Cookie consent crumbles under fresh UK data law proposals
- Reference: 1655468106
- News link: https://www.theregister.co.uk/2022/06/17/cookies_crumble_in_uk_data/
- Source link:
Also notable is the removal of the requirement for a Data Protection Impact Assessment, as well as a new political direction over the Information Commissioner's Office.
However, Nadine Dorries, the minister for the Department of Digital, Media, Culture and Sport, rejected controversial proposals to [2]remove the right to challenge automated decision-making . Privacy campaigners had said the proposals were "irresponsible" and would make it harder for people to "challenge the government or corporations."
[3]
Meanwhile, one legal firm welcomed the response as the "incremental reform of the current framework" — rather than an entirely new approach to data rights.
What exactly is being proposed for cookies?
UK rules on website and app cookie consent are set to change if these proposals move forward. The government plans new laws to remove the need for websites to display cookie banners to UK residents, permitting cookies and similar technologies to be placed on a user's device without explicit consent.
The proposals — which also apply to apps on smartphones, tablets, smart TVs or other connected devices — advocate "browser-based and similar solutions that will help people manage their cookie and opt out preferences."
[4]
[5]
However, websites must give the web user clear information about how to opt out of having cookies set.
"The government will work with the industry and the regulator to ensure technology is effective and readily available so people can set their online cookie preferences to opt-out via automated means," the proposals said.
How will it protect users from tracking?
Peter Church, counsel in law firm Linklaters' global data team, said: "The reform of cookie laws is also long overdue given the widespread annoyance caused by cookie pop-ups. However, it's not clear how the new regime will adequately protect individuals from excessive and intrusive internet tracking."
Elsewhere, the government has rejected proposals to remove the right for individuals to challenge automated decisions made about them, a right enshrined in the EU GDPR, a piece of legislation the government had promised to move away from after Brexit.
[6]
"Our proposals retain human review as currently required under Article 22, but will ensure that a data subject has access to clearer safeguards for any significant decision made without meaningful human involvement, potentially to include a justification of how a decision is reached which may enable a data subject to more easily identify how protected characteristics have been factored into a decision," the proposals said.
Church welcomed the move. "It appears the government has pushed back on some of the more radical suggestions – such as replacing the GDPR with an entirely new Framework of Citizen Data Rights," he said.
However, the proposals have alarmed privacy and rights campaigners. Organizations will no longer have to complete data protection impact assessments (DPIAs) before collecting data. Instead, they will have to conduct "risk-based privacy management programme" to "mitigate the potential risk of protected characteristics not being identified."
American cookies Over in the US, aside from the California Consumer Privacy Act (CCPA), the [7]Colorado Privacy Act , and the Children's Online Privacy Protection Act (regulating data collection of users under 13), there are few federal laws and no national laws regulating the setting of cookies on a user's device without explicit consent.
As The Register noted [8]last month , a recent [9]report claims there is little appetite among lawmakers for data privacy laws more generally, a situation news non-profit group The Markup – which wrote the report – ascribes to the fact that corporations hire lobbyists and law firms to "defang or drown state privacy bills."
Data protection consultant Rowenna Fielding warned that the shift away from broader right to focus only on privacy could be a danger to individuals.
"If government's talking about replacing [the DPIA] with a privacy management program, that takes away that enormous requirement to consider holistically what rights might be affected and avoid detrimental impact to them and replace it with a very narrow focus on privacy.
[10]
"This means that there will no longer be a requirement to consider impacts on say employment rights, consumer rights, contractual rights, citizens' rights and so on.
"It is actually extremely disturbing because it indicates that either they haven't understood data protection law at all or they have understood it, and they are derailing the core purpose of data protection which is to protect rights and freedoms.
"They are changing the conversation to reframe it in a very, very narrow sense to be about privacy," she said.
[11]Salesforce touts Google Ads, ecommerce, social media integration for Customer 360
[12]Europe twists YouTube's arm to get better cookie consent popups
[13]Big Tech loves talking up privacy – while trying to kill privacy legislation
[14]UK police lack framework for adopting new tech like AI and face recognition, Lords told
[15]Europe's GDPR coincides with dramatic drop in Android apps
[16]It takes more clicks to reject their cookies than accept them, so France fines Facebook and Google over €200m
The government is also proposing changes to the role of the Information Commissioner's Office, the independent watchdog overseeing data protection in the UK.
