Hacker News new | ask | show | jobs
by chalst 5523 days ago
That's really an enforcement problem, not a legislative problem.

Even so, I think the answer is clear: it depends on whether you store data that permits you to infer privacy-intruding things about the user. If you store a cookie that just encodes preferences and you store no persistent data about the cookie on your side, you should be fine. It's the making a relationship between client local state and your customer profiles that's key.