Hacker News new | ask | show | jobs
by IMTDb 1206 days ago
> Neither ePrivacy nor GDPR require cookie consent popups

Except that it does. The law specifically prohibits any form of consent that is not informed and specific. As a consequence, a user cannot just consent - or disallow - cookies globally. He has to tick a box for every single domain on earth; and can only do so after reading the specific information box associated to said domain.

As a user, saying "I am OK with analytics cookies but not with marketing ones" is not something I am allowed to express or setup. I have to do it for every domain because the law explicitly forbids a global solution to be implemented.

1 comments

I'm afraid you are wrong for the global disallow button, as informed and specific consent is necessary to allow the processing of personal information, not to forbid it. See the definition in article 4(11), and the definition of the basis in article 6(1)a.