Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

E.U. Privacy Organizations Launch Initiative to Kill Cookie Consent Banners​

By: Nick Heer
27 August 2026 at 04:03

In September, the European Commission began pondering how to correct its 2009 privacy law that resulted in cookie permission banners littering the web, with the resulting proposal announced in November.

Jennifer Rankin, the Guardian:

EU officials said users would remain in control of their data on the internet, but new rules on cookies — the internet files that are stored on a user’s device so a website can remember them — would make life simpler by ensuring one-click consent. “I think we can all agree we have spent too much of our time accepting or rejecting cookies,” [Henna] Virkkunen said.

This was not the first time the Commission had attempted to correct for the permissions pollution that resulted from the e-Privacy Directive. In 2020, its efforts were focused on ineffective consent options like, as reported at the Verge, “a cookie consent policy with no obvious way to opt out of tracking”. I still see many websites, like the Verge itself, providing no meaningful consent for third-party tracking.

This time, though, the Commission said it was trying to make cookie consents less prevalent by allowing, for example, simple statistical cookies without any consent, and it was going to give users an option to decline tracking universally. When I looked into the changes in November, it seemed like this signal could be ignored by publishers and media companies who would be free to ask for consent anyway. As of May, it seemed this proposal was moving forward by requiring consent management platforms to respond to browser signals. By summer, however, things had changed.

Ernestas Naprys, Cybernews (“Article 88b” refers to the universal browser signal proposal):

Google suggested ditching Article 88b.

“Article 88b should be deleted. Retaining this provision risks anchoring the Omnibus to a proven-failed architecture, Google’s position reads.

“It will drastically impair the ability of most websites to monetize content and drive client acquisition. The resulting low consent rates and severely restricted data access.”

Meta suggested removing the entire Article 5(3) of the ePrivacy Directive. This rule is why we have cookie banners in the first place, as it requires website operators to obtain clear user consent before storing or accessing their information.

It was not just U.S.-based companies that argued against better user privacy controls. According to noyb, French, German, and Polish representatives were in alignment with Google’s position, which ultimately led to its scrapping. All three countries are home to companies that would be affected by this regulation. None, however, are as big or as powerful as Google or Meta.

Privacy-defending organizations are understandably not impressed. They have launched Kill the Cookie Banner to drum up support for legal recognition of a browser signal. In the U.S., five state governments say the Global Privacy Control must be respected. At a browser level, it is only implemented in Brave, DuckDuckGo, and Firefox, but it seems that Apple is working to add it to Safari, and it seems it is being actively worked on for Chromium, too. The European Commission should throw its weight behind this control, too.

⌥ Permalink

Strokovna delavnica v CTK: UMETNA INTELIGENCA V RAZISKOVANJU: avtorske pravice, GDPR in odgovorna raba ter etika

10 July 2026 at 08:58

Centralna tehniška knjižnica Univerze v Ljubljani (CTK) vabi raziskovalke in raziskovalce na strokovno delavnico, bo potekala v četrtek, 17. septembra 2026, od 9.30 do 15.00 v prostorih konferenčne dvorane CTK.

Delavnica je namenjena obravnavi aktualnih pravnih, avtorskih in etičnih vprašanj uporabe umetne inteligence v raziskovalnem okolju.

Udeleženci boste spoznali:

  • izzive avtorskega prava in odprte znanosti,
  • uporabo raziskovalnih podatkov in publikacij v orodjih AI,
  • odgovorno rabo umetne inteligence v akademskem okolju,
  • varstvo osebnih in zaupnih podatkov ter skladnost z GDPR,
  • etične meje uporabe generativne umetne inteligence pri raziskovalnem delu.

Delavnica bo ponudila aktualne dileme, praktične primere in priporočila za odgovorno, transparentno in zakonito uporabo umetne inteligence v raziskovanju.

Program delavnice

9.00–9.30Registracija udeležencev
9.30–10.30Avtorske pravice in umetna inteligenca v raziskavah
Izr. prof. dr. Matija Damjan, Pravna fakulteta Univerze v Ljubljani
10.30–11.30Zaupni podatki, GDPR in umetna inteligenca
Dr. Katja Štemberger Brizani, Pravna fakulteta Univerze v Ljubljani
11.30–12.00Odmor s pogostitvijo
12.00–13.00Umetna inteligenca v raziskovanju: etične meje in dobre prakse
Lucija Strojan, mag. prava, Pravna fakulteta Univerze v Ljubljani
13.00–13.30Vprašanja in razprava

Delavnica bo potekala izključno v živo. Udeležba je brezplačna, vendar je število mest omejeno, zato se je na dogodek treba prijaviti, in sicer preko naslednje povezave.  Prijave sprejemamo do zapolnitve mest.

Delavnico organizira Centralna tehniška knjižnica Univerze v Ljubljani z izvajalci iz Pravne fakultete Univerze v Ljubljani.

Izr. prof. dr. Matija Damjan

Izredni profesor za civilno in gospodarsko pravo na Pravni fakulteti Univerze v Ljubljani, direktor Inštituta za primerjalno pravo pri Pravni fakulteti v Ljubljani in sekretar uredniškega odbora revije Pravni letopis. Pri svojem raziskovalnem in pedagoškem delu se posveča zlasti pravu intelektualne lastnine, pravu informacijske družbe ter pravnim izzivom, ki jih prinašajo informacijske tehnologije in umetna inteligenca. Med letoma 2020 in 2022 je sodeloval v delovni skupini za upravljanje podatkov pri Global Partnership on Artificial Intelligence (GPAI). Aktivno sodeluje na domačih in mednarodnih strokovnih ter znanstvenih dogodkih s področja avtorskega prava, odprte znanosti in pravnih vidikov digitalnih tehnologij.

