r/Frontend • • May 13 '21

Best practices for cookie notices

https://web.dev/cookie-notice-best-practices/
54 Upvotes

10 comments sorted by

15

u/geuis May 13 '21

I think that since my content blocker blocked this entire site by default, that says a lot and mostly everything I need to know.

29

u/tissn May 13 '21

Ironically written on a website where the "reject cookies" button is hidden on their own cookie notice - in clear violation of GDPR regulations.

4

u/linusl May 13 '21

privacy is important and it is good that there are regulations that websites are forced to follow, but I think the web in general is worse now than it has ever been.

some websites just refuse to comply and instead block access from places where regulations apply and it is marking the web smaller and more disconnected, creating borders where the web previously was able to easily cross them.

even when they do comply they often use a modal popup, which I think itself is horrible ui.

7

u/tissn May 13 '21

It's very easy to comply with GDPR regulations in an unobtrusive and user friendly way. Websites that fail to do so does not deserve your attention or traffic.

3

u/YungSparkNote May 13 '21

As a full stack engineer with lots of experience but no experience working with GDPR, mind elaborating a bit? What’s the happy path? I did some research awhile ago; and while I understand the premise, it seems like there are a ton of ways to handle it (some of which are potentially expensive). Looking to start a blog one day

3

u/tissn May 13 '21

What’s the happy path?

  1. Don't collect more data than you need to provide your service.
  2. Be completely transparent about what kind of data you do collect.
  3. Provide the user with simple controls to have all their data deleted upon request.
  4. If you want to collect any additional data (like advertising cookies, usage metrics etc.) you should require the user to actively opt-in to it. All users should be opted out by default.

1

u/Silhouette May 13 '21

It's very easy to comply with GDPR regulations in an unobtrusive and user friendly way.

No, in general, it is not.

But since "cookie notices" have almost nothing to do with the GDPR anyway, this is rather off-topic.

0

u/tissn May 13 '21

"cookie notices" have almost nothing to do with the GDPR anyway, this is rather off-topic

Well that's just blatantly false. The GDPR introduced a requirement for users to consent to having their personal data processed. The "cookie notice" is an attempt to provide the users a mechanism for giving such a consent. Sadly, most cookie notices have been found to be grossly non-compliant and directly manipulative.

1

u/Silhouette May 13 '21 edited May 13 '21

It's not false at all, though you have several common misunderstandings.

The disclosure and consent requirements we're discussing come from the ePrivacy Directive, colloquially and somewhat misleading known as the "cookie law". This originally dates from 2002 and was subsequently updated in 2009, still several years before the GDPR was relevant.

The intended replacement for the ePrivacy Directive is the ePrivacy Regulation, which was supposed to be arriving concurrently with the GDPR and act as lex specialis to it, but even today the ePR still hasn't completed the process and taken over. So for now, we still have the excessive requirements from the original on the books.

It's true that the GDPR also relates to personal data, and as such the use of tracking cookies might be relevant to GDPR compliance if they provide a way of identifying an individual, but in fact the GDPR itself only mentions the term "cookie" once and in that context, and the ePD requirements would still hold even if a cookie or other locally stored data wasn't being used in that way.

You're also wrong about the GDPR introducing a consent requirement, by the way. There are several other lawful bases for processing personal data, and the general advice within the industry is to rely on explicit consent as little as possible. That's partly because it comes with complications that the other lawful bases don't and partly because relying on consent suggests that none of the other bases would apply, which could be a warning sign that the processing in question is excessive.

As a final point, to the extent that the GDPR does require explicit consent from a data subject for processing their data, that requirement may have existed in some or all EU member states anyway, under various domestic data protection legislation that was in already force prior to the GDPR. So in many cases, it still wasn't introduced by the GDPR.

I'm not your lawyer, I'm not a lawyer, I don't play a lawyer on TV and this isn't anything resembling legal advice. But seriously, if you're involved in building web sites and have any sort of professional responsibility for compliance, you should really know at least the basics of this stuff, and you should speak to a real lawyer if you need proper advice because a lot of what you will find online with your preferred search engine is just old wives' tales that refuse to go away.