It takes more clicks to reject their cookies than accept them, so France fines Facebook and Google over €200m
- Reference: 1641471968
- News link: https://www.theregister.co.uk/2022/01/06/cnil_facebook_google_cookie/
- Source link:
The CNIL kicked off its investigations after receiving complaints regarding the way cookies can be refused on facebook.com, youtube.com and google.fr. The crux of the matter is that while there is a button to permit immediate acceptance of cookies, there is not the equivalent to refuse them as easily. "Several clicks are required to refuse all cookies, against a single one to accept them," explained the CNIL.
"The restricted committee," it went on, "considered that this process affects the freedom of consent: since, on the internet, the user expects to be able to quickly consult a website, the fact that they cannot refuse the cookies as easily as they can accept them influences their choice in favor of consent. This constitutes an infringement of Article 82 of the French Data Protection Act."
[2]
Both fines have similar reasoning behind them. Google LLC was fined €90m while Google Ireland was fined €60m. Facebook Ireland's fine stands at €60m. The companies have three months to give internet users located in France a means to refuse cookies that is as simple as accepting them. "If they fail to do so, the companies will have to pay a penalty of €100,000 per day of delay," said the CNIL.
[3]
[4]
The Register asked the tech giants for their take on the fines, which follow the expiration of a deadline on 31 March 2021 for websites and mobile applications to comply with the rules.
A Meta spokesperson told us: "We are reviewing the authority's decision and remain committed to working with relevant authorities.
[5]
"Our cookie consent controls provide people with greater control over their data, including a new settings menu on Facebook and Instagram where people can revisit and manage their decisions at any time, and we continue to develop and improve these controls."
A Google spokesperson said: "People trust us to respect their right to privacy and keep them safe. We understand our responsibility to protect that trust and are committing to further changes and active work with the CNIL in light of this decision under the ePrivacy Directive."
[6]SlimPay fined €180k after 12 million customers' bank data publicly accessible for 5 years
[7]Luxembourg judge hits pause on Amazon's daily payments of disputed $844m GDPR fine
[8]Facial recog firm Clearview hit with complaints in France, Austria, Italy, Greece and the UK
[9]EU court rules Right To Be Forgotten doesn't apply outside member states
The ePrivacy directive is concerned with the privacy of communications, violations of which have enabled the CNIL to take direct action. Action under GDPR would have resulted in the Irish Data Protection Commission (DPC) taking the lead since both Google and Facebook entities are based in Ireland and only the privacy agency in the country where a company is established can enforce things. [10]Just ask WhatsApp .
We asked independent privacy researcher and consultant Dr Lukasz Olejnik if other countries might follow France's lead.
"This is unlikely," he said. "And even France was only able to pursue this case because the EU is unable to agree on the final ePrivacy Regulation. If it was in force, the responsibility would likely stop stay with the Irish DPC who might happen to have different priorities.
[11]
"It is also unlikely because it requires motivation and 'guts' to do this. And some EU countries deployed the old ePrivacy Directive in ways that effectively paralyse enforcement of the kind," he added.
"It seems that France remains on the forefront of data protection enforcement."
As for what Google and Facebook might have to do, Olejnik said: "Technically it is a very simple change. UX-wise it might be harder to swallow for the companies."
He went on to note that a literal adoption of the definition of consent would require the rethinking of some business processes. "Yet, it seems that not doing so may be costly," he concluded.
Facebook reported over $28bn in revenue in its [12]last set of quarterly results (an increase of 33 per cent on the previous year) and Alphabet (Google) [13]notched up [PDF] $65.1bn. ®
Get our [14]Tech Resources
[1] https://www.cnil.fr/en/cookies-cnil-fines-google-total-150-million-euros-and-facebook-60-million-euros-non-compliance
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YdcgR4K0i1t5vUKNrevWGAAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YdcgR4K0i1t5vUKNrevWGAAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YdcgR4K0i1t5vUKNrevWGAAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YdcgR4K0i1t5vUKNrevWGAAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/01/04/slimpay_breach_fine/
[7] https://www.theregister.com/2021/12/20/luxembourg_amazon_fine/
[8] https://www.theregister.com/2021/05/27/clearview_europe/
[9] https://www.theregister.com/2019/09/24/eu_court_justice_right_to_be_forgotten_ruling/
[10] https://www.theregister.com/2021/09/02/whatsapp_to_appeal_irish_gdpr_fine/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YdcgR4K0i1t5vUKNrevWGAAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://investor.fb.com/investor-news/press-release-details/2021/Facebook-Reports-Third-Quarter-2021-Results/default.aspx
[13] https://abc.xyz/investor/static/pdf/2021Q3_alphabet_earnings_release.pdf?cache=f1ba3f6
[14] https://whitepapers.theregister.com/
Yea - where did that ridiculous “legitimate interest” shite come from? Is it an attempt to make you feel bad for clicking “bugger off”?
