According to GDPR it’s illegal to condition content on tracking approval. This is VERY clear if you read the law. I can’t understand why this has become very popular to do just recently.
Personally I do agree, but enforcement is unfortunately behind DPAs and it's pretty clear that they are trying to avoid ruling on it.
In theory someone could directly sue some company which engages on this via Article 79, but this can be expensive and depending on jurisdiction the plaintiff can end up with personal liability on defendant's legal costs if court ends up finding that this is actually legal (e.g. Finland has "loser pays" rule in civil suits).
Additionally this does also touch ePD and in some countries there might be different agency which handles ePD complaints compared to GDPR, like in Finland Data Protection Ombudsman handles GDPR, but Transport and Communications Agency (Traficom) handles ePD. If there is something that touches both the Ombudsman usually lets Traficom take care of ePD aspects before they give any GDPR ruling. Both of these can take years.
> The EU's own government websites have these same cookie banners.
Most of them decidedly don't have the same cookie banners. E.g. in vast majority of cases they don't prevent you from seeing content, and have an easy opt-out mechanism without dark patterns.
The result matters, which is why regulations should be considered carefully. The whole cookie fiasco is exactly that: they created a whole industry of shitty compliance and the rules are complex enough that every engineering team is like "just use the off-the-shelf shitty thing". And here we are.
As a reminder "EU cookie banners" are not required if you use cookies for site functionality. They are only required if your site uses these to track users.
This needs repeating, it's a common misconception (deliberately spread by many, too) that the EU requires cookie banners for all cookies.
> This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.
This gets repeated a lot, but is not my experience after having worked with both in-house and contracted lawyers to understand how functional cookies are handled. We end up wanting something more durable than session cookies to track user preferences so we can set them next time they visit. This is super standard light/dark mode, region, language type of stuff. But that's considered “tracking" in many of these discussions, which never made sense to me.
Im pretty sure it is illegal. In my understanding, it must be equally easy to reject and accept. And the website MUST continue working under either choice. Which is not the case here.
I think the lawmakers should have made all forms of tracking illegal instead. That would make law writing and following easier. And closer to the spirit of what they are trying to accomplish and what everyone wants (except you Silicon Valley O.o)
I hate the tracking too. But how to websites monetize free content otherwise? Advertising doesn’t work if you can’t price it. Without tracking, everything becomes a paywall.
It seems a lot of people are doing amazing things with Patreon. Share some things for free (free as in beer) then have a paid tier for those who want more. Convince us you’re worthy, then we’ll give you money willingly.
I know the EU cookie banners have basically ruined the internet, but this seems like a whole 'nother level of obnoxious.