Duyurular
EDPB Adopts Final Report of Outcome of the Cookie Banner Task Force
The European Data Protection Board (“the EDPB”) adopted a report on the findings of the first coordinated enforcement action focusing on the use of cloud-based services by the public sector. The EDPB underlined the need for public authorities to act in full compliance with the GDPR and contains recommendations for public sector organizations when using cloud-based products or services. In addition, a list of measures already taken by data protection authorities (“DPAs”) in the field of cloud computing is presented.
The EDPB adopted a report on the work undertaken by the Cookie Banner Task Force established in September 2021 to coordinate the response to complaints about cookie banners made by the NGO NOYB to various EEA DPAs. The Task Force aimed to promote cooperation, information sharing and best practices among DPAs, which was instrumental in ensuring a consistent approach to cookie banners across the EEA. In the report, DPAs agreed on a common denominator in the interpretation of the applicable provisions of the ePrivacy Directive and the GDPR on issues such as opt-out buttons, pre-ticked boxes, banner design or opt-out icons.
According to the Report;
- Type A Practice -No Reject Button on The First Layer
It has been noted that some cookie banners displayed by some controllers appear to include a button to accept the storage of cookies and a button that allows the data subject to access more options, but not a button to reject cookies.
- Type B Practice -Pre-Ticked Boxes
Competent authorities were asked whether they would consider that a banner that does not provide acceptance and decline/non-consent options on any layer with a consent button is in breach of the ePrivacy Directive, the vast majority of competent authorities considered that the lack of decline/non-consent options on any layer of a cookie consent banner with a consent button is incompatible with the requirements for valid consent and therefore constitutes a breach.
It has been observed that some controllers offer users various options (typically representing each category of cookies the controller wishes to store) with pre-ticked boxes in the second layer of the cookie header (after the user clicks on the "Settings" button of the first layer). It was verified by members of the task force that the pre-ticked boxes for opt-in do not lead to valid consent as provided for in the GDPR (see in particular recital 32 "Silence, pre-ticked boxes or inactivity should therefore not constitute consent.") or Article 5(3) of the ePrivacy Directive.
- Type C Practice
Deceptive "Link Design" It has been observed that some cookie banners displayed by various controllers contain a link, not a button, as an option to refuse the placement of cookies (either a direct link to refuse or a link to a second layer where the user can refuse the placement of cookies).
It was agreed by the task force members that, in all cases, there should be a clear indication of what the banner is about, the purpose of the consent sought and how to consent to cookies.
In order for valid consent to be freely given, the task force members agreed that, in any case, a website owner should not design cookie banners in such a way as to give users the impression that consent is required to access website content or to force the user to give explicit consent (one way of doing this could be, on the contrary, for example, to allow navigation to proceed without cookies, especially from the first level).
- Type D & E Practices - Deceptive Button Colours & Deceptive Button Contrast
It was agreed by the task force members that a generic banner standard on color and/or contrast cannot be imposed on data controllers
Based on concrete examples, the task force members took the view that offering an alternative action in the form of a button where the contrast between the text and the button background is so low that it is almost unreadable by any user could be misleading for users.
- Type H Practice- Legitimate Interest Claimed, List of Purposes
It was agreed by the members of the task force that the lawfulness of subsequent processing based on cookies requires a determination of
- the storage/access to information through cookies or similar technologies is done in accordance with Article 5(3) of the ePrivacy directive (and national implementing rules).
- any subsequent processing is carried out in accordance with the GDPR.
- Type I Practice- Inaccurately Classified, Essential Cookies
Some controllers have been seen to classify as "essential" or "strictly necessary" cookies and processing activities that use personal data and serve purposes that would not be considered "strictly necessary" within the ordinary meaning of "strictly necessary" or "essential" under Article 5(3) ePrivacy Directive or GDPR.
It has been stated that tools that only list cookies but cannot control the nature of cookies are an additional aid for competent authorities to request further clarification and information from website owners in addition to the information also provided on the website. WP 29 Opinion 04/2012 on Cookie Consent Exemption is also recalled in relation to the criteria set out for assessing which cookies are necessary and in particular the fact that cookies that allow website owners to store preferences expressed by users in relation to a service should be considered necessary.
- Type K Practice- No Withdraw Icon
Website owners should implement easily accessible solutions that allow users to withdraw their consent at any time, such as an icon (a small, hovering and constantly visible icon) or a link placed in a visible and standardized location.
You can reach further information here.
Kind regards,
Zumbul Attorneys at Law
Türkçe
English