Remix.run Logo
otterley 3 hours ago

I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.

> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.

I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.

IsTom 3 hours ago | parent | next [-]

EULAs are restricted in power in EU and at least to me these cookie banners are similar in spirit.

tempestn 3 hours ago | parent | prev | next [-]

"I didn't read it," sure. But, "A reasonable person would not read it?"

ChadNauseam 2 hours ago | parent [-]

Why would a reasonable person not read it?

I just visited theguardian.com to see their cookie banner. The banner says this:

> Your Privacy (`x` button to close the tab)

> US residents have certain rights with regard to the sale or sharing of personal information to third parties.

> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.

> You can opt out of the sale of all of your personal information by pressing

> <button>Do not sell or share my personal information</button>

It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.

preg_match 2 hours ago | parent | next [-]

> Why would a reasonable person not read it?

Because this is there 1 millionth cookie banner, because every site and their momma has one.

Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.

troupo 2 hours ago | parent | prev [-]

This is indeed a rather good implementation of ehat GDPR requires: clear unambiguous language, an opt-out available immediately.

This is the definition of informed consent

jkaplowitz 8 minutes ago | parent [-]

The GDPR doesn’t allow opt-out consent to count as consent. The only consent it recognizes as valid consent is opt-in.

However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.

tacitusarc 3 hours ago | parent | prev [-]

But it is complicated, no? Even if you click you agree, if the you thought you were agreeing to one thing but actually agreed to another because they buried the lede, “I didn’t read it” is a reasonable defense.

SiempreViernes 2 hours ago | parent | next [-]

Why would you claim the false "I didn't read it" ahead of the true "I read it but understood it differently"? The latter allows for adding the fault shifting claim "because the other party wrote it deceptively", while "intentionally didn't read" makes it much harder to blame the other guy.

otterley 2 hours ago | parent | prev [-]

It just won’t fly in court. Full stop. There are perhaps other defenses to be raised, like unconscionable terms, but not that one.

ferngodfather an hour ago | parent [-]

It really depends on the term they're trying to rely on. We have the "red hand rule" in England and Wales that means that unusual and onerous terms will not be incorporated unless it can be expressly shown they were fairly brought to the parties attention.