What are Cookies?
Cookies are small files placed on your device by websites and apps, and are designed to hold a small amount of data specific to your usage of that website/app. This information can be accessed by both parties, and can be used for various reasons including gathering anonymous data but also specifically targeting users.
The theory of GDPR
Last year, the GDPR introduced new privacy rules that specifically pertained to our online world and digital technologies. For example, users must explicitly opt-in to accept things, consent cannot be implied or assumed – therefore, websites and services must not use pre-checked boxes in forms and must ask for consent in order to use Cookies.
At the time this new law came into effect in May 2018, this has a big impact on websites and services – both those who were trying to be compliant and those who perhaps were trying to bypass previous legislation by assuming consent.
However, although the theory sounds relatively straightforward, the reality is much more complex. Particularly regarding Cookies, as they can perform a vast variety of functions. A Cookie that specifically tracks a user for advertising sales is not the same as a Cookie that collects purely anonymous data for tailoring an online service’s performance.
The reality of GDPR
TechCrunch’s report in August said that a lot of the new regulation has been ignored in regards to Cookies. Whether this is purposeful or down to the lack of clarity in the legislation is open to debate.
Most of us remember the tricks more aggressive platforms use where different tick boxes do different things – one has to untick a box to opt-out of email marketing but then, right below that, one has to tick a box to do the same for telephone marketing. And we’ve all probably clicked to dismiss a Cookie notice on a website, without really considering what we are consenting to. Monty Python’s “The Meaning of Life” liver donor scene, anyone?
At the start of this month, the Court of Justice of the European Union (CJEU) clarified some of this regulation by ruling that storing Cookies requires “active consent”:
“EU law aims to protect the user from any interference with his or her private life, in particular, from the risk that hidden identifiers and other similar devices enter those users’ terminal equipment without their knowledge.”
And even more significantly:
“That decision is unaffected by whether or not the information stored or accessed on the user’s equipment is personal data.”
Previously, conditions for consent were interpreted differently across Europe and thus services and websites did not have a clear line to follow. The GDPR is intended to protect individuals’ privacy, but clarity in the legislation is key, and the GDPR is – legally speaking – still a work in progress.
Cookie walls
There is still a question over the legality of cookie walls – Cookie walls require users to accept the privacy usage before they can enter a site/service. If users don’t accept they are forced to leave and cannot use the site/service. The Dutch DPA deemed cookie walls to be illegal earlier this year. However, interpretation here is also vague and thus open to legal challenge. Further reform of this point may be seen after the hearing of related cases by the CJEU.
Summary
The GDPR’s stricter privacy regulations and enforcement in terms of consent are steps in the right direction. Transparency is key to user satisfaction as well as ensuring good practice – and the GDPR is absolutely a step in the right direction on this front. But further definition and clarity is required as to how this actually pertains to real world use cases.
