Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is only one choice being expressed by either protocol. One against data collection, the other against the sale of collected data.

DNT has legal standing in the EU, GPC has theoretical legal standing in the USA, where laws are more geared towards protecting data brokers. Removing a protocol because it doesn't work in the USA despite it being a legal opt-out in the EU is foolish; just send both headers, let local jurisdiction pick the which one is legally binding and which one can be ignored.

GPC has been standardised to never make it extendable beyond "Sec-GPC: 1" so there is no way for it to imply a set of choices in the future, without breaking backwards compatibility. The choices are limited by design.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: