The Impending Cookie “Crackdown”: Irish Data Protection Commission Expected To Start Enforcement of Its Cookie Guidance This Fall
- Express Consent Reigns Supreme. Companies cannot rely on implied consent. The individual user must be required to take some affirmative action to give their consent.
- User Interface Design Around Cookies – The DO’s and DON’Ts. The Guidance issued by the Commission provided some concrete directives around cookie consent and user interface design including the following:
- DON’T use pre-checked boxes for individual user consent to your company’s notice regarding its privacy and cookie practices.
- DON’T set any “slider” options to “On” as the default.
- DON’T use cookies as individuals review and decide if they want to consent to your privacy policies or cookie notice.
- DO pay attention to web accessibility guidelines. If your site is not designed to allow for individuals with visual impairments to actively engage with your granular privacy and cookie choices, you could face scrutiny.
- DO provide both “Accept” and “Reject” options to individuals. Cookie management for individuals should be granular and provide meaningful choice.
The Irish Data Protection Commission does not stand alone in its provision of guidance around distinct requirements for the use of cookie technologies: similar guidance has been issued by the data protection authorities in France, Germany, and Spain, as well as the United Kingdom’s Information Commissioner’s Office (ICO).
Coupled with emerging regulatory requirements in the United States, such as Nevada’s cookie law and the California Consumer Privacy Act (CCPA), this fall seems to be the season to revisit compliance programs and cookie practices.
The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.