Remix.run Logo
jshmrsn an hour ago

Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.

From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).

It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).

Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".

https://gdpr.eu/cookies/

https://wp-gdpr.eu/gdpr-cookie-consent-2026/

https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...

dijksterhuis 15 minutes ago | parent [-]

> (i.e. popups, banners large enough to push users to interact with them, etc.).

"i.e." doing a lot of work there.

GDPR doesn't mention pop-ups or banners. the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites.

for the specific case of websites -- they could have a line of text on saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah".

and i hear HN collectively cry out: "of course they wouldn't choose that! that would be more expensive for them! and no-one would send them a letter! of course they would choose banners/pop-ups over a letter!"

so what? websites choose to implement pop-ups and banners and inflict that on their users.