ICO surprises with last-minute cookies changes
By Nicole Kobie
Posted on 28 May 2012 at 10:32
The Information Commissioner has surprised web admins by rolling out changes to how it views the cookies law the day before an enforcement deadline.
The law - the result of an EU directive regarding online privacy - requires websites to get consent before dropping cookies and other tracking technologies onto users' computers. It came into law last year, but the ICO gave websites a year's grace before enforcement started.
However, a day before enforcement was due to start, the ICO revealed it would consider "implied consent" to be good enough - meaning sites can simply tell users that by continuing to use the site, cookies will be used.
"Implied consent is a valid form of consent and can be used in the context of compliance with the revised rules on cookies," said Dave Evans, head of business policy, in a post on the ICO site. "If you are relying on implied consent you need to be satisfied that your users understand that their actions will result in cookies being set. Without this understanding you do not have their informed consent."
Find out moreFor more on cookies, read our policy here
The data watchdog has issued limited guidance on how to meet the law, saying it doesn't want to tell companies what to do. "We’ve stressed that there’s no ‘one size fits all approach’," Evans said. "We think that organisations themselves are best placed to develop their own solutions. They will know how and why their customers use their websites better than we do."
Implied consent appears to be a popular tactic for many websites. As well as PC Pro, sites such as the BBC, The Sun, and The Guardian are also running banners advising users that use of the site means cookies will be dropped.
While the move will probably be welcomed by many websites, the timing led to some complaints.
"This is a striking shift," Stephen Groom, head of marketing and privacy law at the law firm Osborne Clarke, told The Guardian. "Previously the ICO said that implied consent would be unlikely to work. Now it says that implied consent is a valid form of consent."
"Cookies law changed at 11th hour," said one Twitter user. "All that work last week was really worth it. Thanks ICO."
"Let's all get a box of cookies sent to the ICO to thank them for their capriciousness," added another Twitter user.
The ICO has made it clear it has no plans to unleash a "torrent of enforcement action" against sites, especially those working to meet the law, and that it won't be doling out fines.
Fast Forward to the Past
EU Law: Cookie compliance states that permission MUST be obtained from users BEFORE cookies are used IF THEY ARE NOT IMPERATIVE FOR OPERATION OF THE WEBSITE VISITED.
This was to strengthen privacy law and data law where businesses track and obtain personal data.
Computers are so refined now that they can tell who is on line by the way they type, the phrases used and mannerisms of the content. Yes... they now can tell one individual from another by the "personal footprint".
Facebook Google and others attempt to say "If a person has nothing to hide, they tend to become less obvious, like many birds in a flock".
Putting statements or photographs on line, may warrant a future boss to take a tainted viewpoint.
There are many flaws to this extroversion, such as Identity Theft and the possibilities of future secularism.
There are supposed to be laws to protect privacy, but no law exists to erase any "recorded activity", no matter for how long the data is stored. One strong opt out clause is "Collected data is for HISTORICAL PURPOSES and exempt deletion".
For the ICO not to understand that they ARE supposed to ENFORCE REGULATIONS proves they are not fit for purpose. At worst they may be perverting the course of EU Justice.
By lenmontieth on 28 May 2012
Claude Shannon's theory of communication says that no information can be passed through a channel with 50 per cent random errors, as best I recall.
Considering the ICO's about-turn, I would think that, in terms of their ability to express coherent policy, they have now reached that 50 per cent, and may as well be disconnected from our input channel.
By fogtax on 31 May 2012
- Google Glass: mugger bait, pub problem and other lessons learned from two dangerous weeks
- Twitter, please don't fiddle with my feed
- How Satya Nadella can get some pay-raise karma
- Windows 10: a step back to go forward
- Michael Dell: Cloud infrastructure is the roads, bridges and highways of the 21st century
- How to check your identity hasn’t been sold to the hackers
- Tim Cook: this is how much TV has changed since the 70s
- Westminster wins the .London battle
- 20 years of PC Pro: from deep pan pizza to virtualisation
- Five reasons why the Apple Watch leaves me cold
- How to sell more ebooks on Amazon
- 10 ways to make your business more secure
- Top five VoIP mistakes
- How to add in-app purchasing to an iPhone, Android or Windows app
- Remote-control ransomware: TeamViewer and software hardball
- Why laptops with serial ports matter to the Internet of Things
- Make your mobile battery last longer
- Small steps into handling Big Data
- Nexus 5: does it really run stock Android?
- How to get broadband to a garden office