3 ms·
Well, the cookie policies in the EU are sort of weird, but they're not from the GDPR, but from an older directive, 2009/136/EC, the "cookie law". And this direc
by gnud 6y ago
Well, the cookie policies in the EU are sort of weird, but they're not from the GDPR, but from an older directive, 2009/136/EC, the "cookie law". And this directive only uses the word once, in the parenthetical "(such as certain types of cookies)".
Even if you replace cookies with something else (localstorage or whatever), you're still on the hook for all the rules both here and in the GDPR with regards to personal information and informed consent.
Remember that the 'cookie law' says
> Exceptions to the obligationto provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user.
So you don't need a cookie banner for a login session cookie, or a cookie that stores preferences the user actively selected.
But you _do_ need a cookie banner, and a way to opt out, for all kinds of user tracking, both first- and third-party.
Of course, IANAL. Just angry at advertisers for muddying up this issue.