beyond the silicon valley itself) has been about focussing on what could be done rather than whether it should, and this "restraint" must come from "outside the tech bubble".
I think GDPR is more good than bad, but the author's example of surveillance capitalism is easily repeated on most EU news sites. Visit bild.de and watch the network inspector light up like a christmas tree. Do you really feel your privacy is being respected?
The 996 partners banner is just the piss take that supposedly makes this legal.
Bild doesn’t have one bit of respect for their readers, it’s no too surprising.
What people are missing is that before GDPR the threat of sharing data with 3rd party wasn’t seen as serious by most of the population. GDPR establishes clear rights people have, and a framework for companies to work in this new space, which changed the assumptions people have regarding their own data and privacy, in a positive way. People now in the EU have an explicit concept of consent for the use of personal data. That’s a really big deal
This is where you should apply eng principles. If something adds complexity without solving a problem, start by removing the complexity rather than tweaking
It did nothing for ad tech crap yet, but it gives you many easily exercised rights to access and erase your data. An American company "OpenAI" has released a very useful human-EU bureaucrat-translation tool for drafting such requests.
I'd argue that it actually did one good thing regarding ad tech: I've seen many people - who generally aren't interested in privacy, or politics in general - being very surprised by the number of companies their data is being sold to.
For someone who isn't aware of the scale, seeing "we sell your data to >1000 companies" can be enough to build interest in advocating for privacy laws.
> Banner gets a lot of attention because of the never-ending annoyance it's causing. It's like being surprised that someone would care about something so small as a little rock in their shoe.
No one is surprised that anyone is annoyed by the banners. But it doesn’t make sense to be annoyed at the law¹ instead of the perpetrators. If someone is deliberately putting pebbles in your shoes you should get annoyed at the person doing it, not the pebble.
The GDPR doesn’t require websites to have those banners², nor do they require them to be annoying³. That’s a choice the websites make. Every time you are annoyed at the GDPR because of those banners, you have been manipulated by the website to be mad at the wrong thing.
Imagine restaurants are pissing in their soup. This has become so rampant that a law comes out saying that if you pee in soup, you must warn your customers and give them the option for a pee-free soup. Restaurant then start serving you soup but before letting you eat force you to unwrap hundreds of layers of cellophane. You get so mad at it, “I just want to eat my soup, I don’t care about the pee, what a stupid law”. You should instead be mad that they were pissing in your soup in the first place, and when you see a restaurant doing the cellophane shenanigan you should leave in search of another which doesn’t pee in your soup.
¹ Unless you are annoyed that it is too lenient and think there should’ve been no option at all and that data collection should’ve been outright forbidden, not given a “consent” option that is abused.
² You can choose to not disregard people’s privacy.
³ Quite the contrary, the law requires that rejection be as easy as acceptance.
If virtually all the websites operators make the same choice, then this is the result of GDPR. What's nonsensical is ignoring real-life results of regulation because it had some other intention. I don't live with its intention.
Meta, but what’s the point of engaging in a discussion forum and writing a comment only to back out of actually discussing the points you disagree with?
It's a social manoeuvre, the idea is basically like standing up and clapping to show support. For example, maybe someone wants to support/oppose a position but is genuinely not the sort of person who believes in making an argument. From that perspective a little public "I disagree and question your character" post is an obvious tactic. The idea isn't to make a point so there isn't normally much reason to respond.
The idea is to make people think about what they say, and maybe not declare themselves the winner in advance. Kinda like you do by declaring what my intentions were.
The purpose of GDPR was never data protection or privacy. It was designed to legitimise data trade and give corporations legal basis for selling and processing the data where before that it was a grey area. If you look at it through that lens, it will make sense.
Regulators are just a potemkin village thing to make it look like the law is serving ordinary person.
As a dual American-European (citizenship in both, lived in both) I celebrate the EU data privacy laws and lament the absolute lack of protection of data or privacy that prevails in the US. Because of US based websites the genealogical history of my extended family (to many degrees), my past US residence history, etc. are easily available online, while in the EU it is very difficult to obtain any information online whatsoever about me or my immediate family (based in the EU), where we live, or even what we do for a living.
Most of the websites that are bad (operationally) in the GDPR sense are based in the US or represent US based entities. It is primarily US based entities that engage in bad faith fake compliance.
