Cookies are an important part of a website’s construct and functionality, but they can also land the website in trouble with GDPR and other Privacy Laws. So what do we need to know about Cookies Consent?
Lets start from the beginning.
What are Cookies?
A Cookie is a small snippet of code left on visitors browser that allows the website to identify the browser during the visit, and/or for future visits.
Why use cookies?
Cookies are used for a variety of reasons. Some are beneficial to the visitors, some critical for the operation of the website, and some are a little sinister!
What are the different types of cookies?
Here are some of the reasons a website might be using cookies:
- Analytics Cookies – Traffic analysis are anonymised, and give an insight to the activities of a visitor on the website, including how the user found the website. These cookies are only used whilst the visitor is on a website, and some have expiry dates in order to recognise a returning visitor. Example: Google Analytics, or other traffic analysis tools.
- Functional Cookies – Functional cookies are similar, but they are important to the functionality of the website. For example, on a e-commerce website, when visitors add a product to their “basket”, cookies are used to remember the items whilst the visitor makes additional purchases. Cookies are also used during the payment process, in order that the website can allocate the payment to the correct basket. Additionally, they can be used in case of connection failure, or a visitor returning to the website later, which means they do not have to start their purchases from the beginning.
- Tracking Cookies – These are the cause of most controversy. These cookies are used to track visitors activities even after they have left the issuing website. This enables the issuing website to track where else visitors have been, what other purchases they have made, etc. These are really the types of cookies that motivated countries to enact legislations in order to protect the privacy of visitors. To put it crudely, these are spying cookies.
What is GDPR?
The GDPR (General Data Protection Regulation) was enacted within the EU in 2016, and was adopted by all EU member states. This regulation is being adapted by other countries outside of the EU, with some modifications, but the essence of this legislation is being replicated in many countries.
What is the essence of GDPR?
GDPR is not limited to the Internet, but here we are only going to discuss its implications for your websites. In brief GDPR has a number of basic objectives including:
- Whatever the purpose of the data being collected, the website must first obtain the consent of the visitor for the data collection.
- The visitor must be informed clearly and specifically about what data is being collected, its purpose, and visitors should be given the option to reject each type of cookies individually (for example Marketing or Tracking, etc.).
- Data cannot be shared with 3rd parties without specific consent of the visitor
- Visitors must be able to check and view, or obtain, what personal data the website has collected, and ask the data to be deleted.
- Personal Data collected must be kept safe, and must be limited to the minimum the website needs to process orders, or transaction.
- Wherever the data is stored, it must also comply with all GDPR data processing requirements.
What is prohibited?
Anything outside of the above is not allowed, but for sake of clarity, these are some of the things you cannot do:
- Blocking Visitors – Websites cannot prevent visitors from viewing content, if visitors reject cookies. Unless of course the website is members only, or applies a paywall to all or some parts of the website.
- Non-Consent Redirect – Website cannot redirect visitors to another website, if consent is not given to some or all of the cookies. We see this a lot, where websites redirect visitors to Google homepage if visitors select “Reject All”. This is not permitted, so stop it now!
- Undeclared Cookies – Websites cannot sneak in cookies that they have not declared, and/or those that visitors have not given consent to.
- Necessary Data – Only request for personal data that is absolutely necessary to process the visitor’s request, and not just because the website owner “likes to know”. (see below)
Where are you allowed to keep the data?
In essence anywhere you like, as long as it is secure and it complies with GDPR data storage rules.
Data must be treated on “Need-to-Know” basis, so a data holder should only collect data that is essential, and should only give access to data to those who need access in order to process the transaction or visitor’s request.
Lets use an example of membership data a website needs to demonstrate “Necessary Date”. In order to process membership, the website needs the email address, phone number, and in some cases payment. So unless the data holder is going to ship something to the member, then there is no need to ask for, or store their address, their date of birth (unless the content or product is has a legal minimum age applied to it).
What are the consequences of non-Compliance?
Extremely painful, as fines can be up to 10 million euros, or up to 2% of its entire global turnover of the preceding fiscal year, whichever is higher.
What are the consequences of a Data Breach?
Putting it mildly it can be ruinous, with huge financial penalties. The fine can be up to 20 million euros, or up to 4 % of an organisations total global turnover for the preceding fiscal year, whichever is higher.
Data must be kept safe with all reasonable security in place, and released on a “need-to-know” basis internally, or externally with consent only. Notification of any breach must be sent as soon as the data holder discovers it, so that the data subject can take remedial action.
Summary
Cookies are important part of functionality of any website, and not all cookies are sinister. Websites must comply with the Cookies Consent process, and all other parts of GDRP regulation when storing and handling personal data.
Do not become complacent and count on being under the radar because you are a small business. A single complaint from a visitor could trigger an investigation or action, so make sure you understand your responsibilities and implement them correctly.
Contact us if you need help with implementing Cookies Consent and responsible management of the data you gather on your website.
