Utter props to silktide to pushing this, I feel like half my posts on HN have been about this retarded legislation. Those who misuse cookies will soon use even more insidious means, those who don't are being forced into implementing stupid confusing boilerplate, utterly ridiculous!
Thanks! (I'm the founder of Silktide and author of that rant).
We had some constructive suggestions on what could be done instead, although these are definitely up for debate. The gist would be using a rel element like so:
and then using that as a means of consistently linking to a privacy policy. As a result, policies would have consistent language for users ('look for the "Privacy" link') but could also be detected automatically by browsers or testing tools.
That way you could actually test your site is properly linking to a policy, and users could have browser preferences like "disable cookies until I've seen a policy" or whatever.
It's just an idea but we've implemented it on our sites and will be interested to see what others think:
Until the ICO start taking people to court it will stay ridiculous, but I think the intent of it is important. Using etags to track individuals is really no different to a cookie with a unique ID...
Having a 10 page complaint form is what is dumb. Why can't you just send a suspect URL, then have it scoured for dubious cookies?