'Most Innovative Startup 2020' by RSA - Watch the video
Learn MoreBlogs
Published on November 10, 2020 AUTHOR PRIVACY RESEARCH TEAM
The deadline to implement the Updated Guide on the Use of Cookies (Updated Guide) released by the Agencia Española de Protección de Datos, the Spanish Data Protection Authority (AEPD) was 31st October 2020. Organizations were provided a three-month transition period to adopt the Updated Guide when it was released on 28 July 2020. It aligns with the latest guidelines of the European Data Protection Board on consent.
Some of the key takeaways of the Updated Guide are set out below:
For consent to be valid, it must be freely granted and informed. The option to “continue browsing”, user click, scrolling, navigation, or any such similar behavior do not constitute valid forms of consent. Consent is deemed to be valid only where the user has made a clear affirmative and unequivocal action. Consent must be given for each specific purpose to ensure granularity.
The acceptance of the use of cookies must be separate from the acceptance of the terms and conditions of the use of the website or service or the privacy policy of the website.
The information about cookies provided at the time of requesting the user’s consent must be sufficiently complete to allow users to understand its purpose and use. The information must be provided in a concise, transparent, and intelligible manner using clear and simple language. The use of phrases that confuse or distort the clarity of the message should be avoided.
One of the ways for obtaining consent to the use of cookies is to provide layered information.
The information about cookies must be easily accessible. The accessibility and visibility can be enhanced in several ways:
Website publishers must allow users to withdraw consent to the use of cookies at any time. The method to withdraw cookies must be made as easy as obtaining consent. A button to reject all cookies must be installed.
As a general rule, website publishers cannot make access to a service or its functionalities conditional on the user’s acceptance of the use of cookies. Where non-acceptance to the use of cookies prevents access to the website, totally or partially,
In the case of children under 14 years of age, website publishers must make reasonable efforts to verify that the consent for the processing of personal data is given by the holder of parental authority or guardianship, taking into account the available technology and the circumstances of the treatment.
The validity of consent provided by a user for the use of a certain cookie must not have a duration longer than 24 months. During this time, the selection made by the user must be preserved so that the user is not asked to provide consent every single time he or she visits the page in question unless the purpose of cookies is changed.
Website publishers and third parties managing the cookies can define their relationships through contractual arrangements. However, the administrative liability against non-compliance with the cookie consent requirements cannot be contractually transferred to the other party. Therefore, both website publishers and third parties acting as processors must fulfill their respective obligations.
SECURITI.ai’s Cookie Consent Banner Solution enables companies to build cookie consent banners in accordance with the applicable legal requirements with cookie auto-blocking, periodic scanning, and preference center features. SECURITI.ai’s Universal Consent Management Solution captures consent and automates revocation fulfillment.
Ask for a DEMO today to understand how SECURITI.ai can help you comply with the consent requirements of GDPR, e-Privacy Directive, Spanish Data Protection Authority’s Guidance, and a whole host of other global privacy laws and regulations, with ease.
Automate and manage the entire consent life cycle with efficiency for various cookie compliance regulations around the world.
Learn MoreDiscover granular insights into all aspects of your privacy and security functions while reducing security risks and lowering the overall costs
Learn MoreSimplify gathering information, dynamically update your data catalog, and automate assessments and reports
Learn MoreMeet Brian Lillie, Former CPO at Equinix as he discusses the potential challenges of CCPA and how the PrivacyOps framework can be the key to unlocking compliance.
Learn MoreWatch the 3-minute pitch presented by Rehan Jalil on SECURITI.ai in the RSAC Sandbox Competition
Learn MoreCCPA protects consumers from mismanagement of their personal data and gives the consumer control over what data is collected, processed, shared or sold.
Learn More
info[email protected]
PO Box 13039,
Coyote CA 95013
Find data assets, and discover personal and sensitive data in structured and unstructured data systems, across on-premises and multi-cloud.
Classify & label data to ensure appropriate security controls are enabled on most sensitive data in your organization
Collect, organize, enrich and build a data catalog to address privacy, security and governance solutions
Connect to structured and unstructured data sources and automatically discover and build a relationship map between personal data and its owner.
Assess risk scores for every data asset, asset location, or personal data category
Auto discover personal data in Snowflake and enforce access governance
Auto discover personal data in Snowflake and enforce access governance
Discover, classify, manage and protect sensitive data in Box. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Slack. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more
Discover, classify, manage and protect sensitive data in Workday. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Github. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Jira. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Dropbox. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in SAP Successfactors. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Servicenow. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Zendesk. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Apache Hive. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Apache Spark SQL. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Cassandra. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Discover, classify, manage and protect sensitive data in Couchbase. Automate data subject rights fulfillment and maintain compliance with regulations such as GDPR, CCPA, LGPD, PCI and more.
Maintain your Data Catalog with continuous automated updates
Automate data subject rights request fulfillment and maintain proof of compliance
Connect to structured and unstructured data sources and automatically discover and build a relationship map between personal data and its owner.
Audit once and comply with many regulations. Collaborate and track all internal assessments in one place.
Automation of privacy assessment collection from third parties, collaboration among stakeholders, follow-ups and compliance analytics.
Automate global cookie consent compliance.
Simplify and automate universal consent management.
Automate the incident response process by gathering incident details, identifying the scope and optimizing notifications to comply with global privacy regulations.
Keeping privacy notices up-to-date made easy
Operationalize GDPR compliance with the most comprehensive PrivacyOps platform
Operationalize CCPA compliance with the most comprehensive PrivacyOps platform
Revolutionize LGPD compliance through PrivacyOps
Enable privacy by design through the AI driven PrivacyOps platform