Are companies using GDPR as an excuse?

Mikepassword

Free Member
Oct 14, 2018
7
0
Hello everybody, I was directed to UK Business forum by BING.com, you came up almost at the top of the list when I searched for GDPR Forum.
Over the past number of months I have become increasingly exasperated by big companies ignoring my chosen preferences regarding which types of cookies I will accept and which types I will reject when working on the internet. There are some that recognise the options that are available in my web browser but there are a large number of large companies that do not and interestingly one of those companies is Microsoft.
As most of you will be aware there are three basic categories of cookie that can be stored by web sites onto your computer. These categories break down to "First-Party", "Session" and "Third-Party. I have accepted the first two types and I have rejected the latter but a large number of large companies, one of which is Microsoft, curtail any activity unless all cookies are accepted. Some companies will detail the third-party companies in their privacy statement but most do not. Also, almost without exception, the first-party states or suggests in its privacy policy that it will not be responsible for the third-party's privacy policy.
My concern is, are these companies (offenders in my view) being fair to their customers or users and are they acting in good faith and within the 'principle', if nothing else, of the GDPR guide lines? This has only come about since GDPR came into force.
I look forward to reading your thoughts and perhaps your advice. I will also look forward to joining the debate if any.
Thank you.
 
Sorry, you reject cookies and the company concerned then don't allow all activities - what exactly is the problem? Both sides getting what they want.
 
Upvote 0
Sorry, you reject cookies and the company concerned then don't allow all activities - what exactly is the problem? Both sides getting what they want.
I did not say that I have rejected all cookies.
I have accepted the cookies that the first-party (the web site) by definition considers necessary for the operation of that website (First-Party and Session cookies). The cookies that I have rejected are the third-party cookies that the First-Party will not accept responsibility for!
The Data Protection Act and GDPR are in place to protect our personal data and companies are quite rightly responsible for ensuring the security of any data that they may collect and they mostly do that but the third-party companies are not so transparent and are often anonymous or unidentifiable from the names of their cookies.
If I was getting what I wanted I would not have cause for concern so clearly you have misunderstood my post..
 
Upvote 0
I did not say that I have rejected all cookies.
I have accepted the cookies that the first-party (the web site) by definition considers necessary for the operation of that website (First-Party and Session cookies). The cookies that I have rejected are the third-party cookies that the First-Party will not accept responsibility for!
The Data Protection Act and GDPR are in place to protect our personal data and companies are quite rightly responsible for ensuring the security of any data that they may collect and they mostly do that but the third-party companies are not so transparent and are often anonymous or unidentifiable from the names of their cookies.
If I was getting what I wanted I would not have cause for concern so clearly you have misunderstood my post..

You are getting what you wanted, not having 3rd party cookies yes? What other choice were you making on the site?
 
Upvote 0
Cookies are packets of data, usually stored on the user's computer, that retain preferences and other data. Web sites use cookies when the user accesses a web site on a re-visit to deliver a seamless user experience. Most web sites fail to work well if cookies are not enabled.

As the cookie data packages sometimes contain unique data pertaining to the user, or user's computer, they fall under the scope of GDPR.

GDPR requires consent from a user for the processing of personal data, so web sites should throw up a cookie policy and require acceptance, or rejection.

If a web site author deems that the GDPR regulation cannot be complied with if cookies are not enabled, then they should disable activity on the site if cookies are disabled.

If you want to use a site that fails with cookies disables, then you must enable cookies. Your choice under GDPR.
 
Upvote 0
This is a subject that the Information Commissioners Office will be looking into in detail very soon.
at the Direct Marketing Associations recent 2018 Data Protection Conference, Steve Woods of the ICO informed us that a "task force" is being set up specifically to look at third party data sharing on the web, such as advertising cookies.

The practice of requiring acceptance of Third Party cookies is unlawful because it requires users to accept some part of processing that is not "necessary" to provide the service being offered. These are often sites which are hosted outside Europe and not in countries with an "adequacy decision", so the companies require consent to view the site as they are processing personal data just by logging which IP's visit the site. It is however technically possible to present the site without recording this information, so they are not operating within the spirit of the GDPR.

A more concerning practice I have seen on many sites is defaulting the cookie consent to on unless you set it off, which is unlawful. Also there are some sites which have so many third party cookies and nested consents that to a user they are unworkable to choose, which is definitely unlawful.

Sadly we have to wait until the task force investigate and take action, however I suspect when the new ePrivacy Regulation comes into effect (likely effective in two to three years) that this will go much further on this subject.

The best advice from me if you don't like the cookies is to set your browser to default to using InPrivate or Incognito mode so the cookies are not saved when you end your browser session.
 
