Securiti leads GigaOm's DSPM Vendor Evaluation with top ratings across technical capabilities & business value.

View

Irish Guidance on Consent & Cookies – Grace Period ends on 5 October

Download: Consent Report Q2 2024
Published October 1, 2020 / Updated November 12, 2024
Contributors

Anas Baig

Product Marketing Manager at Securiti

Maria Khan

Data Privacy Legal Manager at Securiti

FIP, CIPT, CIPM, CIPP/E

Listen to the content

irish consent

On 6 April, the Data Protection Commission of Ireland (DPC) released a substantive Guidance Note on cookies (Guidance) and provided organizations a grace period of six months to ensure compliance. After the end of the six-month window, which is 5 October 2020, the Irish DPC may act to enforce the Guidance and can hold organizations liable for failing to obtain valid consent before the processing of cookies.

This Guidance was issued based on the report released by the DPC on the findings of a “cookie sweep survey”. The survey was conducted on around 38 organizations operating within the territory of Ireland and around 35 of those companies were found to be significantly lacking in cookie compliance requirements. The DPC noticed the following non-compliance practices of organizations, among others:

  • Dropping of non-essential cookies on landing pages without obtaining user’s consent,
  • The lifespans of most cookies that are dropped are not proportionate to the purposes of the cookies,
  • Inadequate cookie banners,
  • Frequent use of pre-checked boxes for the processing of non-essential cookies,
  • A lack of stand-alone cookie policies,
  • Failure to fulfill the requirements of a valid consent as per the General Data Protection Regulation (GDPR) and the Irish e-Privacy Regulations.

Based on its identification of the above non-compliance areas, the Irish DPC released the comprehensive Guidance for organizations. The Guidance explains the purposes of cookies as well as it adheres to the requirements of the GDPR, e-Privacy Directive, and the Guidelines on Consent of the European Data Protection Board, released on 4 May 2020 that declared cookie walls invalid.

Read EDPB’s Updated Guidelines on Consent

The Guidance also complements the landmark decision by the Court of Justice of the European Union in the Planet49 case that declared the use of pre-checked boxes as an invalid mechanism of obtaining users’ consent.

Key Points:

Some of the key points of the DPC Guidance are set out below:

Data controllers must obtain valid consent of users before the processing of cookies except the processing of strictly necessary cookies and communication cookies, i.e. cookies that are processed for carrying out the transmission of a communication over a network. A user’s consent must be freely given, specific, informed, and unambiguous as per Article 4(11) of the GDPR.

Multiple purposes

Data controllers must allow individual cookie selection by purposes and the user’s consent must be specific to each purpose of the cookie.

Data controllers must allow users to withdraw their consent to the processing of cookies via a user-friendly and easy method.

In order to ensure that the cookie banner complies with the applicable legal requirements, data controllers must give equal prominence to “accept” and “reject” buttons on the cookie consent banner. Moreover, the cookie banner must contain a link to the privacy policy and cookie policy providing detailed and further information. The use of wordings such as “by your continued use of the website – either through clicking, using, or scrolling it – consent to the processing of cookies will be assumed” is not allowed.

Schedule Your
Personal Demo

Learn how you can leverage Securiti’s Data Command Center to address data security, privacy, governance, and compliance.

See a demo
Schedule your demo today

'The duration of each cookie must be proportionate to its purposes.

Transparency requirement

Data controllers must provide clear and comprehensive information to users about the use of cookies before the processing of cookies and ensure compliance with the transparency obligations of the GDPR.

No pre-checked boxes

Data controllers are not allowed to use pre-checked boxes for the processing of non-essential cookies.

Data controllers must reaffirm the user’s consent after every six months.

Controller-processor contracts

Data controllers must arrange controller-processor contracts when they use a third-party payment company to process payments for goods or services of the data controller. In such a case, the controller-processor contract must be in accordance with the requirements of Article 28(3) of the GDPR.

Mandatory data protection impact assessments

Data controllers must conduct data protection impact assessments for certain types of data processing such as processing that involves systematic monitoring or tracking of individuals’ locations.

The DPC acknowledges the use of Consent Management Platforms. Data controllers must maintain records of users’ consents as part of the processing activities as per the requirements of Article 30 of the GDPR.

How Securiti can help?

This Guidance Note reminds data controllers that they need to comply with the requirements of the valid consent before the processing of cookies as per the GDPR and e-Privacy Directive. Data controllers must bring their cookie consent practices in line with the DPC’s Guidance Note before 6 October to avoid any penalties for non-compliance.


Frequently Asked Questions (FAQs)

The cookie policy in Ireland, like in many other European countries, is governed by the ePrivacy Directive and the General Data Protection Regulation (GDPR). Websites in Ireland are required to obtain user consent for non-essential cookies and provide clear information about their use.