All this reflects the complete deterioration of basic business ethics in the US that has been led by the piracy culture that dominates in the tech sector, where the mentality is to bend or break every rule as much as possible, suffer the fines as business cost, and so on.
Watching the US go from laughing at "silly EU bureaucrats making regulations" to "oh shit there's a national, privately owned AI surveillance network already" in two years is interesting.
Tobacco control advocates sometimes referred to a "scream test": the more vigorously the industry opposed a measure, the more likely that the measure was effective.
Yeah but don't tobacco control advocates want to kill the tobacco industry? We don't want to kill the tech industry - surely the tech industry's pain is widely felt sometimes.
They dont want to kill the industry, they want consumers to be informed of the risks and stakes. If that makes consumers not want to consume tobacco then tough luck but the tobacco industry cant be allowed to operate based on lies and misdirection
People are hating it untill goes abroad to the countries where no such regulations exists.
Like in Switzerland it's okay to charge double for the car insurance simply because you carry "unlucky" citizenship.
Or EU law about mandatory 14-day return policy for internet order. Ordered recently something in Switzerland and turns out it was a special sale where standard rules does not apply and items could not be returned.
Or mandatory USB-C charge socket. God bless EU regulations!
Especially Gruber is getting really tiresome. Almost devolving into a “look at them there fruity Yuropeeans with their healthcare and holidays”-level of tech commentary about any minor roadbump big-US-tech encounters in the EU.
I dunno, recently traveling through Europe I mentally “joined” the campaign by seeing the ridiculousness for myself.
I very much support their ideals and their people-centered mindset.
But in execution it’s that meme: US rocket lands in slow motion on reusable pad, Chinese rocket lands in slow motion on reusable pad, European hand in slow motion closes a water bottle cap that is permanently attached to the bottle and always hits you in the nose.
If you agree with that meme, you’ve fallen for the manipulative narrative of lobbyists¹. Bottle caps are a massive problem (as is plastic in general) on the environment (you know, the thing we all live in) and the regulation is already having an impact. There will be more regulating the uses of plastic. If you don’t know why the bottle caps are so problematic, you live a privileged life and are being shielded from the reality your fellow human beings have to endure (but will eventually feel the effects just the same).
We don’t fucking need rockets right now, what we need is to stop poisoning ourselves. True progress is not inventing new technology, it’s understanding how to properly use what we have and reject what is harmful.
¹ Which is not a dig on you; we’re all susceptible to be tricked by these massive corporations whose only goal is to extract value from us. I’m on your side.
I've had the bottle cap in my nose multiple times... nobody's tricking me into not liking it.
Yes: I have the privilege of living in a developed 21st century world where I don't need to deal with stuff like this. Proud of it.
I'm well past being told to eat my vegetables because children in Africa are starving.
The solution is to expand the pie for everybody, not to throw our arms up and return to living in caves in harmony with "nature". Technology and progress solve this.
Nobody's forcing you to buy products in plastic bottles. It would actually be better if you didn't. "Technology and progress" are so far producing mountains of trash and pollution that you're privileged to not have to see, unlike those children in Africa, and other impoverished places where your garbage washes up. You're proud of winning the lottery. Have some self-awareness.
No (what I’m fairly sure is being referred to is that) there are (very recent) significant additional barriers to trade between EU member states, which disproportionately impact small businesses.
I don't think so. The most natural reading of OP's post is that they are outside Europe. You wouldn't say "I can't imagine how much this affects small business in Europe" if you were yourself running a small business in Europe.
Ok, but their post talks about making a product in small volumes. It doesn't explicitly say that it's a small business, but together with the first person singular language, that's definitely the impression given.
There are many powerful actors in whose interests it is to spread FUD about the EU, and none of those entities have the average citizen’s best interests in mind.
Maybe it’s all a misinformation campaign… or maybe even people who live in, recognise and benefit from the good sides of the European experience, can also legitimately criticise bad aspects? It’s not binary - there are shades of grey.
Europeans were blowing each other up 80 years ago. Now we have complete freedom of movement and trade. You're missing the forest for the trees. The EU is the greatest achievement of our parents' generation.
As someone who, until recently, worked in a company heavily impacted by GDPR, it’s a good thing. It forced the mindset away from “just do whatever is easiest,” to considering how it affects where our customer’s data is stored.
Was it a PITA? Sometimes, yes.
Was it stressful having a conversation with Legal to determine whether we had a PII leak under the GDPR terms that would mean we had to reach out to customers? Definitely.