Government plans to give itself powers to prepare a statement of strategic priorities (SSP) for the ICO to regard when discharging its data protection functions, despite widespread criticism that this could undermine the independence of the office.
"Given the government's commitment to ensuring the ICO's independence, the SSP will sit below the ICO's primary objective and duties under the UK GDPR and the DPA 2018. While the ICO will be required to respond to the priorities contained in the SSP, the ICO will not be legally bound to act in accordance with the statement. Further, the SSP will be subject to parliamentary approval before it is designated," the proposals said.
Mariano Delli Santi, legal and policy officer with campaigners the Open Rights Group, said the move could expose the ICO to political direction, corporate capture and corruption.
"Worried about the ICO new guidance or investigation? Giving a substantial donation to the party in government will ensure that the Secretary of State takes care of your concerns," he said. ®
Get our [17]Tech Resources
[1] https://www.theregister.com/2022/05/27/big_tech_privacy/
[2] https://www.theregister.com/2021/09/10/right_to_contest_automated_ai_uk_consult/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqylI2xeEeQZ-qAn-N-@xQAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqylI2xeEeQZ-qAn-N-@xQAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqylI2xeEeQZ-qAn-N-@xQAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqylI2xeEeQZ-qAn-N-@xQAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://coag.gov/resources/colorado-privacy-act/
[8] https://www.theregister.com/2022/05/27/big_tech_privacy/
[9] https://themarkup.org/privacy/2022/05/26/tech-industry-groups-are-watering-down-attempts-at-privacy-regulation-one-state-at-a-time
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqylI2xeEeQZ-qAn-N-@xQAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2022/06/09/salesforce_customer_360_update/
[12] https://www.theregister.com/2022/04/21/google_youtube_europe_cookies/
[13] https://www.theregister.com/2022/05/27/big_tech_privacy/
[14] https://www.theregister.com/2022/01/19/uk_police_lack_framework_for/
[15] https://www.theregister.com/2022/05/09/gdpr_europe_apps/
[16] https://www.theregister.com/2022/01/06/cnil_facebook_google_cookie/
[17] https://whitepapers.theregister.com/
Re: Will this current government's blatant corruption ever cease?
Seems that American-style lobbying by the fatass corporations is alive and well in Blighty. (As an American, I apologize...)
Wonder what the quid for this quo was?
Yes, I know that 'quid' is another word for money (the Pound Sterling, IIANM).
Re: Will this current government's blatant corruption ever cease?
Seems that American-style lobbying by the fatass corporations is alive and well in Blighty.
The US didn't invent bribery.
The government plans new laws to remove the need for websites to display cookie banners to UK residents, permitting cookies and similar technologies to be placed on a user's device without explicit consent.
Good. Max Schrems is a pain in the arse and I curse his name every time I have to click yet another consent-to-cookies button before using a website. Today, everybody, I have been searching for "quick drying varnish".
@Ian Johnston
I cannot upvote you enough.
And if you ignore the "click to consent" thing, they just dump the cookies and caches on your machine anyway.
Cheers... Ishy
consent-to-cookies button
Don't blame Schrems for consent-to-cookies buttons. They're illegal too. See https://noyb.eu/en
Straightforward solution
Websites should not be allowed to set any non-essential cookies without the user opting in, nor should they be allowed to put up blocking banners. If they want more cookies they can just have a link to an opt-in page.
Re: Straightforward solution
@Richard Tobin
Absolutely correct. I long ago proposed an approach whereby only strictly essential cookies would be served by default, and web sites wishing to serve non-essential cookies could only do so if the site visitor consented. That would not require a 'pop up' - just a link somewhere on the page that the user could voluntarily follow should they wish to do so.
The 'cookie pop up' has in fact been essentially used as a means of coercion into accepting non-essential cookies, as evidenced by the obtrusiveness of most - to the extent of blocking access to content unless selection is made (thereby encouraging thoughtless click-through). Indeed in several cases I have inspected, the non-essential cookie acceptance appeared to be unchecked (which is lawful) with styles enabled, but was shown to be ticked by default with styles turned off (illegal). And in all cases 'cookie consent' was provided by a 3rd party serve - surreptitiously engineered to favour the site host at the expense of the user.
The legislators never intended for this to be the case
Re: Straightforward solution
Absofuckinglutely spot on.