Reject all
I personally tend to allow site to store information, select functional and reject anything else (Unless forced to click more than a few, anything with legitimate interest options gets the reject all button clicked then the site closed).
I am wasting years of my life with this crap
Re: Reject all
Browser makers really need to offer an option "save cookies for this site, but scrap them when the tab is closed" along with a list of the cookies with any potentially useful ones (e.g. login token, basket contents) being filtered to the top of the list to be manually excluded.
Re: Reject all
Firefox lets you delete all cookies when the browser closes. That suits me, not least because I tend to leave tabs open.
Re: Reject all
Bob on. EVERY DAY. Delete all your cookies EVERY DAY.
It's not a magic fix but it makes it harder for them.
Every day. All of them.
Re: Reject all
Cookie AutoDelete. Available for FF and Chrom*. Nuff said.
Re: Reject all
Honestly, I bet that they feel allowed to reinstate those cookies as soon as you connect again if you've not explicitly rejected them. They're good at browser fingerprinting, and in addition to home IP addresses being very static nowadays, it's easy enough for them.
Re: Reject all
Apart from the last part about manual exclusion you just described private browsing mode.
Re: Reject all
You want "save cookies for this site, but scrap them when the tab is closed". Install [1]cookie autodelete which does just that.
[1] https://addons.mozilla.org/en-GB/firefox/addon/cookie-autodelete/
Re: Reject all
I see quite afew sites that don't have a reject all button, have a few basic on off buttons and then hidden away in the 'our partners' section, dozens of legitimate interest buttons.
I just reject the entire site as it is obvious they have less interest in doing business with me than taking and selling/sharing my data.
These sites have a standard format that somebodyhas sold them, so now the moment that box appears, I go elsewhere.
Re: Reject all
I am wasting years of my life with this crap
Countless years of human effort are lost to this crap. I accept all cookies. My only browser extension is "I don't care about cookies" which at least stops some of the crap. As I've said before I wish there was a browser setting I could set to take me back to those happy and productive days when I didn't need to choose cookies to accept or agree to privacy policies before being able to do anything productive.
Re: Reject all
I also use the "I Don't Care About Cookies" add-on to ignore/auto accept cookie requests, but I use it in conjunction with the "Cookie AutoDelete" one. So, while I may accept all cookies, they are purged after I quit the site. Maybe they still keep some identifying data on their side or some persistent stuff on mine, but, with the help of NoScript and uBlock Origin I feel I have my back pretty well covered. Am I missing something?
A Google spokesperson said...
"People trust us to respect their right to privacy and keep them safe...."
They what?!
I rather think that most people either A) don't realise how much G invades their privacy or B) regard them as a necessary evil to get stuff done on the great wide interwibble.
Re: A Google spokesperson said...
Or C) Avoid them like a syphalitic sex toy...
Re: A Google spokesperson said...
D) Regard them as evil.
Yes I do use Google search. Yes I do have an Android phone. That is as far as I'm willing to go.
I still don't consider Google a 'necessary' evil, just evil.
But not as evil as Zuck. I will not use his companies' products ever.
Re: A Google spokesperson said...
hrhr Iron. Search and Android. That's like 90% of your digital intent, fingerprint and private details.
Re: A Google spokesperson said...
A Google spokesperson lied would be both more accurate and save copious data transfers.
It's not enough
When countries start issuing the multi-billion fines that Facebook deserve for their advertising practices, then we'll talk. There is no rule that they won't break, no invasion of privacy they won't make, if someone has paid them to force an advert on you. They'll show you adverts for things that are forbidden by their own rules - and in some cases, international law - from companies that you have blocked. They'll even cancel your decision to block a company, literally unflagging a setting and acting like you never set it.
Re: It's not enough
I don't think fines are the right solution. Mainly because they can just become cost of sales and probably expensed.
A simpler solution should be to just adopt the same tech utilised to monitor other home invaders. So fit all C-level execs involved in privacy invasion with ankle tags. Then for every type of data slurped, publish that under each execs corporate bio page. Add say, 10yrs in jail for any attempt to avoid publication of their 'private' information.
It may just be a way to administer a clue-bat, although may require building a few more prisons.
Re: It's not enough
Then how do you pay for the sites?
Obviously all TV should have a menu where I have to select seeing adverts, and it's only fair that the default must be no ads, but there must also be no licence fee.