But you know what? That’s the cost of doing business. The outcome for EU citizens was that their data is in a better place than it otherwise would have been. And that’s a good thing.
Well, it's the cost of collecting data. A lot of businesses don't really need to collect data. It's only the cost of doing business if you are in the personal data business.
For example, a newspaper or a blog have absolutely no reason to produce a cookie banner.
Note that GDPR did not mandate the cookie banners we see everywhere today. Those are a form of malicious compliance. Their goal is not to conform to regulation but to undermine the regulation itself in the eyes of the public.
Even the EU's own government websites are polluted with the same cookie banners. Are they "maliciously compliant" with their own regulations? Are they trying to "undermine the regulation itself"?
I remember, during the german Heat Pump Saga (the Ampel government passing legislation that effectively outlawed installation of new oil and gas heaters and tried to move everyone to heat pumps), there was a minor subplot where journalists found out that the Green party themselves couldn't successfully install a heat pump in their headquarters.
So in the interest of legitimacy, the EU institutions should really fix that and remove the banners from their sites.
The cookie banners come from the earlier ePrivacy Directive, and while it was possible to comply by not storing cookies at all, if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
> if you want to store data on the user's browser you do need to get their consent, hence the cookie banner.
No - you need consent for storing cookies that are not “strictly necessary”. I can implement an offline app that stores data in cookies without consent. The current usage of the banner is overly litigious US focused simplification combined with malicious compliance.
in particular, if you store stuff in the browser, and don't send it to the server later (local storage or one of the other 1000 JS APIs), there is no reason to present a cookie banner.
So you’re saying if I log into HN, every intra-site link should be rendered with “?token=<secret>” and if I send a link to a friend it will let them be logged in as me?
No, because that would be ludicrous, cookies are obviously necessary for the concept of a “login” or even just a “session” to exist.
The ePrivacy directive basically defines it as 'any data your site gives to the user's terminal that the terminal then passes back to your site'. Request tokens in the URL would qualify, but notably storing something in localStorage with javascript that is never sent back would not.
For a programmer of some sort this may seem a meaningless exception, for a lawyer it is not.
I am not a lawyer, but I have had a few law classes and worked a bunch in the legal services branch. If I am asked legally speaking - is this cookie strictly necessary? I will ask is the cookie used only for the purposes of the service provided to the user and which the user expects to get.
If the cookie is used so that when the user logs in and goes to page two of the article they are reading they can read that article without having to log in again we can say it is needed for the service. If the cookie is used to provide recommendations for other articles by using their user history to compare with other user histories and what other users like to read it is not needed for the service. Although from the point of view of the company it sure might be nice to have.
If the cookie is used for your state management of the items you have placed in your basket so that you can go to buy those items it is needed, if the cookie is used to look up your past history and give you recommendations for other stuff to put in your basket, things you bought in the past why not buy some more of those, or how often you rated products you bought badly or anything not required for the current transaction you are doing to go smoothly it is not needed.
As a general rule lawyers and the courts are good at sorting this stuff out, but as edge cases get complicated so does code, and nobody wants to handle all that stuff themselves, so instead they pay for a company that develops cookie banners and everybody gets asked if they accept cookies or not.
You don't need explicit consent for functional cookies, e.g. a session cookie or to store what preferences the user has selected on your settings page. It is implicitly given by the user telling you to treat them a certain way. For that you just need a notice somewhere on the page that reads along the lines of "this website uses cookies". It can be an unobtrusive note in your footer.
You do need consent even for the necessary exemption in practice because of how that is defined; the user must have explicitly asked for the function that requires the cookie:
> strictly necessary in order for the provider of an information society service *explicitly requested* by the subscriber or user to provide the service.
But this the basis for the OK-only style of banner, to inform the user that certain functions require and will use cookies if they use those functions.
Dropping permanent cookies for any of this stuff is not strictly necessary; session cookies would be sufficient, so then to do anything convenient (e.g. persistent cart, Amazon-style) but not necessary you still need to request consent.
GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other.
Site builders argue to themselves that what the regular user would want to do -- e.g. close the site and browser, come back to it and expect the items in the cart are remembered (for some amount of time, e.g. a month, not forever) -- is something the GDPR (or ePR) would strictly prohibit. Neither prohibit this. You can use persistent cookies or local storage for maintaining the user's cart.
