British data watchdog brings cookies to G7 meeting – pop-up consent requests, not the delicious baked treats
- Reference: 1631017219
- News link: https://www.theregister.co.uk/2021/09/07/ico_cookies_g7/
- Source link:
The ICO said it would call on fellow G7 data protection and privacy authorities – three of which used to be its fellow EU member states – to work together to overhaul cookie consent pop-ups to make people's privacy "more meaningfully protected" and help businesses offer "a better web browsing experience."
G7 members' current stances on cookie consent
United States: Does not require consent for cookies, though [1]has data protection laws for under-13s
[2]Canada – no specific cookie consent pop-ups are required. Online data protection governed by Canada's Anti-Spam Law (CASL) which deems in many cases that it is "reasonable" to assume consent pop-up cookie consents,
[3]Japan: – amended its Act on the Protection of Personal Information in June 2020 to include cookie consent,
France: Governed by EU's [4]ePrivacy Directive ,
Germany: Governed by EU's [5]ePrivacy Directive
Italy: Governed by EU's [6]ePrivacy Directive
UK: Governed by EU's [7]ePrivacy Directive (from 2012 onwards) - currently via the [8]Privacy and Electronic Communications Regulations .
Information commissioner Elizabeth Denham, who is set to chair today's virtual meeting of G7 data protection authorities, plans to present an idea on how to improve the current cookie consent mechanism, making web browsing smoother and more business-friendly while better protecting personal data, an official statement said.
People automatically select "I agree" when presented with cookies pop-ups on the internet, she argued, so they don't have meaningful control over personal data.
Denham, whose role is to uphold information rights in the public interest, said the "cookie mechanism is also far from ideal for businesses and other organisations running websites, as it is costly and can lead to poor user experience."
[9]
The EU's ePrivacy Directive, transposed into UK law since 2012 via the Privacy and Electronic Communications Regulations (PECR), states that no cookies and trackers must be placed before prior consent from the user, besides those necessary for basic website function.
[10]
[11]
Denham called on her G7 colleagues to use their convening power to engage with technology firms and standards organisations to develop a coordinated approach to this challenge.
The current ICO is to be replaced by New Zealand Privacy Commissioner John Edwards, the British government's preferred candidate to become the UK's next Information Commissioner.
[12]Google updates timeline for unpopular Privacy Sandbox, which will kill third-party cookies in Chrome by 2023
[13]Google has second thoughts about cutting cookies, so serves up CHIPs
[14]ALPACA gnaws through TLS protection to snarf cookies and steal data
[15]Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins
At the G7 meeting, the ICO will present its vision for the future, where web browsers, software applications and device settings allow people to set lasting privacy preferences of their choosing, rather than having to do that through pop-ups every time they visit a website. It said this would ensure people's privacy preferences are respected and the use of personal data is minimised, while improving users' browsing experience and removing friction for businesses.
Responding to the ICO's call, Jim Killock, exec director of Open Rights Group, said: "The simple fact is that most cookie banners are unlawful, and the data collection behind them is, as her own report states, also unlawful. "If the ICO wants to sort out cookie banners then it should follow its own conclusions and enforce the law.
[16]
"We have waited for over two years now for the ICO to deal with this, and now they are asking the G7 to do their job for them. That is simply outrageous.
"We fully support their call for automated signals, but meantime they should enforce the law, which is their job."
Chip off the old block
Coincidentally, cookies were also high on the agenda for a recent report penned by a government task force and endorsed by the UK PM. In the report, lead author Iain Duncan Smith claimed an "overemphasis on consent" led to "people being bombarded with complex consent requests."
[17]Euro commissioner tells Facebook it has nowhere to hide
[18]Privacy watchdogs: Silence isn't cookie consent
[19]A month to go on Cookie Law: Will Google Analytics get a free pass?
[20]EU's top court says tracking cookies require actual consent before scarfing down user data
Cookies also topped the agenda for the [21]proposed shake-up to data laws announced by UK Digital Secretary Oliver Dowden last month.
In a Telegraph interview, under the heading "Creating our own data laws is one of the biggest prizes of Brexit", he said that many cookie pop-ups were "pointless" and should go.
"No thanks, EU! Hated rules SCRAPPED as UK to end 'pointless' web cookies in Brexit bonfire," crowed the headline in the pro-Brexit Daily Express .
[22]
Quite how the new laws are squared with the need to maintain the EU's "adequacy" ruling to allow cross-border data sharing is a moot point.
But after a bad run in Afghanistan, and facing down COVID-19 and post-Brexit supply chain disruption, Boris Johnson's government could do with a distraction. Seeming to do something about those pop-ups that represent the pinnacle of first-world problems might play well with the newly found Red Wall constituents as well as the disgusted from Tunbridge Wells brigade. ®
Get our [23]Tech Resources
[1] https://www.termsfeed.com/blog/cookie-consent-outside-eu/#:~:text=Essentially%2C%20the%20US%20does%20not,children%20under%2013%20years%20old.