Why are my choices "accept everything" or "do something annoying". Why was "accept minimal" not mandated as an option, and why was it not made a default? Advertisers might not be thrilled with the current disaster, but at least they've managed to subvert it to the point where we think that the consent process is the problem.
Re: Straightforward solution
"I long ago proposed an approach whereby only strictly essential cookies would be served by default"
There's no such thing as a strictly essential cookie. None of them are essential.
Cookies only exist for two reasons: lazy/stupid web developers and marketing scum.
Any web site that cannot work without cookies is fundamentally broken.
Re: Straightforward solution
Don't be daft. HTTP is stateless - if you want to maintain any sort of state, you need either cookies or session codes in the URL (which don't survive browser crashes, and don't really bring any benefit over a short lived cookie). Without state we lose the ability to log in anywhere. No shopping carts, no web email, even Reg comments. How do you think you logged in to post this as... er, Anonymous Coward? OK, perhaps that's not a great example.
It's the "bad cookies" I think most of us don't want. Unfortunately they're like bad art, tricky to describe up front but I sure them when I see them.
Re: Straightforward solution
"HTTP is stateless if you want to maintain any sort of state, you need either cookies or session codes in the URL"
It's true HTTP is stateless. But that's a different thing. Browsers are perfectly able to maintain state - and do that without cookies.
"Without state we lose the ability to log in anywhere."
Nope. State is not needed to login - unless it's to a fucked up, badly designed web site.
"How do you think you logged in to post this"
By typing the username and password while cookies were disabled. It works just fine.
Re: Straightforward solution
If you have a web site that requires a log in, or a shopping site with a shopping cart feature, then cookies are a reasonable solution.
And by logging in, or adding something to a shopping cart, you should be consenting to cookies for those purposes.
But most sites shouldn't need cookies.
Re: Straightforward solution
Any web site that cannot work without cookies is fundamentally broken
If you have a website that uses some combination of identification, authentication and authorisation, you need somewhere to store the token(s) that represent your present authentication status and level of access. You can of course encode that in a URL, but it makes bookmarking a bit of a pain and it simply turns your browsing history into a cookie jar by another name.
The real issue is with cookies belonging to a domain other than the page origin and, whereas it might be attractive to block them completely, as long as you accept the need for websites to have multiple IP addresses (load balancing, redundancy, CDNs...) there will always be DNS games you can play to at least partially circumvent the block.
Re: Straightforward solution
If you have a website that uses some combination of identification, authentication and authorisation, you need somewhere to store the token(s) that represent your present authentication status and level of access.
That may well be the case. This doesn't mean that somewhere must be a cookie. It often is because web developers are so lazy or stupid, they see any sort of identification, authentication and authorisation issue as a cookie-shaped nail that can only be hit with a cookie-shaped hammer. Instead of actually thinking about the problem that needs solving, they just reach for the cookie jar.
Re: Straightforward solution
This doesn't mean that somewhere must be a cookie
Cookies are just local state. They are the only local state that all browsers offer, so I'm not sure where else a web developer, regardless of talent or work ethic, might think to store this data. You can easily turn off the persistent storage of local state in your browser and that should perhaps be the default, but that's not within the control of the web developer.
Any other local state would have exactly the same issues - you don't solve the problem by changing its name.
Re: Straightforward solution
I wouldn't mind so much if once I've said "no to all cookies" that was it but it never is, every month or so (and El Reg is not an exception) up comes the stupid pop-up I suppose just in case I've changed my mind.
I wonder if you select "yes to all cookies" do you still get the cookie message at the same interval or are they deliberately making it as irritating as possible for those who opt out?
Re: The UK
Admit it - you are a cat aren't you....
My feline overlord expresses similar views....
Britain leading again (?!!)
" they are derailing the core purpose of data protection which is to protect rights and freedoms " Rowenna Fielding
I (probably among others) hugely stressed this possibility in my response to the public consultation. The result is protection of data only, not protection of persons in respect of the processing of their data, so the entire original intent of the legislation as currently enacted is rendered void. Those to curb whom the legislation was conceived will be laughing all the way to the bank, and there will probably be plum jobs waiting at the data slurpers for ex-ministers to take up when they leave government office.
Sadly, as other countries continue to model their data protection legislation on the GDPR as the best of kind so far, the UK appears to have decided to abandon it and throw human rights to the wind.
Re: Britain leading again (?!!)
