Skip to content

Comment on UK to overhaul privacy rules in post-Brexit departure from GDPR

Comments

I didn't think the cookie law is actually an intrinsic part of GDPR. But I could be wrong. I know you are supposed to make it clear that you are collecting data, and allow opt out.

So, I can see the political point in "setting fire to the cookie law" whilst basically being GDPR in all but name.

however, given the power of the present government to cock things up, I suspect they are going to make some stupid changes that threaten our equivalence with the EU. The EU will happily remove it, thus making it harder to trade in the EU.

I notice some murmuring about science. I suspect that means they'll try and make it simpler to wholesale sell off the fetid datamine that is NHS medical history. However if we are lucky, they'll also undermine the concept of informed consent for anything to do with research/data, which will be fun.

I didn't think the cookie law is actually an intrinsic part of GDPR

Because it is not. [1] It was part of the ePrivacy directive, it has been amended since. The TL;DR is: today, if you don't use cookies for tracking and/or ads, you're fine. Just put a cookie consent checkbox on the user login form, and your website will have a much nicer user experience.

If you show a cookies consent modal before your visitors can access anything, either:

* you have personalised ads with global tracking. (~= criteo, amazon ads, or google adsense)

* you're using a globalised analytic tool. (~= Google Analytics)

* you're following an outdated version of the ePrivacy/GDPR directives.

But it's easier to blame it on the EU.

[1] https://gdpr.eu/cookies/

They say you don't need cookie consent for login form. Login form is an obvious authentication, opt-in even. You need cookie consent when you authenticate user stealthily - how Google Analytics does it.

I didn't think the cookie law is actually an intrinsic part of GDPR

It isn't, the DCMS is being deliberately misleading to justify gutting UK privacy law.

Could you elaborate on why it is not?

I know you are supposed to make it clear that you are collecting data, and allow opt out.

Just to be clear, the GDPR requires opt-*in* for any data for which you do not have a legitimate interest - that you means you need consent before you start collecting.

As is well documented here, it's not intrinsic but it's the pragmatic outcome i.e. 'it's what is happening because GDPR and the state of the web'.

So it's one thing to point fingers and say 'the law doesn't require it' it's another to recognize that's where the equilibrium landed and that at least some kind of problem still exists.

I personally think there's actually a win-win and that we can have our cake and eat it as well, but these popups are a good indication that the laws as designed are not that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.