Data protection in Ireland is regulated by the Data Protection Commission (DPC), an independent authority responsible for enforcing data protection laws, including the GDPR and the Data Protection Acts. The DPC ensures that organizations operating in Ireland comply with data protection regulations and investigates data protection breaches.

Under the GDPR, organizations in Ireland can face significant fines for data protection violations. These penalties can range from 10 million or 2 % of the company’s global revenue, whichever is higher, for less serious violations to up to €20 million or 4% of the company's global annual revenue, whichever is higher, for serious breaches of data protection laws.

Non-compliance with cookie regulations in Ireland can lead to action from the Data Protection Commission, including fines or orders to change your website’s practices to meet legal requirements.

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share


More Stories that May Interest You

Videos

View More

Mitigating OWASP Top 10 for LLM Applications 2025

Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...

View More

DSPM vs. CSPM – What’s the Difference?

While the cloud has offered the world immense growth opportunities, it has also introduced unprecedented challenges and risks. Solutions like Cloud Security Posture Management...

View More

Top 6 DSPM Use Cases

With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...

View More

Colorado Privacy Act (CPA)

What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...

View More

Securiti for Copilot in SaaS

Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...

View More

Top 10 Considerations for Safely Using Unstructured Data with GenAI

A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....

View More

Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes

As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...

View More

Navigating CPRA: Key Insights for Businesses

What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...

View More

Navigating the Shift: Transitioning to PCI DSS v4.0

What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...

View More

Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)

AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 14:21

AI Governance Is Much More than Technology Risk Mitigation

AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3

You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge

Watch Now View
Spotlight 47:42

Cybersecurity – Where Leaders are Buying, Building, and Partnering

Rehan Jalil
Watch Now View
Spotlight 27:29

Building Safe AI with Databricks and Gencore

Rehan Jalil
Watch Now View
Spotlight 46:02

Building Safe Enterprise AI: A Practical Roadmap

Watch Now View
Spotlight 13:32

Ensuring Solid Governance Is Like Squeezing Jello

Watch Now View
Spotlight 40:46

Securing Embedded AI: Accelerate SaaS AI Copilot Adoption Safely

Watch Now View
Spotlight 10:05

Unstructured Data: Analytics Goldmine or a Governance Minefield?

Viral Kamdar
Watch Now View
Spotlight 21:30

Companies Cannot Grow If CISOs Don’t Allow Experimentation

Watch Now View
Spotlight 2:48

Unlocking Gen AI For Enterprise With Rehan Jalil

Rehan Jalil
Watch Now View

Latest

View More

From Trial to Trusted: Securely Scaling Microsoft Copilot in the Enterprise

AI copilots and agents embedded in SaaS are rapidly reshaping how enterprises work. Business leaders and IT teams see them as a gateway to...

The ROI of Safe Enterprise AI View More

The ROI of Safe Enterprise AI: A Business Leader’s Guide

The fundamental truth of today’s competitive landscape is that businesses harnessing data through AI will outperform those that don’t. Especially with 90% of enterprise...

Data Security Governance View More

Data Security Governance: Key Principles and Best Practices for Protection

Learn about Data Security Governance, its importance in protecting sensitive data, ensuring compliance, and managing risks. Best practices for securing data.

AI TRiSM View More

What is AI TRiSM and Why It’s Essential in the Era of GenAI

The launch of ChatGPT in late 2022 was a watershed moment for AI, introducing the world to the possibilities of GenAI. After OpenAI made...

Managing Privacy Risks in Large Language Models (LLMs) View More

Managing Privacy Risks in Large Language Models (LLMs)

Download the whitepaper to learn how to manage privacy risks in large language models (LLMs). Gain comprehensive insights to avoid violations.

View More

Top 10 Privacy Milestones That Defined 2024

Discover the top 10 privacy milestones that defined 2024. Learn how privacy evolved in 2024, including key legislations enacted, data breaches, and AI milestones.

Comparison of RoPA Field Requirements Across Jurisdictions View More

Comparison of RoPA Field Requirements Across Jurisdictions

Download the infographic to compare Records of Processing Activities (RoPA) field requirements across jurisdictions. Learn its importance, penalties, and how to navigate RoPA.

Navigating Kenya’s Data Protection Act View More

Navigating Kenya’s Data Protection Act: What Organizations Need To Know

Download the infographic to discover key details about navigating Kenya’s Data Protection Act and simplify your compliance journey.

Gencore AI and Amazon Bedrock View More

Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock

Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...

DSPM Vendor Due Diligence View More

DSPM Vendor Due Diligence

DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...

What's
New