| ▲ | orwin 11 hours ago | |
> - deny is the default: one button to deny everything but one accept button for every partner Yes, that's in the law. I you do not click on consent, the default is deny everything, and a button to refuse everything should be easy to access. > - making payments for non-tracking illegal In the law too. > - remove or rephrase "legitimate interest" ruling, because providers use that as an excuse to enable everything True, this loophole was introduced by UK/US lobbyists at the time if I remember correctly. My (very small, 3 dev) company at the time worked on health data and managed to find itself in the arcanes of Brussels because anything related to PII security was good news for us. - and probably: prohibit any other dark pattern, or at least make it extremely hard to implement This is the courts who can judge that. The main issue with the gdpr law is local enforcement. It is honestly well written and easy to understand, which is why you have so much legal loopholes, but EU courts are RAI rather than RAW (our fast americanisation is changing that though). | ||