The reason they massively overstate what the regulations prohibit is because there are many things they want to do: user tracking and analytics, marketing engagement, etc., and know fine well the regulations prohibit that unless they get consent. So they pretend they can't possibly even do a basically functional site without getting consent, which is bollocks, so they don't feel so bad about imposing a consent banner on every visitor.
The same thing happened in the UK where businesses told customers lies that "Health & Safety made me do this" or "the EU made me do this"
The banner is not needed for the website to work, otherwise how would the "decline" button work? They can store cookies, otherwise how would they remember your choice? They can track a functional session just fine, full shopping cart and checkout if they want.
What they can't do, not without your opt-in consent, is track the fuck out of you. Non-functional tracking. Analytical tracking. Behavioural tracking. Tying that tracking to an identity. Selling the data about that identity's behaviour to advertisers, to data brokers, to whoever pays.
The banner gets in your face and loudly prefers you press "accept" because if you do -- $$$$ CA-CHING!!! $$$$ -- they now have your opt-in consent to sell visitor data.
It is. It’s also often not necessary at all. You can’t do things with people’s data without either getting consent or basically having a good reason to. I like the ICO pages (uk regulator) for explaining a lot of things like this.
If I’m shipping an item to someone I don’t have to ask them if I can keep their address for long enough to send them the item. I do need their permission to use that data to send them marketing though, or sell it on. If you have to legally keep records for X years that’s fine.
Keep only what you need, for the time you need to keep it, in an appropriately secure way.
Not only is it legal, it’s expected by the law. It specifically mentions that rejecting consent must be at least as easy as giving it. Websites just choose to make it hard to reject, going against the law.
You may have noticed many websites have begun to be better behaved in that regard, for which you can thank organisations like noyb (https://en.wikipedia.org/wiki/NOYB).
I’ve posted this before. I was working on a website where we used a single cookie for an auth token, and we logged absolutely _everything_ on the server side (we didn’t sell it FWIW). When it came to publishing the site, we went to legal for our parent company and filled in their form. One question was “do you use cookies”, to which we answered truthfully. That site has a cookie banner, and absolutely 0 mention of the piles of telemetry we gathered.
The ePrivacy directive is a waste of time, money, attention and resources and I wish we spent that effort on complying with GDPR instead which is much much better.
Cookie banners are made annoying on purpose. This has nothing to do with GDPR itself.
The entities forced to show them would rather not, and thus make it as annoying as possible for you. They then use this to weaken support for the GDPR.
The reasoning treats a correlated characteristic as a causal mechanism.
successful person → unusual trait
And infer:
unusual trait → success
The most popular example of this in tech (that never seems to die) is when people notice moments where Steve Jobs was an asshole, or he said no directly to customers, and infer they need to be more like this because it's the unusual trait they're missing and need to emulate.
FDR's hatred was a byproduct of his consequential actions. But consequential actions are not the only things that produce hatred. In fact, rather petty actions can cause someone to feel hatred.
If you use hatred as a proxy for importance, you are effectively saying: "All impactful people are hated, therefore all hated people are impactful." This is logically equivalent to saying "All dogs are animals, therefore all animals are dogs." The metric has zero predictive power because the set of "hated people" is vastly larger than the set of "impactful people."
Friction is also terrible metric for progress. I would argue privacy has actually gotten worse due to the banners because if you decide you're not going to sign in to do something like a Google search (so it's not tied to your account), then you're immediately punished with a nag box. So you actually decide you'd rather stay signed in so you don't get nagged. Even if you're in favour of using the government, you should be using friction as a counter-signal. For example, switching to the Euro, reduced friction. Standardising to USB-C, you could argue this reduces friction for consumers.
TFA talks exclusively about being hated by the right people. If you are only hated by the right people (yes, I made an adjustment there), it's probalby not because you are a jerk. Come on.
Steve Jobs was against the "status quo" of Windows users, hated by "the right people", people that wanted to keep the OS monopoly. So why are you against his management style, do you not want people to succeed? Do you see how the caveat actually does nothing? I steered away from it because "the right people" is highly subjective, especially in a political context.
He was an asshole who did rich person bullshit to park in handicap parking spaces without consequences, he was also hated by people who were not his competition.
I feel that this must be logical error related to ad hominem and fallacy of composition, instead of this is bad because bad people like it, this is good because bad people dislike it.
