4 ms·
As a European who had to make sure the provisions contained in this law were implemented on a few high-traffic sites targeting consumers, I can definitively say
by crivabene 9y ago
As a European who had to make sure the provisions contained in this law were implemented on a few high-traffic sites targeting consumers, I can definitively say that the law is at least a little bit "controversial" and unclear. We had to request the assistance of a law firm to make sure we complied.
Originally it looked like you had to give the users an option to decide if they allow the use of tracking cookies or not, potentially having to deal with NOT pushing such cookies in case the user did not consent. In reality, most of the implementations I've seen are just informing the customers that tracking cookies are used and let them know that usage of the site represents consent of such usage, adding that they can modify the browser preferences if they want to modify their cookie preferences. Additionally, you have to link to a cookie policy that you publish on the site.
As a clarification, this law does not apply to cookies in general: certain cookies, sometime referred as technical cookies (e.g. session) are exempted as long as they're not used for tracking purposes.
- stephenr 9y ago> As a clarification, this law does not apply to cookies in general: certain cookies, sometime referred as technical cookies (e.g. session) are exempted as long as they're not used for tracking purposes. That's good to know. Any chance you know/can link to the specific section that makes that exemption?
- simooooo 9y agoWhich is a bit silly as it's a tracking cookie by default
- stephenr 9y agoI understand their point - a cookie can be used purely for a session ID, without using it to track the user for other purposes (e.g. a cookie unrelated to the session could be used to track which pages the user visits, regardless of whether there're logged in)
- crivabene 9y agoHere's an excerpt taken from the EU Internet Handbook [0]: Cookies clearly exempt from consent according to the EU advisory body on data protection- WP29 [1] include: - user‑input cookies (session-id) such as first‑party cookies to keep track of the user's input when filling online forms, shopping carts, etc., for the duration of a session or persistent cookies limited to a few hours in some cases - authentication cookies, to identify the user once he has logged in, for the duration of a session - user‑centric security cookies, used to detect authentication abuses, for a limited persistent duration - multimedia content player cookies, used to store technical data to play back video or audio content, for the duration of a session - load‑balancing cookies, for the duration of session - user‑interface customisation cookies such as language or font preferences, for the duration of a session (or slightly longer) - third‑party social plug‑in content‑sharing cookies, for logged‑in members of a social network. [0] http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm [1] http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf http://ec.europa.eu/justice/data-protection/article-29/docum...
- stephenr 9y agoHmm, interesting to note that it doesn't allow for long-lived 'remember me' style cookies without the notice.
- ge96 9y agothanks a lot, this is very helpful/enlightening.
- deleted 9y ago[deleted]