Upvote 0
This is a subject that the Information Commissioners Office will be looking into in detail very soon.
at the Direct Marketing Associations recent 2018 Data Protection Conference, Steve Woods of the ICO informed us that a "task force" is being set up specifically to look at third party data sharing on the web, such as advertising cookies.

The practice of requiring acceptance of Third Party cookies is unlawful because it requires users to accept some part of processing that is not "necessary" to provide the service being offered. These are often sites which are hosted outside Europe and not in countries with an "adequacy decision", so the companies require consent to view the site as they are processing personal data just by logging which IP's visit the site. It is however technically possible to present the site without recording this information, so they are not operating within the spirit of the GDPR.

A more concerning practice I have seen on many sites is defaulting the cookie consent to on unless you set it off, which is unlawful. Also there are some sites which have so many third party cookies and nested consents that to a user they are unworkable to choose, which is definitely unlawful.

Sadly we have to wait until the task force investigate and take action, however I suspect when the new ePrivacy Regulation comes into effect (likely effective in two to three years) that this will go much further on this subject.

The best advice from me if you don't like the cookies is to set your browser to default to using InPrivate or Incognito mode so the cookies are not saved when you end your browser session.

And by then the UK will be in no position to impose its own version of internet privacy on companies operating in other countries with their own ideas about privacy and advertising.
In other words don't expect much to change soon.
 
Upvote 0
And by then the UK will be in no position to impose its own version of internet privacy on companies operating in other countries with their own ideas about privacy and advertising.
In other words don't expect much to change soon.

I would admit that Brexit is a very grey area for data protection however whatever happens, the UK will have to implement comparable law if we have any hope to trade in the EU.
Also, don’t forget that with the exception of perhaps Germany, the UK has been one of the leaders in data protection for over 20 years.
 
Upvote 0
I would admit that Brexit is a very grey area for data protection however whatever happens, the UK will have to implement comparable law if we have any hope to trade in the EU.
Also, don’t forget that with the exception of perhaps Germany, the UK has been one of the leaders in data protection for over 20 years.

We can certainly implement whatever laws within our own borders. Persuading others to do so too that meet our requirements may not be as high on the agenda.
Possibly as part of a trade deal - though likely to be years away for those anyway.
 
Upvote 0
T
This is a subject that the Information Commissioners Office will be looking into in detail very soon.
at the Direct Marketing Associations recent 2018 Data Protection Conference, Steve Woods of the ICO informed us that a "task force" is being set up specifically to look at third party data sharing on the web, such as advertising cookies.

The practice of requiring acceptance of Third Party cookies is unlawful because it requires users to accept some part of processing that is not "necessary" to provide the service being offered. These are often sites which are hosted outside Europe and not in countries with an "adequacy decision", so the companies require consent to view the site as they are processing personal data just by logging which IP's visit the site. It is however technically possible to present the site without recording this information, so they are not operating within the spirit of the GDPR.

A more concerning practice I have seen on many sites is defaulting the cookie consent to on unless you set it off, which is unlawful. Also there are some sites which have so many third party cookies and nested consents that to a user they are unworkable to choose, which is definitely unlawful.

Sadly we have to wait until the task force investigate and take action, however I suspect when the new ePrivacy Regulation comes into effect (likely effective in two to three years) that this will go much further on this subject.

The best advice from me if you don't like the cookies is to set your browser to default to using InPrivate or Incognito mode so the cookies are not saved when you end your browser session.

Thank you Mike, that is what I thought.
The situation that I alluded to with Microsoft is that unless I accept 'third-party' cookies I cannot get technical assistance nor can I access my own account with Microsoft.
I am therefore not able to get problems solved which also raises questions about breach of contract.
 
Upvote 0
Cookies are packets of data, usually stored on the user's computer, that retain preferences and other data. Web sites use cookies when the user accesses a web site on a re-visit to deliver a seamless user experience. Most web sites fail to work well if cookies are not enabled.

As the cookie data packages sometimes contain unique data pertaining to the user, or user's computer, they fall under the scope of GDPR.

GDPR requires consent from a user for the processing of personal data, so web sites should throw up a cookie policy and require acceptance, or rejection.

If a web site author deems that the GDPR regulation cannot be complied with if cookies are not enabled, then they should disable activity on the site if cookies are disabled.

If you want to use a site that fails with cookies disables, then you must enable cookies. Your choice under GDPR.