I don't quite understand GDPR though as it theoretically let's me remove my personal data from benign websites, but doesn't let me remove my data where I would really want it removed, e.g. (my personal nemesis) SCHUFA, CRIF, Boniversum - which are all private companies.
SCHUFA is especially bad. They gather some strange data, and then "based on statistical analysis" give you a rating that is completely disconnected from reality. It's borderline necessary to rent an apartment, but if you're a new expat, have 2 credit cards, NOT (!) paying a mortgage, or you like to move apartments often, or try buying something with installments and get rejected (...via SCHUFA check...), then you're in a shitlist without any recourse.
While you might hate them, you don’t want your data to be removed from their systems. If you’re having a hard time accessing credit with them, imagine what happens when you try to access credit as a ghost.
Right. The problem is, I do not need credit, but in Germany most landlords ask for this SCHUFA report to consider a rental application. They get 100s of applications (there is housing shortage), so not having any report is not working. And if you are a new expat without a permanent address, or you didn't know and tried to check how much something would be with installments (which triggers the application procedure and the rejection - all in one click often), or you just didn't like your first apartment and moved, or you didn't like your first bank, didn't close your credit card, and opened another bank with another credit card - your score is going to go down the drain. Thankfully now at least they have a report on "why" you have a low score. Before Sep 2025 it was just "low" and no explanation. You can check here https://www.schufa.de/en/scoring-data/new-score/index.jsp
Given the relatively recent European experience (Nazis and Communists, among others) there is a reasonable argument for data privacy even if it hampers economic growth. However...
> If the rules are so terrible, why did nobody choose market exit?
Because major players don't particularly mind such rules; the public doesn't care about their data all that much and everything will tick on as usual with some nag banners and compliance officers.
The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started. There is a reason the EU is backseat driving US software companies - EU industrial policy killed off the EU ones in the crib (to be fair that wasn't the GDPR, the GDPR is just part of the same anti-growth regulatory pattern). They died so young we've never really even learned what their names would have been.
EDIT I'll point at companies like Uber. It looked pretty illegal for most of its early years, until it could afford enough lobbyists to legalise its business model. Never would have worked in the EU.
>The problem is the major players aren't going to be European because it is no longer legal for EU companies to get started by doing what the US companies did to get started
essentially finding ways around the law and its spirit to screw people over and degrade the quality of life for the citizens to one's own benefit. Your edit pointing to Uber never working is pretty much making the case here.
GDPR itself is quite a good law. It's implementation and enforcement are not.
E.g. the nag problem would have been solved simply and effectively with something like do-not-track header (probably as OS setting, as apps are often even worse than websites with tracking). Also enforcement of obvious violations taking years and years, especially against large corporations, means it's just violated all the time.
EU also failed to give good interpretation guidelines early on, causing massive piles of overjealous lawyer CYA red tape and just silly stuff like removing names from apartment buzzers.
The do-not-track header is a nice idea but could never have worked. The GDPR is based on the idea that you can only store certain data about users if you have their consent to do so. Bearing in mind that most users have no idea what a header is and no idea how to configure their browsers, a user simply not sending a particular header does not imply consent to store information beyond that which is absolutely necessary for use of the site.
I take your point. It would be nice to have a header that effectively just automatically canceled all the consent pop ups for you. But there are still some issues.
1) You'd have to find a way of writing the regulations without baking in particular technical assumptions about the web. The current GDPR talks about general principles of consent and data processing, not the specifics of cookies, headers, etc.
2) People can change their minds or override their general preferences in specific instances. Just because someone has a default setting in their browser indicating that they don't want to accept tracking cookies doesn't necessarily mean that they won't want to allow your site to store more data about them. So it is still legitimate for sites to ask them the question – and then you're back to the pop ups.
1) is not a problem. This is actually already defined technology neutrally in GDPR: "the data subject may exercise his or her right to object by automated means using technical specifications". For specific implementations the law can defer to e.g. standards, as is also very common in legislation.
In general defining laws technology neutrally is bread and butter of legislation, there are just a lot of misconceptions that laws are about specific techniques.
2) you can easily make a non-intrusive UI for that.
Yes, you can make a non-intrusive UI for that. Indeed, website creators can do that right now, with existing technology and compliant with the GDPR as-is.
The question is how do you prevent the annoying UX without making overly technology-specific rules. Just adding a do-not-track header does not stop websites from ignoring the header and showing a pop up to ask you if you want to override your default settings.