Rofl
Why don't they just ask nicely* instead of imposing ludicrous, unlawful fake penalties that will never be paid and are completely unenforceable?
[*If the ICO asks nicely, you still have to comply.]
Oh yes, because it's just political grandstanding.
I agree that wrist-slaps are deserved by companies who make it too hard to opt out, but this is silly.
"...ludicrous, unlawful fake penalties..."
Unlawful? Who says?
It's the French imposing this fine for activities conducted on French soil so unless the US and France have a secret treaty which says that US companies only answer to US law when ever they conduct business in France then the fines are lawful.
As for ludicrous, well if Google wants to play on French turf then they must accept French rules, and if they don't they either pay up or leave.
I have no idea if you are a US citizen but a world exists outside the US with their own laws and sovereignty.
Oh, you can be sure that Google and Facebook are paying these fines. It's not much for them, and that is fine, considering the issue is not so important. But they are paying.
We French have a saying: «nul n'est censé ignorer la loi».
That particularly applies to company who literally spend millions paying lawyers.
The CNIL even conveniently published a how-to describing the rules, with pictures, that many websites with much less income than Google managed to understand :
https://www.cnil.fr/fr/cookies-et-traceurs-comment-mettre-mon-site-web-en-conformite
So arguing that Google is still too new at the World Wide Web thingy, had no idea they could search the internet to find that information and needed somebody to come hold their hand to guide them, that's unlikely to work.
Can I piont out that is takes two clicks here to reject, but one to accept as well.
The flow here is much, much better though: the reject click locations are not intentionally spaced to make it more difficult. Unlike Google, which somehow is not able to display 3 buttons on a single screen, and forces to scroll down to reach them all.
Oh thank god.
There are quite a number of sites with a boilerplate list of dozens of trackers and scum, with an easy to use button to disallow cookies except the many marked as "Legitimate interest" that need to be selected one by one by one.
It's horseshit anyway as this boilerplate rubbish always lists the same sites over and over. Forget one, and I'm pretty sure they'll accept that as given consent over and above the many times you've said get lost.
But, yes. Accept all needs a corresponding Reject all.
All websites (including this one) should have a one-click policy to allow or reject cookies. Period.
Anything else is a weaselish tactic to try to get personal data from users.
This site is one of the rare ones that, when you ask to check which cookies are enabled, only list essential cookies as on - the rest are unchecked.
So El Reg is a step above many others in this regard.
Editor should be half spanked then ^^
Bring back the..... Moderatrix!
My experience is that a large number of German and Scandinavian sites have either a “reject all” or “only necessary “ button. UK and Iberian sites you often have to switch off by category, and with US sites you consider if it really is that interesting.
Similarly, I often find settings mostly off in the first group and everything on in the latter.
CookieAutoDelete is my friend.
I wonder if it would be technically possible for a browser extension similar to Ublock origin to be developed that can automatically reject none essential cookies for you, rather than have to manually wade through loads of options?
Opt in
Necessary cookies (logged in etc) - you don't need to tell anyone but can if you want.
All others: opt in.
Not an opt out, no matter how few clicks implment it.
Re: Opt in
Brilliant idea, mate!
I can't wait for page after page of opt-in before being allowed to even glance at the site.
I would say that 90% of the cookie opt-in procedures make it much easier to opt-in than opt out. There should be three options on the dialog:
1. Opt-out - (May provide a warning that things might not work properly)
2. Opt-in Fully (Should indicate what you are getting yourself into)
3. Opt-in to cookies used for distinct reasons - this should provide a method of selecting cookies used for website operation, marketing cookies, performance measurement cookies, ...
Anything other than this is an attempt to get consent for marketing cookies.
Funny ...
that only FB and Google are fined.
Because, every single french newspaper site is exactly like FB and Google, as far as cookies go. Plus thousands of other french sites, of course.
But probably it's better seen, politically, to fine FB and Google, rather than Le Parision, Media Part, Le Monde etc ...
Re: Funny ...
That's the danger of using fines as an alternative to tax for multi-nationals. It becomes very political which companies get asked for money, and the reprisal sanctions tend to hit a lot of bystanders
Saying "no cookies" involves setting a cookie
A site has to store the fact that you've said 'no' to cookies, which it does by ... storing a cookie.
Sites should have a standard query string which specifies the user's choice without using cookie storage. This would avoid those of us who delete cookies on browser exit having to go through the preference rigmarole _every single time_.
Good for France
Bloody good on ‘em for actually doing something about this glaringly abusive behaviour.
Why it has taken so long (when did the cookie law come in???) is anyone’s guess but still a good move
No cookies for the French
Let them eat cake.
But it's in their "legitimate interest"