4 ms·
"You DON’T need consent for: First-party cookies used just for your own analytics (in most cases)" They claim that, but the page they link to as the source say
by buzer 9mo ago
"You DON’T need consent for: First-party cookies used just for your own analytics (in most cases)"
They claim that, but the page they link to as the source says "You must...Receive users’ consent before you use any cookies except strictly necessary cookies.". So what exactly makes them think that first-party analytics cookies are "strictly necessary"? The Mastodon link in the at the start of page doesn't seem to work.
- gamblor956 9mo agoExactly. Analytics is one of the types of data for which permission is explicitly required. Session auth cookies are the only ones the EU considers strictly necessary.
- latexr 9mo ago> Session auth cookies are the only ones the EU considers strictly necessary. There are several others which are permissible. The EU has six examples. https://commission.europa.eu/resources/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources/europa-web-guide/desi...
- buzer 9mo agoThis is what European Commission has determined to be acceptable for them. One very important distinction here is, as far as I understand, that EC is not bound by ePrivacy Directive as directives bound member states and require them to include them on their national law. The text on that website does state that some DPAs have found some first-party analytics acceptable, but that's not something that is confirmed by CJEU. And ePD does not have single-stop shop so you need to follow every DPAs directions if you are offering services to that DPA's country.
- deleted 9mo ago[deleted]
- Aloisius 9mo agoCase and point, the EU Data Protection Board has a cookie consent banner and only uses a first-party cookie for analytics. https://www.edpb.europa.eu/concernant-le-cepd/mentions-legales/edpb-cookie-policy_en https://www.edpb.europa.eu/concernant-le-cepd/mentions-legal...
- pas 9mo agothat might be overdoing it. I don't know where is the current case law, but IMHO storing a random number and identifying the retuning user is not PII (to count how many times that user returned). now of course if it gets joined with other data it can become PII. IP address is usually treated as PII, because it can have very high "selectivity" (and with a subpoena can be turned into PII, whereas a site specific cryptorandom cookie id cannot)
- krageon 9mo agoAnyone that says the quote is the case doesn't know what they're talking about. For the love of god, just read the law text :(((