Thank you Chris,
Doesn't the fact that it is the users choice whether he or she accepts cookies open GDPR to abuse?
A website that gets paid by its third-party 'partners', as some are described, earns its living from third-parties so it is not necessarily interested in people who are just 'window shopping'(?). Furthermore, those third-parties are often anonymous and unless one is into IT forensics they are very difficult to identify so the user's personal security cannot be assured.
Another problem with GDPR as I understand it is that it has made websites responsible for all the data that it holds so in order to get around that stipulation the website now dumps that data onto the user's computer in the form of cookies. I cleaned out my cookies the other day after not much more than a week of moderate internet activity and cleared several megabytes of data from IE and Edge. That is not small data files as we are often told they are.
 
Upvote 0
Doesn't the fact that it is the users choice whether he or she accepts cookies open GDPR to abuse?

Apparently, yes -
This is a subject that the Information Commissioners Office will be looking into in detail very soon.
at the Direct Marketing Associations recent 2018 Data Protection Conference, Steve Woods of the ICO informed us that a "task force" is being set up specifically to look at third party data sharing on the web, such as advertising cookies.

This is something that I was unaware of until this thread appeared.

The main purpose of GDPR is to lay down the framework for 'testing' that which becomes real world practice.

Don't expect the ICO to be able to foresee all possible outcomes and preemptively act to prevent violation. I understand that the ICO plans to expand its workforce to 600 by 2020, even then there will be insufficient bodies on the ground to act as a preventative force.

The practical rule then is - if you see something you don't like, challenge it.

If you were to rephrase your original question as "Are companies going to exploit ever loophole they can find in order to improve market penetration?" I would answer Yes.

That is what marketing departments do.

If you wish to avoid having your data harvested for marketing or profiling don't use an Internet connected computer.

We will wait to see the outcome of the developments on third party cookies.
 
Upvote 0
If you wish to avoid having your data harvested for marketing or profiling don't use an Internet connected computer.
.

It is very difficult not to use a computer that is not connected to the internet when Microsoft's latest Operating System is reliant upon a connection,. Without an internet connection it is not possible to get full usage.

The practical rule then is - if you see something you don't like, challenge it.

Contacting Microsoft to challenge its cookie policy is extremely difficult; as it is with most other websites.
 
Upvote 0
It is very difficult not to use a computer that is not connected to the internet when Microsoft's latest Operating System is reliant upon a connection,. Without an internet connection it is not possible to get full usage.

You don't need to use a Microsoft product at all.

Contacting Microsoft to challenge its cookie policy is extremely difficult; as it is with most other websites.

You would challenge through the ICO, not direct to Microsoft.

What is not apparent in this thread is a clear idea of what it is that you are afraid of.
 
Upvote 0
It is very difficult not to use a computer that is not connected to the internet when Microsoft's latest Operating System is reliant upon a connection,. Without an internet connection it is not possible to get full usage.



Contacting Microsoft to challenge its cookie policy is extremely difficult; as it is with most other websites.

Have you considered not using Microsoft products if they don't provide what you want?
 
Upvote 0
You would challenge through the ICO, not direct to Microsoft.

I had no knowledge of the ICO before reading your reply and I am sure that most people could say the same.
Surely it would be beneficial if websites were to include a reference to the ICO informing the user that he or she can challenge the website's cookie policy if they so wish. Instead most sites do not even tell you that you need to enable cookies leaving you to believe that there is a problem with your computer or your internet connection.
Apart from empowering the user such an inclusion would perhaps make intransigent websites more inclined to tow the line in the spirit of GDPR.
 
Upvote 0
You don't need to use a Microsoft product at all.

What is not apparent in this thread is a clear idea of what it is that you are afraid of.

I am not writing from a fear of anything; my purpose evolves from the anger that I feel when companies sell me a product that includes a warranty of some sort but deny me the full usage of the product or the support that the warranty provides unless I allow that company unrestricted licence to store data on my computer and to monitor what I do with my computer.

I have just been reading The Spectator magazine in which there is an advertisement for annual subscription to that magazine. In the advert there are the small boxes asking me if I would like them to send me regular emails or promotional material from them or their 'selected' partners. It does not matter whether I mark those boxes or not-I am still able to enjoy the magazine that I have bought! Why is it therefore that when I buy something online I have to give away so much to the website when in real-world shopping there are no such demands, restrictions or stipulations?

That is where I am coming from.
 
Upvote 0
I had no knowledge of the ICO before reading your reply and I am sure that most people could say the same.

Then your post on this forum has served its purpose. You have learned something new. Due to the fact that the content of these posts are also available to search engines, your concerns and the responses to them are now also in the public domain.

I am not writing from a fear of anything; my purpose evolves from the anger that I feel when companies sell me a product that includes a warranty of some sort but deny me the full usage of the product or the support that the warranty provides unless I allow that company unrestricted licence to store data on my computer and to monitor what I do with my computer.

As @Mike Kilby PC.dp points out above, this issue is already in scope for examination by the ICO.
 
Upvote 0

Latest Articles