Hacker News new | ask | show | jobs
by caffeine5150 2930 days ago
There is much confusion. Cookies are governed by the ePrivacy Directive, not GDPR. ePrivacy regulates email, phone, text and other communications – not personal data per se. It prohibits setting a third party cookie on a device without first getting consent. It also requires consent for email marketing, which, when collected in the context of a sale to a customer (and some other restrictions) may be opt-out (this is often called a “soft opt-in”). Otherwise, the consent must be opt in. This is getting confused with the GDPR.