Dr. Katja Štemberger Brizani

Docentka na Katedri za upravno pravo Pravne fakultete Univerze v Ljubljani in raziskovalka na Inštitutu za primerjalno pravo pri Pravni fakulteti v Ljubljani. Pri svojem pedagoškem in raziskovalnem delu se posveča zlasti upravnemu pravu, javnim naročilom, koncesijam ter javno-zasebnim partnerstvom. Aktivno sodeluje na domačih in mednarodnih strokovnih ter znanstvenih konferencah, predavala pa je tudi na tujih univerzah, med drugim na Masarykovi univerzi v Brnu. Je ustanoviteljica in koordinatorka Pravne klinike o javnih naročilih, koncesijah in javno-zasebnih partnerstvih. Kot avtorica in soavtorica številnih znanstvenih prispevkov raziskuje predvsem vprašanja upravnih pogodb, koncesij, pravnega varstva ter sodobnega razvoja upravnega prava.

Lucija Strojan, mag. prava

Asistentka na Katedri za civilno pravo Pravne fakultete Univerze v Ljubljani in raziskovalka na Inštitutu za primerjalno pravo pri Pravni fakulteti v Ljubljani. Pri svojem raziskovalnem delu se posveča zlasti civilnemu pravu, pravu varstva potrošnikov, pravu informacijske družbe ter pravnim vidikom umetne inteligence in digitalne regulacije. Sodeluje pri več domačih in mednarodnih raziskovalnih projektih s področja odprtih podatkov, digitalne regulacije in umetne inteligence. Aktivno sodeluje na domačih in mednarodnih znanstvenih konferencah ter objavlja strokovne in znanstvene prispevke s področja civilnega in digitalnega prava.


Dogodek poteka pod okriljem Odprte knjižnice in je sofinanciran v okviru Akcijskega načrta za odprto znanost za izvedbo Ukrepa 6.2 ReZrIS30.

⌥ Engineering Consent

By: Nick Heer
30 July 2024 at 02:02

Anthony Ha, of TechCrunch, interviewed Jean-Paul Schmetz, CEO of Ghostery, and I will draw your attention to this exchange:

AH I want to talk about both of those categories, Big Tech and regulation. You mentioned that with GDPR, there was a fork where there’s a little bit of a decrease in tracking, and then it went up again. Is that because companies realized they can just make people say yes and consent to tracking?

J-PS What happened is that in the U.S., it continued to grow, and in Europe, it went down massively. But then the companies started to get these consent layers done. And as they figured it out, the tracking went back up. Is there more tracking in the U.S. than there is in Europe? For sure.

AH So it had an impact, but it didn’t necessarily change the trajectory?

J-PS It had an impact, but it’s not sufficient. Because these consent layers are basically meant to trick you into saying yes. And then once you say yes, they never ask again, whereas if you say no, they keep asking. But luckily, if you say yes, and you have Ghostery installed, well, it doesn’t matter, because we block it anyway. And then Big Tech has a huge advantage because they always get consent, right? If you cannot search for something in Google unless you click on the blue button, you’re going to give them access to all of your data, and you will need to rely on people like us to be able to clean that up.

The TechCrunch headline summarizes this by saying “regulation won’t save us from ad trackers”, but I do not think that is a fair representation of this argument. What it sounds like, to me, is that regulations should be designed more effectively.

The E.U.’s ePrivacy Directive and GDPR have produced some results: tracking is somewhat less pervasive, people have a right to data access and portability, and businesses must give users a choice. That last thing is, as Schmetz points out, also its flaw, and one it shares with something like App Tracking Transparency on iOS. Apps affected by the latter are not permitted to keep asking if tracking is denied, but they do similarly rely on the assumption a user can meaningfully consent to a cascading system of trackers.

In fact, the similarities and differences between cookie banner laws and App Tracking Transparency are considerable. Both require some form of consent mechanism immediately upon accessing a website or an app, assuming a user can provide that choice. Neither can promise tracking will not occur should a user deny the request. Both are interruptive.

But cookie consent laws typically offer users more information; many European websites, for example, enumerate all their third-party trackers, while App Tracking Transparency gives users no visibility into which trackers will be allowed. The latter choice is remembered forever unless a user removes and reinstalls the app, while websites can ask you for cookie consent on each visit. Perhaps the latter may sometimes be a consequence of using Safari; it is hard to know.

App Tracking Transparency also has a system-wide switch to opt out of all third-party tracking. There used to be something similar in web browsers, but compliance was entirely optional. Its successor effort, Global Privacy Control, is sadly not as widely supported as it ought to be, but it appears to have legal teeth.

Both of these systems have another important thing in common: neither are sufficiently protective of users’ privacy because they burden individuals with the responsibility of assessing something they cannot reasonably comprehend. It is patently ridiculous to put the responsibility on individuals to mitigate a systemic problem like invasive tracking schemes.

There should be a next step to regulations like these because user tracking is not limited to browsers where Ghostery can help — if you know about it. A technological response is frustrating and it is unclear to me how effective it is on its own. This is clearly not a problem only regulation can solve but neither can browser extensions. We need both.

❌
❌