I worked in a small startup in Berlin and I remember we used to have a person dedicated to handle GDPR stuff. She had to go to Berlin data authority periodically and report status. I was really surprised given how small the company was, why we needed a dedicated person to handle all the bureaucracy. Apparently it was the law.
Also with the new package law in EU. I believe all these laws are how EU creates employment for their citizens. With almost every law they introduce, another new position is created in private as well as government offices and in a slowly aging continent that’s a good way to keep people employed when there isn’t much of a prospect
I think there will be more small businesses that would be created to handle all the package regulations and they will provide it as a service to all those businesses. I agree that it’s another unnecessary layer of bureaucracy, but maybe that was the intention of the lawmakers
If someone hates something doesnt mean that the other thing is good, thats a bizarre assumption. Im all for GDPR but has it helped stopped our data truly getting out? No just look at social media companies using subversive tactics.
At a previous job, I didn't have a company phone when I got set up, so when I signed up for a tool we all used, I used my real phone number. Unfortunately it was an American company, and from that day FOR YEARS I got spam calls, which I never got before.
I can't prove it was them, but it feels like I got too naive because there was never trouble giving my real number to services...
GDPR is good for corporations because it legitimises data trade. Population trained to agree to cookies now also agree to data processing just to get the banner go away and corporations have legal basis to process and sell the data.
It is all working as intended.
The tell tale is bodies like ICO being powerless when it comes to enforcing it. You've been screwed by big corporation? ICO will shrug.
I hate the banners and the ugliness too but they are designed precisely to do that, and adtech maneuvers to ensure the hate is directed at the wrong source - the lawmakers instead of the people doing all the spying.
GDPR 1.1 should address all that - no legitimate interest exclusion of any kind, ONE SINGLE CLICK to reject all, no witholding service at ANY degree unless consent is granted, a 3rd option (I offer to pay to not be tracked), and a mandatory disclaimer on the cookie banner saying in clear terms: "Tracking is spying. If we were not tracking you and invading your privacy, this banner would not be necessary at all". Maybe even revive the "do not track" header by mandating that websites react to it accordingly, obey it 100%, not even show a banner if the header already tells them what to do, and ask users if they want this set or not, without a default value which would give an excuse for complaint from the people spying on you.
I also read the post, and have handled multiple GPDR adjacent migrations in Asia.
The end result is still the same, even with GDPR 1.1, another interstitial barrier between the user and whatever site they are trying to reach imposed by a poorly planned attempt to protect user privacy while simultaneously enabling the predatory companies who violate said privacy to continue business as usual.
The cookie banner will remain on the vast majority of sites, and users will spam click past it as they have been trained to do.
Treating the browser's "disable cookies" feature as a way to reject consent is not real consent. That cripples many legitimate use cases outright; it's neither accessible nor understandable by normal users; it's a technical defence measure, not a way to consciously reject contractual consent.
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
I tried to use it, but it didn't remember the "no" answer. Every time I loaded a page, the same confirmation for the same cookie was presented again and again.
Yeah, but that's still way too narrow to capture what the law is about. The GDPR doesn't really care about cookies, or storing data on clients in some way. Instead, it's about end-users giving informed consent to processing their data. Not just by hand-waving away some disclaimer, but actually conscious of the consequences of that action, and why it is necessary to do so.
I know this sounds all lofty and Brussels ivory-tower-ish, but I'm absolutely convinced it's the only sensible way to deal with personal information - even if American companies insist on forcing a new normal of lacking privacy on all of us.
Yeah, I was more talking about ePrivacy cookie banners, which really are about storing data on user devices. The whole thing exists because the already implemented technical solution was deemed inadequate.
US companies like Meta or Google __LOVE__ GDPR. It is quagmire of complicated rules, and small startups will get burried under this quick sand. Large corporations can maintain departments of lawyers, and navigate this legal minefield. Small fines are cost of doing business, bribe that goverment would not force monopolies to spkit!
Try to do marketing ad campaign as small eshop owner in EU!
I'm responsible for GDPR in a small European company that processes fairly sensitive data. It's not that complicated as people like you make it out to be - if you're willing to actually try to do the right thing.
You don’t need to hire such a person since you’re way too small for the thresholds. And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?
You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.
We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.
If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .
