Articles

Working Party 29 guidance on cookie consent

Working Party 29 guidance on cookie consent

Working Party 29 guidance on cookie consent

14.10.2013

The Article 29 Working Party ("WP29") published a working document on how consent for cookies may be obtained. The WP29's opinions and working documents provide authoritative guidance on EU data protection rules.

Based on the e-Privacy Directive 2002/58/EC, the use of cookies or similar tracking technologies may require a website user's consent. The manner in which consent must be obtained varies per EU Member State. This WP29 [1] document provides guidance on obtaining consent for a website operating across Member States. To access the document, click here
 
1.  Consent 

The WP29 advises that a website should contain a mechanism that satisfies each of the following main elements for valid consent:

consent must be specific and based on appropriate information, including e.g. the purposes of the cookies;
consent must be provided before the cookies are set or read;
a positive response or other active behavior of the user is required; and
on the entry page the user should be provided with a real and meaningful choice to freely accept all, some or no cookies. 
 
2.  Consent mechanism 

According to the WP29, a website should contain:

  • an immediately visible notice informing whether various types of cookies are being used, providing the information in a so-called 'layered approach';
  • an immediately visible notice informing that by using the websites, the user agrees to cookies being placed and read by the websites;
  • information explaining how the user can express and later withdraw cookie consents;
  • a mechanism by which the user can choose to accept all or some or decline cookies; and
  • an option for the user to subsequently change a prior preference regarding cookies. 

3.  Layered approach to information and consent 
 
The WP29 in this working document confirms the notion of layered information approach (information to be provided layer by layer upon request of the user) and various consent options as introduced in previous documents. In this working document, the WP29 confirms that a user should not only be informed about the various categories of cookies, but also be able to choose which categories it allows or declines.

Furthermore, the WP29 advises that access to a website should not be made conditional on acceptance of all cookies. If the user does not accept cookies, the user should not be denied access, but may be offered access to less content of the website. 
 
4.  Tracking cookies 

Specific mention is made of tracking cookies. When tracking cookies are being used to single people out, such as by creating profiles based on behaviour, such data likely are personal data according to the WP29. The WP29 advises that for the processing of such personal data together with reading and setting of tracking cookies, the unambiguous consent of the user is obtained. Whether such consent is validly obtained  will be assessed by the competent national data protection authorities. 
 
5.  Conclusion 

With the guidance provided in this working document, the national authorities will have practical guidelines to verify compliance and enforce the rules regarding consent for cookies.

Footnotes:

1Representatives of the European data protection authorities, the European Data Protection Supervisor and the European Commission

Team

Related news

12.10.2018 BE law
Ignace Vernimme and Michiel Van Roey speak on IP rightsduring Agoria's Research & Standardization Event

Speaking slot - On Thursday 25 October, Agoria's Regulatory and Standardization Expertise Center organizes its 5th information day about regulations and standards for topics including international trade, privacy and contract law, transport, Internet of Things and blockchain, eHealth, ... at regional, national and European level.

Read more

11.10.2018 NL law
Stibbe hosts NGB Extra Seminar about product development and counsel’s role at the interface of new technology and law

Seminar - On 11 October 2018, Stibbe will host the NGB (Dutch Association of Corporate Lawyers) Extra Seminar.  IT/IP lawyers Judica Krikke, Jasper Klopper, Marc Spuijbroek and Frederiek Fernhout will discuss the practical aspects of the development of innovative new products. 

Read more

12.10.2018 NL law
Tim Berners-Lee's Solid proposal: the future of data traffic?

Short Reads - The General Data Protection Regulation (GDPR) aims to strengthen the rights of individuals in respect of their personal data. Although this aim has been achieved to a certain extent, the fundamental framework of the way personal data is processed remains unchanged. Companies are still able to use large amounts of user data, in many cases without even obtaining their consent. Tim Berners-Lee, the inventor of the World Wide Web, has announced his plans for a decentralised web, in which users remain in control of their personal data.

Read more

10.10.2018 NL law
Ongevraagd advies Raad van State: normering van geautomatiseerde overheidsbesluitvorming

Short Reads - Op 31 augustus 2018 heeft de Afdeling advisering van de Raad van State (hierna: "Afdeling advisering") een 'Ongevraagd advies over de effecten van de digitalisering voor de rechtsstatelijke verhoudingen' betreffende de positie en de bescherming van de burger tegen een "iOverheid" uitgebracht. Het gebeurt niet vaak dat de Afdeling advisering zo een ongevraagd advies uitbrengt. Dit onderstreept het belang van de voortdurend in ontwikkeling zijnde technologie en digitalisering in relatie tot de verhouding tussen de overheid en de maatschappij.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring