3 ms·
I'm a privacy lawyer at a multinational company that has dealt with cookies for years. I created an account because none of the responses to you are correct. Th
by privacylawthrow 6y ago
I'm a privacy lawyer at a multinational company that has dealt with cookies for years. I created an account because none of the responses to you are correct. The ePrivacy Directive was not replaced by GDPR and cookie rules do apply to first party cookies.
We ended up with cookie rules because regulators were concerned about the use of cookies to create user profiles based on activity across multiple websites, especially for "evercookies"/"zombie cookies" where a user's cookieID would be resurrected even after a user deleted them. Instead of banning zombie cookies or cross-site tracking, the EU instead decided it was a violation of user privacy to place any cookies or other data files on the user's machine without their consent.
The actual language is "Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information."
Cookie consent boxes are implemented at the website level because the law applies to website publishers, not browser makers. Website publishers were explicitly told that they cannot rely on a user's browser settings. This put the browsers in the back seat and ended up with today's world where you have to opt out of a service provider like Google Analytics on a site-by-site basis.
The vast, vast majority of users do not touch cookie settings. There are probably more users running scripts to disable cookie popups than there are users opting in or out of specific cookies.
It is an odd world where websites bend over backward to make cookie popups that actually work knowing full well users do not care. The average user doesn't really know much about cookies, much less the wide variety of activities powered by cookies. Cookie consent popups are publicly available, making them easy targets for regulatory audits. Ireland ran a huge sweep and sent out letters to a number of large companies telling them to clean up their act by October or else. We are a few weeks away from seeing what the "or else" will be.
I'm happy to answer any other questions you have on this.
- ryandvm 6y agoThank you for the fantastically detailed response. That actually does explain how we ended up her.
- AlexanderZ 6y agoSo what does the real minimal setup look like? Will text ("This website uses cookies") + a button ("I agree") work?
- privacylawthrow 6y agoNo because that's not informed consent. Different countries have different requirements, so the minimum varies by country, but all countries require some level of information about cookies for the consent to be "informed". At a minimum you'd need to link to more information about what cookies are and how they are used. If the cookies do not involve personal data, then GDPR does not apply, and a popup/pushdown/modal with text, a link, an accept button, and a reject button is all you need. If the cookies do involve personal data (e.g., IP address), then GDPR applies. For cookies where GDPR applies, the legal requirements depend on the purpose for using the cookie. Wach purpose for using cookies requires its own consent. For example, cookies used for analytics require separate consent from cookies used for third party advertising. If a website only used cookies for a single purpose, the consent window could be pretty small. If there are multiple purposes, it's basically going to be a privacy policy just for cookies. There are several billion dollar lawsuits against online adtech because it's not clear under GDPR whether anonymous but unique cookieIDs are personal data. If they are, the entire industry violates GDPR.