Hacker News new | past | comments | ask | show | jobs | submit login

You don’t require any for cookies that facilitate necessary site functionality, like login or, in this case, a uuid.

There’s widespread misunderstanding of the law.




In the UK (and broadly under the UK GDPR and PECR – the Privacy and Electronic Communications Regulations), yes, you generally do need to get consent before setting non-essential cookies, even if it's just for rudimentary analytics like a unique visitor count.

Here's the key distinction:

Strictly necessary cookies: No consent needed. These are required for the site to function properly (e.g., shopping cart cookies, login sessions).

Analytics cookies (including the case with a unique ID for tracking visitors): Not strictly necessary, so consent is required.

Even if the data is anonymous or pseudonymous (like a randomly generated unique ID), if the purpose is analytics and it involves storing or accessing data on the user’s device (like setting a cookie), you must ask for consent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: