← 返回日报
略读 预计 2 分钟

1,741 "informed" consents with one click? GDPR complaint filed

摘要

noyb 组织向奥地利数据保护机构投诉在线词典 dict.cc,因其 cookie 同意横幅要求用户一键同意 1741 家 “合作伙伴” 访问个人数据,用户即便每份隐私政策只读 6 分钟也要 170 小时才能读完,无法做出知情同意。noyb 认为这违反 GDPR 对同意必须自由、具体、知情且明确的要求,请求删除非法处理的数据并处以罚款。文中指出这是广告行业普遍做法,并列举 repubblica.it、bergfex.de、fifa.com 等类似案例。

荐读理由

如果你做面向欧盟用户的产品,这个案例直接提示 cookie 同意横幅的合规红线:列出上千合作伙伴会让同意无效,可能招致投诉和罚款。同时,它揭示了广告技术行业依赖模糊同意的普遍现状,可作为产品设计时规避法律风险的参考,但具体操作细节(如如何设计合规横幅)并未给出,需要进一步查证。

原文

Cookie Banners

/ 30 July 2026

*Today, noyb has filed a complaint against *the popular online dictionary dict.cc. The GDPR requires that consent is freely given, informed, specific and unambiguous. However, when visiting dict.cc*, users are nudged into consenting to online tracking by a staggering 1,741 (!) “partners” with a single click. This makes it impossible for users to know exactly who has access to their data and how it is actually used. While dict.cc is an extreme example, requests to blindly waive your right to privacy for countless third parties is unfortunately a common issue with websites and apps relying on online advertising, even 8 years after the GDPR came into force.*

noyb complaint against dict.cc

Background. Online advertising companies heavily rely on tracking people’s browsing habits, their interests, interactions and whereabouts to show them personalised ads. However, according to EU privacy law, online tracking is illegal by default. Companies must therefore ask for your consent to “waive” your right to privacy if they want to follow you around. That’s why you see consent banners everywhere. The problem is, however, that most of these banners request your consent for hundreds, if not thousands, of online advertising companies that share your data among each other. While this is initially done for invasive online advertising, data is often also shared and sold by data brokers for other purposes. Even law enforcement agencies from both democratic and authoritarian governments buy such data for surveillance purposes.

**Uninformed consent. **dict.cc’s consent request currently mentions 1,741 “partner” companies that would be granted access to the device and the personal data of users. Reading all of their privacy policies would at least take 170 hours (even if you just scan each policy for 6 minutes). That is more than an entire week for one single consent request. In addition, these “partners” often say that they forward your data even further. For the complainant, as well as for other website users, this makes it practically impossible to understand the consequences of their “consent”. This common practice (see e.g. www.repubblica.it, www.bergfex.de, www.fifa.com) makes obtaining an “informed consent”, as required by the GDPR, essentially inconceivable.

Felix Mikolasch, data protection lawyer at noyb: “It would take days or even weeks to properly read and understand the data protection policies of 1,741 companies. It is ridiculous to assume that this would allow for an informed decision.

Complaint filed in Austria. *noyb *has now filed a complaint with the Austrian Data Protection Authority, as dict.cc lacks a valid legal basis for processing the complainant’s data. We request the Austrian DPA to order the online dictionary to delete the unlawfully processed data – and to inform all recipients of the complainant’s data about the deletion. Furthermore, noyb is proposing that a fine be imposed to prevent similar breaches in the future. The Authority may also issue a wider ban or refer the matter to the European Data Protection Board for an opinion, given its general significance.

Martin Baumann, data protection lawyer at noyb: “Consenting to thousands of ‘partner’ companies using your personal data does not only feel wrong, it indeed is. The data protection authority must finally put an end to this practice.”

Hacker News · 151 赞 · 88 评 讨论 → 阅读原文 →

这条对你有帮助吗?