> You don’t need to hire such a person since you’re way too small for the thresholds
> You also have to keep up with other regulations; that’s the price of doing business
Which one is it then? As small business I am suppose to follow all that ethical regulation bs, the same way as large company, without hiring extra peolle? But I should do it unpaid, in my free time (sleep less, or quit day job)?
Keep on mind I get lower salary than garbage man!
> they absolutely value if you’ve tried your
I do not "store data",. I have a free gmail account, I do not have a "data retention policy". But by GDPR i have to follow the same rules a s facebook!
> they absolutely value if you’ve tried your best....
My absolute best is to check once every a few years. That is not going to fly with goverment!
The only real help I got in past 5 years was AI! It can explain new changes, and audit my workflow, without paying 100x my salary to some consultant!
You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality here, right? Or do you consider filing your taxes as unpaid regulatory bullshit work too?
> Keep on mind I get lower salary than garbage man!
It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite, but if you don’t have a reasonably good income from your company, why do you put up with all the hassle in the first place..?
> I do not "store data",.
Sure you do, if you sell anything. You need to know where to ship stuff, customers contact you, pay you, all that. And as your customer, I don’t want you to store that longer than necessary or sell it to someone else.
There is no compliance officer required by law, at least not in any regulation introduced by the EU.
> The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!
If you have more than 250 employees, you really should have both a higher salary than a garbage man and be able to afford someone to take care of your compliance duties.
> You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?
I don't expect anything. You run a business. Anything you do related to that business is your own working time, just as anything I do in regard to compliance or data protection is of course billed working time. You file your taxes in your working time, you pay your bills in your working time, and of course you also read up on laws you need to comply to in your working time. Those are table stakes for doing business everywhere. Do you think American companies don't have to comply to regulations?
> Because I have social responsibility to make some rare stuff available, as you would put it!
All props to you for making that choice, then, but it's still your decision to have a company and that means you have to abide the law.
> But EU is not making it any easier!
The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of, because you never cared to look.
Just because you have a responsibility to think about and extra work to enable handling data your customers entrust you with carefully doesn't invalidate all of these efforts.
> So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!
You should try to think about protecting the personal data you handle responsibly and be ready to demonstrate that when somebody asks. Again, I am in the same spot and have been for years. This is doable.
> And besides, if you’re unable to accept that you have a social responsibility when you run a business, I don’t know what to tell you?
You were very clear as a business owner i have tons of extra responsibilities. I should go extra mile to "demonstrate". I am single guy, with a few houndred euro a month (lower salary than garbage man), and I have the same obligations as company of 249 people!
> There is no compliance officer required by law
> and be ready to demonstrate that when
> they absolutely value if you’ve tried your best as opposed to not caring at all;
Again, most companies hire an office to "demonstrate best efford" and to offload personal responsibility from company owner. This still applies to one person business!
> The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of
Are you even in EU my friend? I was unable to sell into germany becauee of some local BS. Every country has their own taxes, localization and regulations, there is no single market! EU has several currencies! EU does not protect from foreign traders, it pushes contaminated chicken from outside EU that contains salmonela!
Public infrastructure, education and art is responsibility of national goverment, EU sponsors maybe 2% of that!
> just as anything I do in regard to compliance or data protection is of course billed working time
Here is the core problem! You are not eshop owner! You are consultant who directly benefits from more regulations!!!
Of course you will push for more regulations and more "social responsibility"!
Luckily normal people can replace consultants with AI!
Part of running a profitable business is doing the right thing. Following socially obligated rules is a cost just like buying drywall.
The profits at all cost mentality is a criminal mentality. Maybe it gets away with not being formally criminal because laws or enforcement are weak (as is the case in the USA) but that doesn't justify the mentality.
> Part of running a profitable business is doing the right thing. Following socially obligated rules is a cost
Exactly! But there is a fixed cost of doing a right think! It is much easier for facebook to do the "right think", than some single guy with no employees!
> just like buying drywall.
I do not have a dry wall. Houses in EU usually do not have a dry wall.
> GDPR is easy to implement once, but it is constantly changing every year.
No it’s not. If you’re running an online store, compliance is pretty straightforward. Most of the PII you collect has a good reason: payment, fulfilment, fraud prevention, etc. so you don’t need consent for that.
If you’re collecting marketing data, you need to ensure it’s clear that you’re using it for that and keep your records accurate if you’re informed they changed.