[2] https://www.dlapiper.com/en/canada/insights/publications/2020/04/website-cookies-in-canada-is-consent-required/
[3] https://www.dataguidance.com/notes/japan-data-protection-overview/
[4] https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32002L0058
[5] https://www.theregister.com/2011/12/15/ico_cookie/
[6] https://www.theregister.com/2011/12/15/ico_cookie/
[7] https://www.theregister.com/2011/12/15/ico_cookie/
[8] https://ico.org.uk/for-organisations/guide-to-pecr/what-are-pecr/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YTeMvp4u-tpNtzOyZnfylgAAAAE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTeMvp4u-tpNtzOyZnfylgAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTeMvp4u-tpNtzOyZnfylgAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2021/07/26/google_privacy_sandbox_roadmap/
[13] https://www.theregister.com/2021/07/02/google_cookie_chips/
[14] https://www.theregister.com/2021/06/10/alpaca_tls_protection/
[15] https://www.theregister.com/2021/04/13/cracked_copies_of_microsoft_office/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTeMvp4u-tpNtzOyZnfylgAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[17] https://www.theregister.com/2011/06/21/viviane_reding_interview/
[18] https://www.theregister.com/2010/06/28/cookie_directive/
[19] https://www.theregister.com/2012/04/05/eprivacy_directive_web_analytics/
[20] https://www.theregister.com/2019/10/02/cjeu_tracking_cookies/
[21] https://www.theregister.com/2021/08/26/uk_privacy_law_shakeup_information_commissioner/
[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTeMvp4u-tpNtzOyZnfylgAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[23] https://whitepapers.theregister.com/
Just ban third party tracking
Unfortunately, first party tracking can be just as intrusive. All a first party needs to do is share the data with third parties having gathered it via first party cookies.
Re: Just ban third party tracking
So the first party can sell the data to anyone they met at a party
Just ban tracking. Full stop.
There, fixed that for you. =-j
Tame data commissioner enacts performative cookie banner removal request to wow domestic audience
... while Whitehall gets on with chipping away at the real data protection (UK-GDPR).
It would be more convenient for the UK ruling junta if the banners go before UK-GDPR does, because otherwise people might think something is amiss if the UK-GDPR underpinnings disappear and banners for sites hosted in the UK change to "All your data are belong to us and anyone we sell it to [ACCEPT]".
If this quote is accurate...
"No thanks, EU! Hated rules SCRAPPED as UK to end 'pointless' web cookies in Brexit bonfire," crowed the headline in the pro-Brexit Daily Express.
...they think it's the EU imposing the cookies, and yet brexiters get annoyed when people call them stupid.
>>If this quote is accurate...<<
It's likely as accurate as any other wildly biased tabloid press output, they're just looking for attention and trying to wind up grauniad readers with foaming at the mouth headlines.
Realism please
" [a] future, where web browsers, software applications and device settings allow people to set lasting privacy preferences of their choosing, rather than having to do that through pop-ups every time they visit a website "
Given the criteria for exemption from cookie consent it's hard to see how automation could be made to work at all. They have nothing to do with readily testable attributes such as origin or persistence, for example, but are based on necessity for provision of the service:
the cookie is for the sole purpose of carrying out the transmission of a communication over an electronic communications network;
or
the cookie is strictly necessary to provide an ‘information society service’ (eg a service over the internet) requested by the subscriber or user. Note that it must be essential to fulfil their request – cookies that are helpful or convenient but not essential, or that are only essential for your own purposes, will still require consent. [ICO Guide to PECR].
I for one can't see how the distinction between such cookies and all others could possibly be made by a web browser or client side app as it can have no insight into the provider's service architecture or corporate purposes.
Consequently the almost certain outcome of any proposals will tend towards weakening the control folks have over cookie based data slurping. Indeed the Ministerial foreword to the currently open DCMS consultation on Digital Regulation states " we will take an unashamedly pro-tech approach ". Which of course in reality means "pro tech-corporate approach", so goodbye privacy for those of us who care.
Re: Realism please
The law doesn't mention "cookies". It mentions tracking technologies.
Cookes to record the contents of your shopping basket or your login credentials are fine. You don't even need to ask for consent for them.
It doesn't have to, the browser just sends a 'no ad cookies' request to the site and it's up to the site to obey. The browser doesn't enforce the site behavior anymore than the popup banner does.
What the ad men are afraid of is no one is going to click yes to a simple 'do you want spam' option when they install the browser, even if they would click 'accept all cookies' rather than navigate a 10page preference page at a every site
Maybe we could call it a DO NOT TRACK header? You know like the one all websites ignore anyway.
Been there, tried that, it did not work.
Definition of a cookie
Many people know about cookies but are unaware of other means of tracking a browser or user. So, for the purpose of this review, a cookie should be defined to include: local storage, browser fingerprinting, etc.
Different sorts of cookies need to be understood: cookies from the site that you visit are very different from 3rd party ones. Session cookies (short term ones that tie together pages visited over 1/2 hour or so) are different from ones that survive over weeks & months.
Opting out should be no harder than opting in. Some web-sites or apps have opt-in with one click, to opt-out you need to click every type of opt-out.
The review should be about (mobile 'phone) apps as well as what happens via a web browser.
Web sites should list every cookie that it (any any 3rd party) sets and say what it is used for.
You should be able to opt out of every sort of cookie - with the exception of session cookies.
Re: Definition of a cookie
Hasn't someone - apple, maybe ? - made their browser partition data by website so that the only cookies available were set in that site's private universe ?
What's needed is something like a legally binding form of the Do-Not-Track flag, but considering the vast majority of cookie "consent" pop-ups violate GDPR by not making "Reject All" as prominent and easy as "Accept All", seemingly with no consequences this far, I don't have high hopes.
We already have the ability for "web browsers, software applications and device settings allow people to set lasting privacy preferences of their choosing"
It is called the "Do not track" header.
> People automatically select "I agree" when presented with cookies pop-ups on the internet, she argued, so they don't have meaningful control over personal data.
"People" may do that but I don't. I click REJECT ALL and if that option doesn't exist I close the window.
But then I also do wierd things like read what is written on the screen rather than blindly pressing buttons like a toddler on a sugar rush.
I click reject all as well. What pees me off is people like ziff davis who re-ask the question REPEATEDLY on the same page. and again when you restart the browser. I'd think a cookie saying 'I do not want all this tracking' would be within the letter and spirit of the law, rather than just the letter as currently.
Just ban third party tracking.