Hacker News new | ask | show | jobs
by _o_ 2939 days ago
Yes, you are right, the opt-out is violating GDPR (unless it is about changing mind after giving opt-in - this is again required and must be as easy as giving consent), you have to be preticked to "not giving consent" and user must actively click to give consent. Also you are missing explanation what giving consent means for the user including what data are used for what purpose.

Watch out with GDPR, this is not cookie law, and on top of it, you can't force it for user as a condition for entering site (like Forbes is doing - they will get a complain, already beeing finalized by some privacy organisation)