Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’d have to read this specific decision but my opinion is that while the GDPR says the user can refuse consent “by automated means” it doesn’t specify what those means are, thus making it quite hard to follow, enforce and therefore likely that other courts will decide differently on similar cases. E.g. would my own “X-Tracking-Is-Stupid: don’t track me” header be valid as refusing consent? What if I add it as a query parameter in the URL? And so on - DNT is not special in the eyes of the law.


DNT is both common practice and a documented standard; the law will take both these into account in judging it vs `X-Tracking-Is-Stupid`.


I disagree that it’s common practice or standard. The W3C never even standardized it, mainly because of low adoption: https://github.com/w3c/dnt/commit/5d85d6c3d116b5eb29fddc6935...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: