Closed benjaminclot closed 4 years ago
Tagging a few people to help comment on this topic. @bretg @harpere @mkendall07
We could implement some temporary changes to the userId module and the userSync feature to disable the syncs to be on the safe side. May also want to look at this logic for the recent USP/CCPA as well (really to see if it applies, since the default state of consent is different than GDPR).
We will discuss.
FYI - discussions are underway. Will update by Thurs.
@benjaminclot - if you're satisfied that https://github.com/prebid/Prebid.js/issues/4747 generally addresses the issue here, please close this issue and feel free to comment in the other thread. Thanks for bringing it up.
Type of issue
Description
Today, when no consent is explicitly given through an IAB-compliant CMP (e.g. Quantcast) or when consent is "off", data is still being stored on the user device. We are beginning to receive complaints from official government organizations and need a quick resolution so that GDPR is enforced for each and every module.
List of modules that seem to store cookies no matter what the consent is:
Steps to reproduce
Expected results
No data should be stored (or read...).
Actual results
Data (mainly cookies) is stored.
Other information
May be related to issue #4572 ? Should usersync be disabled in the absence of consent?