| ▲ | amiga386 2 days ago | |||||||
If you're in a shopping site and "add to basket" -- explicity requested. If each page you browse on the shopping site shows what's currently in your basket -- explicitly requested. If you checkout and get a list of what's in the basket and give you card details for payment and email for receipt -- explicitly requested. No consent needed. On the other hand, deliberately analysing log data after the fact for which products they looked at but didn't add to cart -- consent needed. Javascript measuring which sub-parts of the page they lingered on -- consent needed. Tracking how often they come back without buying anything -- consent needed. Using the email address for anything other than order receipt and delivery status -- CONSENT VERY MUCH FUCKING NEEDED. See the difference? | ||||||||
| ▲ | brainwad a day ago | parent [-] | |||||||
Dropping permanent cookies for any of this stuff is not strictly necessary; session cookies would be sufficient, so then to do anything convenient (e.g. persistent cart, Amazon-style) but not necessary you still need to request consent. GDPR's legitimate interest basis is better written. But ePD is not superceded by GDPR, they are layered on top of each other. | ||||||||
| ||||||||