Look, Jeff Atwood, it is difficult to take you seriously when you write authoritatively on a subject you clearly donât understand. GDPR doesnât mandate cookie notices. Cookie notices are *malicious compliance* by the surveillance-driven adtech industry. If youâre not tracking people, you do not need a cookie notice, period.If youâre only using first-party cookies for functional reasons, you do not need a cookie notice, period. If youâre using third-party cookies to track people â i.e., if youâre sharing their data with others â then *you must have their consent to do so*. Because, otherwise, you are violating their privacy. Even then, the law doesnât mandate a cookie notice. How would you conform to EU law without a cookie notice if your aim wasnât malicious compliance?You would not track people by default and you would make it so they have to go your siteâs settings to turn on third-party tracking if, for some inexplicable reason, they wanted that âfeatureâ.Boom!No cookie notice necessary.Whatâs that? But that would destroy your business because your business is founded on the fundamental mechanic of violating peopleâs privacy?Good.Your business doesnât deserve to exist.Because the real bullshit here isnât EU legislation that protects the human right to privacy, itâs the toxic Silicon Valley/Big Tech business model of farming people for data that violates everyoneâs privacy and opens the door to technofascism.https://infosec.exchange/@codinghorror/115120175033311443