HomeSecurityCookie Walls do not comply with GDPR rules

Cookie Walls do not comply with GDPR rules

Walls

Cookie Walls used by various websites, apps and services to force their visitors to accept tracking cookies before they can access them have been shown to not comply with the EU's General Data Protection Regulation (GDPR), the Dutch Data Protection Authority (DPA) said on Thursday.

This is due to GDPR requirements , which require companies to first ask for permission before they can track individuals through cookies, tracking software, or other digital methods.

The GDPR also prohibits the use of other techniques and tools such as Javascripts, Flash cookies, HTML5 local storage and/or web beacons to track users as they browse the web without their valid consent for ad targeting or other similar purposes.

“Digital monitoring and recording of Internet surfing behavior through tracking software or other digital methods is one of the largest methods of processing personal data, because almost everyone is active on the Internet. To protect privacy, it is important to ask permission from visitors to a website,” says Aleid Wolfsen, president of the DPA.

The placement of tracking cookies requires valid user consent

A DPA spokesperson made a statement to TechCrunch regarding the issue of cookie walls and their compliance with the GDPR, saying that “cookie walls do not comply with the consent principles of the GDPR. They must comply immediately, regardless of whether or not we review it in a few months, which we certainly will.”.

While the DPA acknowledges that some cookies, called functional cookies or non-privacy-sensitive analytical cookies, are necessary for the GDPR's consent requirements, tracking cookies are not essential for the proper functioning of a website, or the service must be used with users' permission.

Why are cookie walls not GDPR compliant?

The GDPR defines consent as “a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the subject’s agreement to the processing of personal data” and says that “the request must be clear, concise and not unnecessary, relevant to the use of the service for which it is provided.”

Considering that, in the case of cookie walls, users are forced to give their consent to tracking cookies, the GDPR requirement for free consent is not met.

GDPR has delivered its benefits in less than a year

GDPR is a user and data privacy regulation that came into effect by the European Union on May 25, 2018, and is designed to regulate the data protection of EU residents, as well as the export of personal data outside of EU territories.

According to a Cisco analysis, more than 59,000 data breach notifications have been reported to European Data Protection Authorities (DPAs) by private and public organizations since the EU's GDPR was adopted.

Also, a European Commission statement issued in January said that Data Protection Authorities (DPAs) across Europe received 95,180 complaints about the mishandling of personal data, while companies announced a record number of 41,502 data breaches.

Finally, companies that failed to comply with the new data protection regulations received record fines, with Google being fined 50 million euros ($56.8 million) in January by the French Commission Nationale de l'informatique et des Libertés (CNIL).

The fine of 50 million euros was imposed for violating the transparency and information obligations required by the GDPR and for the lack of user consent requests for the processing of data collected for the purposes of targeted advertising.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS