Consent is now needed to most uses of cookies by UK-based websites.
The law, adopted in May 2011 to implement a European directive, was accommodated by the announcement of a 12-month moratorium on enforcement. Simultaneously with the expiry of the moratorium, the data protection regulator, the Information Commissioner's Office (ICO), has issued revised guidance and has invited web users to inform it of websites that are not yet compliant.
Since May 2011, website operators throughout Europe have been required to obtain consent in relation to most cookies placed on a user's PC (or mobile device) by websites. In recognition of the challenges in moving to a consent regime, the ICO announced the moratorium. (Other countries were simply late in implementing the law change; some have not yet done so.) As this grace period has now come to an end, the Commissioner will be able to look at the impact of any breaches of privacy and other rights of website users in determining whether to take enforcement action. The ICO has announced that it has already written to a number of large organizations.
The new rules — required by a European Directive — are implemented in the UK by means of an amendment1 to the Privacy and Electronic Communications (EC Directive) Regulations 2003 (the PEC Regs). Initial guidance on these rules from the ICO) has now been revised (the ICO Guidance).2
The International Chamber of Commerce has also issued guidance which many website operators will find useful (the ICC Guidance).3
We covered the change in law in our DechertOnPoint of June 2011, but it is timely now to issue a reminder of the requirements and a summary of the ICO Guidance (as updated).
What Is a Cookie?
A cookie is a small file downloaded onto a user's device when the user accesses a website which then allows the website to recognise the user's device. Cookies are used for a variety of purposes such as remembering the user's name (to display when the user visits the website) or remembering the date of a user's last visit.
What Do Businesses Need to Do?
Organisations should now take the following three steps:
- Check what type of cookies and similar technologies are used and how they are used. Businesses should analyse which cookies are used. Many may be redundant and could be dispensed with.
- Assess the intrusiveness of the cookies' use. The more intrusive the use of a cookie is, the more likely it is that it will need to change. ICO advice is that more information and detailed choices will need to be provided to users for more intrusive cookies — for example, cookies that create detailed profiles of an individual's browsing activity.
- Decide the best solution for obtaining consent. There are a number of solutions, some of which are discussed in the ICO Guidance (summarised below). Businesses need to bear in mind that consent does not need to be obtained repeatedly for the same person each time the same cookie is used (for the same purpose) in the future.
Implied consent. The ICO guidance has evolved since May 2011. The latest version (version 3 of May 2012) now contains a greater emphasis on when it may be possible to get "implied" consent; that is, treating the continuing browsing on a website by a user (when there is a prominent enough notice) as that user consenting to the cookies that are then served. This may be suitable when the cookies are not particularly intrusive; and a user must still know that a cookie will be served. Information provided needs to be suitable for the audience.
Functional uses. Collecting information about how people use a site — for example, which pages they visit on a website — still requires consent. (A common technique uses "analytics" cookies, sometimes supplied by a Google tool.) The ICO suggests a solution of footer/header text that becomes highlighted when a cookie is going to be set. This seems to be the approach the ICO has adopted for its own website.
Browser settings. In the lead up to the new legislation, there had been much discussion of browser settings and whether they will be sufficient to indicate consent by only allowing certain types of cookies. The new PEC Regs recognised that browser settings can in some circumstances be used. However, the ICO's and the Government's view was (and remains) that the functionality available through current browsers is not sophisticated enough for businesses to assume consent has been given. The UK government is separately working with browser manufacturers (Microsoft, Google, Apple) to change that position. In the meantime, the ICO is therefore currently advising that consent is obtained in other ways.
Third Party Cookies
A third party cookie is one which a website sets (or allows to be set) on behalf of another business. They are commonly used in online behavioural advertising (OBA) activities. The ICO's view on third party cookies is that "everyone has a part to play in making sure that the user is aware of what is being collected and by whom". If a business uses or allows third party cookies it should do everything it can to help users make informed choices.
There is going to be a phased approach to implementation of the changes. The ICO has stated that if it receives a complaint about a particular website, it would expect an organisation to explain how it had considered the new rules and to show that it had a realistic plan to achieve compliance.
Businesses have had one year to get their cookies policies and procedures in order. Some will not yet have started doing so. A first step is to take stock of what cookies are being used and how intrusive they are. Once this "cookie audit" is complete, businesses can start to think about the best ways to get consent for different uses of cookies. For assistance and further guidance on this process, please get in touch with our named contacts below.
1. The full name of the legislation is the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 (SI 2011/1208) — available at http://www.legislation.gov.uk/uksi/2011/1208/contents/made.
2. Available through http://www.ico.gov.uk.
3. ICC UK Cookie guide (April 2012).
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.