I didn't think the cookie law is actually an intrinsic part of GDPR. But I could be wrong. I know you are supposed to make it clear that you are collecting data, and allow opt out.
So, I can see the political point in "setting fire to the cookie law" whilst basically being GDPR in all but name.
however, given the power of the present government to cock things up, I suspect they are going to make some stupid changes that threaten our equivalence with the EU. The EU will happily remove it, thus making it harder to trade in the EU.
I notice some murmuring about science. I suspect that means they'll try and make it simpler to wholesale sell off the fetid datamine that is NHS medical history. However if we are lucky, they'll also undermine the concept of informed consent for anything to do with research/data, which will be fun.
I didn't think the cookie law is actually an intrinsic part of GDPR
Because it is not. [1] It was part of the ePrivacy directive, it has been amended since. The TL;DR is: today, if you don't use cookies for tracking and/or ads, you're fine. Just put a cookie consent checkbox on the user login form, and your website will have a much nicer user experience.
If you show a cookies consent modal before your visitors can access anything, either:
* you have personalised ads with global tracking. (~= criteo, amazon ads, or google adsense)
* you're using a globalised analytic tool. (~= Google Analytics)
* you're following an outdated version of the ePrivacy/GDPR directives.
They say you don't need cookie consent for login form. Login form is an obvious authentication, opt-in even. You need cookie consent when you authenticate user stealthily - how Google Analytics does it.
I know you are supposed to make it clear that you are collecting data, and allow opt out.
Just to be clear, the GDPR requires opt-*in* for any data for which you do not have a legitimate interest - that you means you need consent before you start collecting.
As is well documented here, it's not intrinsic but it's the pragmatic outcome i.e. 'it's what is happening because GDPR and the state of the web'.
So it's one thing to point fingers and say 'the law doesn't require it' it's another to recognize that's where the equilibrium landed and that at least some kind of problem still exists.
I personally think there's actually a win-win and that we can have our cake and eat it as well, but these popups are a good indication that the laws as designed are not that.
Comments
I didn't think the cookie law is actually an intrinsic part of GDPR. But I could be wrong. I know you are supposed to make it clear that you are collecting data, and allow opt out.
So, I can see the political point in "setting fire to the cookie law" whilst basically being GDPR in all but name.
however, given the power of the present government to cock things up, I suspect they are going to make some stupid changes that threaten our equivalence with the EU. The EU will happily remove it, thus making it harder to trade in the EU.
I notice some murmuring about science. I suspect that means they'll try and make it simpler to wholesale sell off the fetid datamine that is NHS medical history. However if we are lucky, they'll also undermine the concept of informed consent for anything to do with research/data, which will be fun.
Because it is not. [1] It was part of the ePrivacy directive, it has been amended since. The TL;DR is: today, if you don't use cookies for tracking and/or ads, you're fine. Just put a cookie consent checkbox on the user login form, and your website will have a much nicer user experience.
If you show a cookies consent modal before your visitors can access anything, either:
* you have personalised ads with global tracking. (~= criteo, amazon ads, or google adsense)
* you're using a globalised analytic tool. (~= Google Analytics)
* you're following an outdated version of the ePrivacy/GDPR directives.
But it's easier to blame it on the EU.
[1] https://gdpr.eu/cookies/
They say you don't need cookie consent for login form. Login form is an obvious authentication, opt-in even. You need cookie consent when you authenticate user stealthily - how Google Analytics does it.
It isn't, the DCMS is being deliberately misleading to justify gutting UK privacy law.
Could you elaborate on why it is not?
Because it stems from an earlier law.
The one stems from the e-privacy directive which stems from 2002, the other is the GDPR.
https://en.wikipedia.org/wiki/EPrivacy_Regulation
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
https://edps.europa.eu/data-protection/data-protection/gloss...
https://gdpr-info.eu/
Just to be clear, the GDPR requires opt-*in* for any data for which you do not have a legitimate interest - that you means you need consent before you start collecting.
As is well documented here, it's not intrinsic but it's the pragmatic outcome i.e. 'it's what is happening because GDPR and the state of the web'.
So it's one thing to point fingers and say 'the law doesn't require it' it's another to recognize that's where the equilibrium landed and that at least some kind of problem still exists.
I personally think there's actually a win-win and that we can have our cake and eat it as well, but these popups are a good indication that the laws as designed are not that.