@Mike 337
I was with you until your last paragraph. Your last paragraph is a load of biased bollocks. Which makes me think you are clueless.
Cheers... Ishy
Re: Britain leading again (?!!)
It looks a bit like you might be on your own there.
"The government will work with the industry"
Should be read "the government will bow to the industry"....
Re: "The government will work with the industry"
@LDS
All governments everywhere bow to taxes that hopefully may get paid someday,, soz I mean't to say industry. It's just that some governments are more blatant about doing so than others.
Cheers... Ishy
Re: "The government will work with the industry"
In other news, big business continually avoid paying taxes by the use of offshoring and highly creative accounting...
It's unlikely to be taxes, and rather more likely to be a more direct route between cash-strapped corp and politician's wallet.
I fully agree with cookie consent requirements in principle, I don't believe the requirements should be lifted.
In practice, unfortunately, most people have no idea what they are consenting to, and it has just put people in the habit of blindly clicking 'Accept' on anything that pops up on a website, which means they also blindly give consent to websites to bombard them with pop-up notifications, which leads to me getting phone calls from people who think they have "a virus or something"
That's exactly what cookie consent is for, to legitimise the data collected by corporations.
Before the cookie law it was a gray area, now it enables them to openly sell data as the subjects have consented.
Give sites the option of consent or do not track with a mandatory fine 1% of global turnover for every user tracked.
No thanks, EU! Hated rules SCRAPPED as UK to end 'pointless' web cookies in Brexit bonfire *
Lots of comments about cookie banners but we really should be more interested in not being able to challenge automated decision making and the other stuff they've buried in this bill.
Friends don't let friends be Express readers.
* Actual Express headline.
And for EU visitors ?
Presumably UK sites will still need to comply for their visits. ?
People who bleat about "rights" forget that you ONLY have the "rights" society chooses to grant, and society can change its mind at any time. There is no such thing as a "natural" or "inherent" right that you are truly guaranteed.
Anyone who thinks otherwise need only consider their so-called right to "freedom" and what happens to it when they get locked up for committing a crime.
The War on Cookies is a good example of "be careful what you wish for," though. With cookies now easily defeated by the average consumer, [1]adtech is moving their tracking to server-side where it's much harder to detect and block.
[1] https://www.kickbite.io/server-side-tracking-a-marketers-alternative-to-cookies
Intrusions are avoidable - teach people how to deny access
I suppose everybody commenting here already implements one or more of the free to use 'apps' and browser add-ons available for blocking intrusions from 'commerce' on their personal devices. For some years I have managed a cookie-restricted, free from pop-ups, and 'ad-free' existence. For most interactions with the Internet little more than basic configuration of these protective utilities suffices. Sometimes, when sites by default push a large number of ancillary connections it is desirable by trial and error to identify which can be blocked e.g. script injecting sites.
Perhaps, the generality of mankind deploys at most limited scope tools bundled with the MS Windows Home Edition and some may buy programs and suites offered on the Windows 'Market Place'. Because recent Windows Home incarnations have become marketing and entertainment places, ordinary users have limited control, but still can use the free tools alluded to above. Maybe some proportion of these users enjoy garish 'ads', 'pop-ups', tailored 'ads', and notifications; I doubt the Windows user interface would be so 'busy' were not that the case.
Nevertheless, many users of Windows and Android devices are unaware of the power they have to curtail intrusions. Legal restriction on cookies etc. are almost irrelevant when a device is properly configured; the only truly annoying feature for which seemingly there is no workaround yet is the the permission seeking overlay which can deny access unless acknowledged.
Almost universally in Internet connected schools across the globe Windows devices are used some of the time as teaching aids. Pupils generally have Windows PCs and laptops for home use and Android phones are ubiquitous in the West. Presumably all pupils are exposed to some general teaching about computer technology and IT; that is the point at which protection against commercial intrusion can be introduced. So far as I know, schoolteachers in the UK retain some flexibility concerning how a syllabus is approached. Should not teachers with IT knowledge accept as professional responsibility need to acquaint pupils with how to curb commercial intrusion? This particularly in context of Windows and Android devices. Given Microsoft's cleverly concocted dominance of educational computer use in schools and colleges, it may be too much to ask for pupils to be introduced to operating systems (primarily Linux variants) not inherently designed to service commercial marketing.
Will this current government's blatant corruption ever cease?
(see above)