Cookies, consensus and co – “May we ask for your consent?”

0
7


Whenever you visit a website for the first time these days, a window inevitably pops up. At the top it says: “May we ask for your consent?” or “We want to offer you the best user experience!” – Below or next to it, a button for “accept” and several small-case notes on how users can exercise their data rights. If you want to object to the disclosure of your data, you often have to click your way through a confusing maze of buttons, hidden options and links to really find all data uses. If you simply click away from the dialog, you usually have to live with the fact that the website sets dozen or even more than 100 cookies. If, on the other hand, you refuse cookies across the board using your browser settings, the consent dialogs will be displayed again and again.

There are two main reasons for this new flood of banners. On the one hand, in May the Federal Court of Justice ended the German special route that had allowed German website operators to save cookies on users’ devices without being asked, contrary to the European E-Privacy Directive. Second, following the new data protection laws in Europe and California, the advertising industry has agreed on a new standard for ensuring that data usage continues to comply with the law. The “Transparency & Consent Framework” is now available in version 2.0 and has been widely accepted – not least because Google supports the framework. Consequence: Anyone who tries today to do without such a cookie banner will be rejected by most advertising networks.

What is it specifically about? Cookies are actually an almost 30 year old web technology that makes it possible to save default settings in the browser. The server sends a short text string to the browser, which is saved there as a cookie. If you visit the same website again, the web server asks about the cookies that have been set and the text string is sent back.

This text string can consist of a postcode, for example, so that the forecast for your own place of residence is always displayed on the website of a weather service. The text string can also contain a unique identifier so that you do not have to log in every time you visit. Thanks to cookies, the shopping cart in the online shop is still full the next day, cookies can be used to save language preferences for websites or to find content that has been searched for with just a few clicks.

But cookies are also a central technology behind personalized advertising. For example, anyone who visits a website not only receives cookies from a publisher, but usually also the cookies from many advertising networks, which use them to track user activities across the web. With the compiled user profiles, users can be presented with targeted offers. With retargeting, for example, users are shown advertisements for goods that they previously viewed in an online shop but did not buy. In order to be able to play almost every advertisement in a targeted manner, the advertising industry collects comprehensive profiles that store all information relevant to advertising in a profile, from age, place of residence and income to interests and hobbies.

In addition to advertising cookies, there are also a number of cookies that users do not track through the web. For example, statistics scripts use cookies to try to consolidate the visit statistics. In this way, operators keep track of how many users are actually on the website and which route they are taking. Another example of tracking-free cookies are those from VG Wort, which are displayed on many publishing houses’ websites in order to enable the allocation of annual royalties to authors, but not to create cross-offer user profiles.

The cookie banners are not just about cookies, but about many types of data processing. For example, advertisers want to prevent their advertising from appearing next to unsuitable content – so specialized “brand safety” providers ask which article an advertisement appears next to. If such scripts are refused, many advertisers will not want to advertise. Cookies also record how often a certain advertisement is played – after all, advertisers do not want to spend too much on one and the same user. Website operators who want to achieve reasonable prices on real-time programmatic advertising marketplaces have to provide a lot of data.

Anyone who operates a website and wants to earn money with advertising therefore has a clear goal: users should give their consent to data processing as often as possible. If the users refuse, a rapid loss of income is usually hardly avoidable: Even if the websites are still able to deliver certain advertisements to users without tracking, these banners are paid significantly less. And even at reduced prices, the data-hungry advertising industry usually doesn’t deliver enough advertising – if users reject all cookies, many advertising spaces usually remain empty.

The result looks accordingly: There are many operators who do their best to enable users to make an informed choice. However, many cookie banners appear to be purposely intended to confuse the user. The buttons for approval are highlighted in color, but the options for rejection are kept plain and ambiguous.

In the newly published information, the Lower Saxony data supervisory authority warns against such practices. “Nudging” is an attempt to get users to agree. The privacy advocates try to work out exactly where the limits are. “It is certain that there are limits to permitted nudging and that behavior-manipulating designs can lead to the ineffectiveness of the consent,” says the recommendations from Hanover. In no case should one rely on the default settings for the consent tools available on the market, which take over the processing of cookies for the site operator. A so-called cookie wall, in which users are locked out of content if they do not consent to cookies, is also incompatible with the General Data Protection Regulation. Data protection authorities from all over Germany are currently investigating the practice of cookie banners.

To home page



Source link
https://www.heise.de/hintergrund/Cookies-Konsens-und-Co-Duerfen-wir-um-ihre-Zustimmung-bitten-4981016.html

LEAVE A REPLY

Please enter your comment!
Please enter your name here