3 ms·
Have you read what the directive actually says? It exempts pretty much all reasonable cookies: you don't need to inform your users about login cookies, session
by msl 9y ago
Have you read what the directive actually says? It exempts pretty much all reasonable cookies: you don't need to inform your users about login cookies, session cookies or user settings cookies [1]. There are other types on the list too. Check it out, it should not take you more than a couple of minutes. The only missing type of cookie that I can imagine is one designed to track people in the long term (longer than a session) without their knowledge. Does it really sound that stupid?
[1] http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
- fauigerzigerk 9y agoThe law was well intentioned but completely ineffective. I think it should be scrapped now that GDPR offers far more meaningful protection for consumers.
- zxcmx 9y agoYep, but if you have analytics (or like 20 different analytics providers!) then you should include the warning. That is most sites now, so cookie warning fatigue sets in. I think the law was well intentioned, but it didn't quite manage to do what it was trying to do.
- BjoernKW 9y agoThe rule of thumb with these regulations unfortunately for the most part is: Better safe than sorry. These regulations tend to get abused by shady lawyers who specifically target small business that supposedly don't comply with the rules. The same kind of reasoning for example applies to the notorious legal notice requirement for websites in some EU countries: The exact requirements for these documents are still not entirely clear. People and companies go to great lengths to implement (hopefully) legally compliant legal notices for their website while many of them are really just cargo cult intended to appease powers beyond one's control.
- SyneRyder 9y agoI tried clicking on the link to their PDF of exemptions - it is no longer available. The actual ePrivacy Directive 2002/58/EC Section 25 does not mention exemptions for any type of cookies, and specifies: "Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment." http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32002L0058:EN:HTML http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...