Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce.


Something being beneficial to a business does not make it broadly necessary, desirable, or - in many cases - legal.

It would be extremely beneficial to businesses to put a clause in their terms and conditions that limit damages to 1 cent in the event of any dispute. For obvious reasons we don't allow anything like that to be enforced.

I'm not saying whether tracking should or shouldn't exist, but "the business can make more money" is not a valid argument in my book.


Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.

At least for GDPR...

The only ways to actually track without a consent pop-up are:

(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or

(2) confine any device storage to what's strictly necessary for the service the user requested


This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.


you don’t need to track users by giving them an ID they send with every request.

in fact. you probably don’t need to track users.


tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much?


I don't exactly see how these two statements are contradictory. Policy is about conflicting interests.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: