Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m wondering if i should implement the consent prompt myself or use some plugin? If i were to implement it myself is it enough to give two options Yes/No or does the law require me to give some additional customisation options?

Edit:typos



A "I do not consent to any of this" option that you actually respect is perfectly compliant. All of these granular options are to "provide full control to allow users to customise the partners that they trust" (read: extra complexity to put off users exercising their right to not be tracked, plus the marginal improvement to telemetry from the 1% of users that will allow google analytics but not ad tracking).

That said, you do need to inform users of who specifically they're sending the data to (and what they're going to do with it) in the consent option. So "Yes, track me with all your unspecified partners" doesn't quite cut it for the yes option.


Yes you can implement it yourself – given how bad available cookie consent tools are, you're more likely to be compliant that way.

However, consent under the GDPR must be specific. That means the user should be able to consent to or withhold consent for individual processing purposes. Analytics would be one purpose, personalized ads another.

Note that under EU cookie laws you don't need consent for cookies that are strictly necessary for the service requested by the user. E.g. using a cookie for dark mode preference, for a shopping cart, or for the consent status itself is perfectly fine without consent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: