Thread · 2 tweets · 31 Jan 2023

Replying to @RobertJBateman and @hemanthkumarak, @siobhansolberg

So load-balancing counts; DDoS prevention is more complicated as you point out, however if I were someone's privacy person I'd point out that security measures that are defeated by the refusal of consent are useless and be prepared to make the case.
Basically, if the third party is a processor, has good protection measures, limited collection, short retention, etc. and if the threat is real then I'd be comfortable with it — even though those cookies are likely to be fingerprinting. But yeah, it'd prolly scare the lawyers :)
↺ 1