Skip to content

Comment on All software in EU under product liability from 2026

Comments

Who will be liable for "defective" directives and regulations? I would like to sue someone for all the wasted time and effort around cookie popups.

While I don't like cookie popups, I prefer them to the alternative - websites silently tracking me however they wish.

If the industry didn't want cookie popups, perhaps they should have respected the DNT header[1].

[1] https://en.wikipedia.org/wiki/Do_Not_Track

If you don't like cookies and don't want to be tracked, perhaps you should disable all cookies in your browser.

It's really simple, you'll get no more cookies ever. That tracking vector is totally disabled and you have full control over it. There's absolutely no need for a cookie banner for a person to be free of cookies.

https://support.mozilla.org/en-US/kb/block-websites-storing-...

Which isn't helping [0], cookies are just a more convenient shortcut for fingerprinting, and GDPR is not against cookies but tracking and profile building so prevents those too. The removal of cookies by the majority of people would bring up "Fingerprint banners"

[0] "Yes! You are unique among the 2926891 fingerprints in our entire dataset." https://amiunique.org/fingerprint

Ironic that this site, attempting to raise awareness about online privacy issues, has a cookie banner...

That site is truly scary...

Cookie pop-ups is a clear case of "malicious compliance" and I guess all spying companies hoped they could make it so annoying that citizens of EU would revolt or something.

Didn't work, instead many more people (at least here in EU) are now aware how how bad the spying has become.

It's easy: if you as a website owner transfer personally identifiable information to a third party and it's not strictly necessary to provide your service, then you need consent from the user.

If you would refrain sharing that info, you wouldn't need to ask for consent. There is no law that asks for cookie popups

Yes, e.g. there is no law for cookie popups, you can use cookies without consent if you use cookies say for session handling.

I would like more sites asking consent when passing info to a 3rd party becomes necessary (in relation to a requested service, like when you use location services in a phone app, for example) instead of asking for bulk consent for the whole site visit.

Even the EU's own official web portal [1] has a cookie pop-up that covers half the screen of my mobile phone when I visit it.

[1] https://europa.eu/

Probably built by a web gency who added tracking, perhaps even GA, so there was need for a cookie pop up banner. Why that website would need tracking and profiling is beyond me.

I think every website should understand how and by who their website is used. I don't consider this "spying." If you walk into a brick and mortar store the shopkeeper has every right to count that you came in, and watch where you go in the store to optimize it. The web should be no different.

Fortunately there are in fact cookieless analytics systems that people can use to get this information why not being required to have the stupid cookie popup.

"I think every website should understand how and by who their website is used"

1. You don't need cookies or profiling for that - use Simple Analytics et. al.

2. You can ask for my consent, but you can't profile me against my will

3. A brick and mortar store does not profile me without my consent.

Yes, a brick and mortar store can absolutely profile you without consent if they wished, and so can a website. The only condition is not collecting PII.

Difficult, they try from time to time, then they get fake email adresses and fake zip codes in their database.

(Not using loyalty cards or CCs)

FWIW I am a website/webapp owner and use zero third party cookies or services, not even first party tracking (apart from analyzing web server logs from time to time).

Still, the GDPR obviously had some "bugs" which let companies get away with basically showing you "we're tracking you, click OK". Which is a waste of time for the companies and users and doesn't improve users' privacy in any way. So, it was a faulty law that caused damages

Your first paragraph describes GDPR, which does not require cookie popups.

But there is also the e-privacy directive (older than GDPR) that does require a cookie popup for any cookie not strictly required to deliver the service. Regardless of whether it tracks PII. So this also applies if for example you only want to know whether someone is a returning visitor or a new visitor without storing any identifier.

The worst cookie pop-ups come from a Florida company, that is hell-bent on punishing the whole internet for not allowing them to invade privacy.

They not only do some shoddy attempt of malicious compliance, they don't even do it actually right, for example EU law says if you have an accept all button, you must have a reject all button, but they don't do that.

Also the law doesn't give an exception for "legitimate interest", yet when you open their menu to disable manually everything (that by the law, should be disabled by default, except cookies essential to keep the site working), they have a bunch of random tracking cookies enabled because it is "legitimate interest". I think the only reason they weren't sued out of existence yet, is because it is a US company, thus they don't have to actually follow EU laws or something. (or they act like that, at least, I am not a lawyer).

EDIT: linkedin link to the offending company: https://www.linkedin.com/company/getadmiral/

Is there a requirement in the EU laws that the popups need to be in a specific language? I've seen plenty of websites in the EU that uses a non-english language in the popup and there is no option to switch to another language to understand what you are agreeing to.

Websites don't have to show cookie popups, unless they want to track you, gather or sell data on you, etc. The issue here lies with the websites, not with the legislation.

There's no rule requiring cookie popups.

Sue the companies that design or use these anti-user cookie pop-ups.

People here love them but it's become the same as just about every ToS. No one reads them, you just bash whatever button lets you get to the page.

The EU essentially mandated popups.

It's the politicians, that's why vote them in and out every few years.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.