Apparently the eu official website really needs to track you then. For what’s essentially just static content. I’ll consider dropping cookies banner when their website can work without. Stop the “do as I say not as I do”
They apparently hired incapable people to build that. Very silly to build it in a way that kind runs contrary to what the intentions of the very laws they are making are.
I get similarly upset, when I see Google tracking on official websites of government or public institutions.
Not wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.
No, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality.
You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent.
Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.
This is actually slightly narrower exception than people (and regulators) think. The exception is:
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
Apparently the eu official website really needs to track you then. For what’s essentially just static content. I’ll consider dropping cookies banner when their website can work without. Stop the “do as I say not as I do”
EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr
They apparently hired incapable people to build that. Very silly to build it in a way that kind runs contrary to what the intentions of the very laws they are making are.
I get similarly upset, when I see Google tracking on official websites of government or public institutions.
> Apparently the eu official website really needs to track you then.
No, they don't really need to track you, that's why it requires consent to do it.
They are doing exactly what they say.
In other words, they're not saying don't track your visitors. They're saying get consent first.
You could try to understand why that’s the case, instead of assuming maliciousness or incompetence.
https://commission.europa.eu/resources/europa-web-guide/desi...
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
they use third party cookies, just read their linked info on it and it's fairly clear why they have a banner
if they didn't use third party cookies they wouldn't need it
Outlawing user tracking/profiling and selling their data would be the biggest change to the internet.
It’s not that easy to make a distinction between what is necessary.
Wrong.
Not wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.
No, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality. You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent. Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.
4 replies →
This is actually slightly narrower exception than people (and regulators) think. The exception is:
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
2 replies →