Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This doesn't read quite right to me. Maybe I missed something.

Under the GDPR sites are emphatically NOT allowed to deny service over rejecting cookies.

Iirc the only valid options are providing a paid alternative or blocking service to the entire class of GDPR covered citizens.



Even a paid alternative is very iffy. Some jurisdictions like Germany have allowed it after a court ruling but most have not. Meta is also getting flak from the EU for their "accept or pay" model.


That is not really GDPR. That is the ePrivacy ( ie. The Cookie Law from 2009 ) directive that supplements but sometimes overrules GDPR.

https://gdpr.eu/cookies/ # Cookie compliance




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: