'Most Innovative Startup 2020' by RSA - Watch the pitch video
View MoreBlogs
Published on October 1, 2020 AUTHOR PRIVACY RESEARCH TEAM
On 6 April, the Data Protection Commission of Ireland (DPC) released a substantive Guidance Note on cookies (Guidance) and provided organizations a grace period of six months to ensure compliance. After the end of the six-month window, which is 5 October 2020, the Irish DPC may act to enforce the Guidance and can hold organizations liable for failing to obtain valid consent before the processing of cookies.
This Guidance was issued based on the report released by the DPC on the findings of a “cookie sweep survey”. The survey was conducted on around 38 organizations operating within the territory of Ireland and around 35 of those companies were found to be significantly lacking in cookie compliance requirements. The DPC noticed the following non-compliance practices of organizations, among others:
Based on its identification of the above non-compliance areas, the Irish DPC released the comprehensive Guidance for organizations. The Guidance explains the purposes of cookies as well as it adheres to the requirements of the GDPR, e-Privacy Directive, and the Guidelines on Consent of the European Data Protection Board, released on 4 May 2020 that declared cookie walls invalid.
Read EDPB’s Updated Guidelines on Consent
The Guidance also complements the landmark decision by the Court of Justice of the European Union in the Planet49 case that declared the use of pre-checked boxes as an invalid mechanism of obtaining users’ consent.
Key Points:
Some of the key points of the DPC Guidance are set out below:
Data controllers must obtain valid consent of users before the processing of cookies except the processing of strictly necessary cookies and communication cookies, i.e. cookies that are processed for carrying out the transmission of a communication over a network. A user’s consent must be freely given, specific, informed, and unambiguous as per Article 4(11) of the GDPR.
Data controllers must allow individual cookie selection by purposes and the user’s consent must be specific to each purpose of the cookie.
Data controllers must allow users to withdraw their consent to the processing of cookies via a user-friendly and easy method.
In order to ensure that the cookie banner complies with the applicable legal requirements, data controllers must give equal prominence to “accept” and “reject” buttons on the cookie consent banner. Moreover, the cookie banner must contain a link to the privacy policy and cookie policy providing detailed and further information. The use of wordings such as “by your continued use of the website – either through clicking, using, or scrolling it – consent to the processing of cookies will be assumed” is not allowed.
The duration of each cookie must be proportionate to its purposes.
Data controllers must provide clear and comprehensive information to users about the use of cookies before the processing of cookies and ensure compliance with the transparency obligations of the GDPR.
Data controllers are not allowed to use pre-checked boxes for the processing of non-essential cookies.
Data controllers must reaffirm the user’s consent after every six months.
Data controllers must arrange controller-processor contracts when they use a third-party payment company to process payments for goods or services of the data controller. In such a case, the controller-processor contract must be in accordance with the requirements of Article 28(3) of the GDPR.
Data controllers must conduct data protection impact assessments for certain types of data processing such as processing that involves systematic monitoring or tracking of individuals’ locations.
The DPC acknowledges the use of Consent Management Platforms. Data controllers must maintain records of users’ consents as part of the processing activities as per the requirements of Article 30 of the GDPR.
This Guidance Note reminds data controllers that they need to comply with the requirements of the valid consent before the processing of cookies as per the GDPR and e-Privacy Directive. Data controllers must bring their cookie consent practices in line with the DPC’s Guidance Note before 6 October to avoid any penalties for non-compliance.
SECURITI.ai’s Cookie Consent Banner Solution enables companies to build cookie consent banners in accordance with the applicable legal requirements with cookie auto-blocking, periodic scanning, and preference center features. SECURITI.ai’s Universal Consent Management Solution captures consent and automates revocation fulfillment.
Ask for a DEMO today to understand how SECURITI.ai can help you comply with the consent requirements of GDPR, e-Privacy Directive, Irish Data Protection Commission’s Guidance, and a whole host of other global privacy laws and regulations, such as the CCPA, with ease.
Read Why you need to adopt SECURITI.ai’s Consent Management Platform
Discover granular insights into all aspects of your privacy and security functions while reducing security risks and lowering the overall costs
Learn MoreSimplify gathering information, dynamically update your data catalog, and automate assessments and reports
Learn MoreMeet Brian Lillie, Former CPO at Equinix as he discusses the potential challenges of CCPA and how the PrivacyOps framework can be the key to unlocking compliance.
Learn MoreWatch the 3-minute pitch presented by Rehan Jalil on SECURITI.ai in the RSAC Sandbox Competition
Learn MoreCCPA protects consumers from mismanagement of their personal data and gives the consumer control over what data is collected, processed, shared or sold.
Learn MoreAudit once and comply with many regulations. Collaborate and track all internal assessments in one place.
Learn MoreComprehensive Solution for California Consumer Protection Action
Comprehensive Solution for General Data Protection Regulation
Revolutionizing LGPD compliance through PrivacyOps
Suite of Schrems II Solutions to help controllers and processors respond to the operational challenges
Scan your Snowflakes instance to auto detect all personal & sensitive data stored in tables and schemas.
Analyze all objects stored in S3 buckets to auto detect all personal & sensitive data stored in them.
Scan your Microsoft OneDrive, SharePoint Online, and Outlook to find personal and sensitive data in files and attachments