| ▲ | pie_flavor an hour ago | |
The law does not say 'reasonably expected', it says 'strictly necessary'. | ||
| ▲ | rcxdude 25 minutes ago | parent [-] | |
Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner. What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API), like how this would normally be implemented nowadays, then these requirements don't apply at all. | ||