1,741 partners
previously: paleoenshittification and a path to adoption for MyTerms
The European privacy organization noyb has filed a complaint over a common web annoyances. This one is a little more extreme than most: 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed. Who has 1,741 “partners”? Anyway, this claimed “consent” to data collection by all these “partners” is stored in the following TCF string.
CQoKcgAQoKcgAAJAGBENCpFsAP_gAEPgACiQMttR_G__bWlr-bb3abtkeYxP9_hr7sQxBgbIkm4FzLvW7JwGx2EZJAyatiIKmRIAu3DBIQNlHBDURUCgKIAFryDMaE2U4TNKJ6BkiFMZIytQCEhvm4tjeQCZ4ur_9kc0mB-t7dr-2dzyy6hHn3a5fmS1UJSdIYesDfv-ZhOS-9IEd-x8v4v4_EbpEm8eSVn9pGtp4jc6Yns6dBmxt-Tyff6Pn_f71fW7X_ve_n3zv8oXn7rr6-__f3-7___-b_-___b-__7Z_zM_37_v_YMttR_G_9bXlv-bBX4btkOYxf9_gD7sQxBAbIomYFzLqW5IwC32ETJEiaMCIIGRAAo1BBIAEpEBhEREChCIAVLxDsAE0Q4TtIAeBkgDMZYiBQAEhPi4tjWQCZ4Op-dUd0iQ2s5Nr22VyyWbAjn3KteOSVUJicKYMFHetuYhMQ-vIU93RK9otI_MbpEkIYARv9lWpl4TYa4vnKVpqxNeRydMSffdFz3fW7RO3a-91k-uqSV_rb4uXW5m__bNn_f138_f_7Z7_1x-3Zf_f__4AAAA.IMttR_G__bXlv-bb36btkeYxf9_hr7sQxBgbIsm4FzLvW7JwG32EbJEyatiIKmRIAu3DBIQNtHBjURUChKIAVrzDsaE2U4TtKJ-BkiHMZYytQCEhvm4tjeQCZ4ur_90d0mR-t7dr-2dzy27hnn3a9fuS1UJydKYetHfv-ZhOS-_IU9_x-_4v4_MbpEm8eSVv9tWtt4zc64vv6dpuxt-Tyff6f__f73fW7X__e__33_-qX3_r76-___3______f__________9_________4A.f_wAD_wAAAAA
If I visit the site from the complaint using a European VPN endpoint, Yes, I went to that site with VPN to Europe on and ad blocker off, and ended up seeing a gross fungus treatment ad. Yeech. The things I do for privacy research and click the obvious button to make the annoying dialog go away, this is what gets stored in the browser. And no, I won’t say that I “consented” because I’m still not informed enough about this industry to give informed consent in all but a few cases.
But why 1,741 partners? Because of the way that this stuff works in Europe right now.
- A site gets a Consent Management Platform (CMP) – a third party script that powers the annoying “consent dialog”/“cookie banner”
- A person with up-to-date knowledge of the site’s data practices carefully configures the CMP to match the…lol, no, somebody clicks various options in the CMP menu until the errors and warnings stop, which is how you end up with “1,714 partners” and other ludicrous messages to end users.
- When a user visits the site and clicks the CMP “consent” button, the CMP stores a record of “consent.” (This can be in TCF, or in a related format called Global Privacy Protocol that wraps TCF along with other strings that apply to non-EU jurisdictions.)
- Any company that is somehow processing the user’s information has to check the record from step 3.
There’s no step in the process for MyTerms, and the way it’s set up makes it look like a MyTerms check is not needed at all. No decision-maker at the site is going to see any need to get contractual permission to do some data processing that, as far as they can tell, they “already have consent for.” (It’s fake consent because Irish politics, but people settle for it.)
So a way to get more sites interested in MyTerms is something like a step 3.5.
- Detect when a CMP is generating a TCF or GPP string.
- Where the string indicates “consent” to anything that would be disallowed by any of the possible MyTerms contracts that the user has indicated they would accept, modify the string to remove the conflict.
This filtering or masking step is not going to produce as good of a result as a full MyTerms transaction that both user and site participate in, but it at least takes a step to prevent the data practices most inconsistent with the user’s preferences (and safety), and gives the site an incentive to upgrade to full MyTerms instead of just filtered GPP.
Different MyTerms implementations might approach GPP and TCF integration differently.
One possibility is to provide a surrogate script for the CMP and prevent the annoying “consent” dialog from ever showing up.
Or implement the CMP API to provide a filtered result to callers.
I’m sure that other possible approaches exist, too. The only approach to GPP and TCF that I know for sure won’t work is ignoring them.
Related
Toward Harmonizing MyTerms (IEEE 7012) with GPC and GPP by Doc Searls.
Bonus links
Ukrainian Drones Disabled Over 30% of Russian Oil Refinery Capacity — FT by Vladyslav Khomenko. (This is a campaign by a low-budget country that is itself under constant attack from the air, against the largest country in the world. It’s past time to assume that future belligerents will have the option of ending all oil refining and LNG exports anywhere they choose, at relatively low cost.)
I Am Quietly And Perhaps Foolishly Optimistic About The Future Of Video Games Journalism By Luke Plunkett. Just as it was clear in 2006 that paying for magazines was a dying business proposition, even as some clung on to newsstands, so too does it look in 2026 that relying on Google search and online ads to sustain journalism is just as terminal. So while things are currently stuck in this painful limbo, where a handful of old websites are dying while new websites struggle to be born, I think the more success you see from subscription-based publications (like our friends and former colleagues at outlets like Defector, 404, Hell Gate, Rascal and Mothership), the more the idea that quality writing has to be paid for will take root among a wider audience, and a rising tide will start lifting more boats. (fwiw, I’m an Internet optimist too, and I even have a good answer to the question: Where will the money to pay for subscriptions come from?)
The Last Small Step for Art on MetaFilter links to The Last Museum. (Now more than ever there’s no excuse to use a slop illustration for a blog post.)
AI’s finally expensive enough to make Wall Street nervous by Elizabeth Lopatto. (Google management has been used to sitting back and raking in the cash from the network effects of search and anything that can be illegally tied to search—possibly the easiest business model in the world to keep going after someone does the hard work of coding a search engine in the first place. Now they’re trying to sell a high-capex, low-differentiation LLM service. Related: Ben Thompson is wrong: US frontier labs are right to be panicking by Larry Salibra. Take the examples he gives: “Claude Code” and “Codex.” As any reader of Hacker News will tell you, Claude Code is already yesterday….in fact, it’s last week. Yesterday was Codex, and Cursor is ancient history….The situation is the same with non-technical users who are seriously using AI. Today, they’re using Claude Cowork but yesterday they were all using Manus. And before that, they were using Perplexity…Sure, the mass market consumer user who asks “AI” a question a few times a week might have downloaded ChatGPT or Doubao when they first heard of AI and never switched to anything else. But those users usually don’t pay much if anything at all and will hardly bail the labs out of their sinking ships.)