For store analytics, your cookie banner covers you, the major players all integrate into standard tools, and they keep their compliance up to date, so you’re fine there.
Small mistakes are very much not punished. Your country’s Data Commissioner equivalent will want to see you try to be compliant first. You’re only going to get put out of business on a first offence if you’re taking the piss. I guarantee any example you provide me as evidence will be exactly that, but feel free to try.
By “major player” I meant the analytics companies that you pay, not you.
> Yet more extra work!
If “customer asks me to update my records on them, so I do it,” is too much work then you really shouldn’t be in the business that requires it.
> Sounds like work for extra GDPR officer!
Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”
Seriously, all your answers here tell me you’re trying to do some shady shit and not even making money from it. If you were a simple retailer, as your original post implied, you would not be worried about the complexity of handling GDPR.
just because I have small profits, does not mean i sell drugs! (But drug dealer would probably get better deal from police for breaking GDPR). I am worried about several thousands euro fines!
I have my own eshop, i do not use "major player"! Too expensive.
> Or you just ask “what do I need to do?” The official tells you, you do it, they say “thank you.”
And than you get different offical, with different opinion. Their advice have same weight as weather forecast!
You said "shady shit"! Deleting some data a few days/weeks or months latter too late is not "shady shit"!
You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides!
Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects. And small eshops are easy targets for fines. Large corporations are untouchable.
Look, I don’t think English is your first language, so I’m trying to give you the benefit of the doubt but it’s getting really tiring having to explain basic things like “context” to you. I’m obviously meaning in the context of data governance. I’m accusing you of selling customer data to unscrupulous characters, to be precise.
> You obviously have no idea how business here works! Some gov offical will tell you to delete data for GDPR. Some other gov offical will ask for the same data latter, to prove tax records or people complied with vacine mandates! You get fined from both sides!
Either you’re bullshitting me or you live in Eastern Europe and need to give kickbacks to stay in business. If the latter, that’s not the GDPR’s fault. It’s the fault of your government for not being able to draft law.
> Every two years there is a big law reform of some area, while other areas with conflicting laws are still in effects.
That’s not the GDPR, that’s your country having a poor grasp of how to make law. It’s a different problem and I’d recommend either lobbying your local representative or just leave to a sane country which will let you do business.
If that were the case they'd have spend money on supporting GDPR rather than sending armies of lobbyists to Brussels in an attempt to prevent it, or attempting to turn the US president in an attack dog on their behalf.
This generic libertarian talking point "companies love regulations!" is routinely disproved by how companies behave. As the article points out, you know what is good by who hates it.
Microsoft also hated windows piracy and "fought" against it, later they admitted it helped their business.
As for "libertarian talking point", it is survivor bios. There are very little tech compenies left in EU. Heavy regulation burden is one of the reasons.
All EU companies that could hate GSPR are gone, and their would be owners are just random people on internet.
GDPR has one single goal - to allow aggregated presumably anonymous data markets. Period. Everything else surrounding it is diversion in a plain sight.
Cookie banners are already obsolete in the age of AI. Who is wasting time defending it? People don't even care to hate GDPR these days, it's an anacrhonistic regulation from a different era that some EUrocrats like to boast about
I do! It’s one of my favorite regulation ever. I find it very well researched and designed, in a world where it often feels we cannot change the status quo it’s really impressive that a community of countries as messy as the EU has been able to design, pass, and actually implemented such a complex and citizen-centered set of rules
Often complaints about it boil down to either not understanding what’s in it, or annoyances that would be solved if sites stopped doing all this shady stuff. “We value your data, our 1644 partners…” yeah you definitely have a value you assign to my data.
The point of the article is not that banners are good; it’s that they would not be needed at all if websites didn’t share all the possible data about their users with hundreds of vendors.
Fun fact: the OP blog doesn’t display a GPDR banner.
It is also definitely true that the regulations are largely written by people who do not understand the tech they're regulating and its potential. Again, not some weird controversial point.
With every next leak where my full name, PESEL (that's like SSN here in Poland), email, phone number become semi-public and... nothing happens, I am becoming more convinced that we are annoying ourselves for nothing. Just degrading our digital lives and generating tons of legal digital text no one reads for no benefit of anyone involved.
At the same time, the very people who pretend to defend my privacy, oppose Tor, Signal, anonymity online, and other tools that definitely benefit me.
reply