Feeds

You can break EU cookie rules ... if your site breaks without cookies

It's the way the cookie crumbles when you split hairs

Maximizing your infrastructure through virtualization

Website operators can only take advantage of an exemption from new cookie laws if site users specifically request a service or function and that service would not work without the serving of the cookie, EU data protection regulators have warned.

After changes to the EU Privacy and Electronic Communications (e-Privacy) Directive that came into force in the UK last year, site operators must obtain user consent to place cookies in users' browsers. There is an exception, though, for services where a cookie is 'strictly necessary' for the operation of the site, such as tracking a shopper's choices to allow them to pay for goods at a checkout stage of an online process.

The Article 29 Working Party has published an opinion which says that sites can only make use of this exception if a user has specifically requested the service or functionality for which a cookie is 'strictly necessary and the service or functionality would not work if a cookie was not served'.

The Working Party said (12-page/151KB PDF) that cookies should only be considered as fulfilling the 'strictly necessary' criteria if an "information society service" is "explicitly requested" by a user who has taken "a positive action ... for a service with a clearly defined perimeter" and where that service would "not work" without it.

"There has to be a clear link between the strict necessity of a cookie and the delivery of the service explicitly requested by the user for the exemption to apply," it said.

The Working Party added that cookies served for the purposes of delivering "specific functionality" within websites will also not be considered 'strictly necessary' unless "the functionality will not be available" without the cookie and the user has "explicitly requested" the functionality from the website.

Technology law expert Luke Scanlon of Pinsent Masons, the law firm behind Out-Law.com, said that some of the detail provided by the Working Party on when website operators can serve cookies without users' consent would be helpful to businesses but that some questions remain unanswered.

"In relation to the 'strictly necessary' exception, the Article 29 Working Party has used as plain a language as possible," he said. "Cookies are only strictly necessary if the service to which they relate would not work without them."

"Put another way, it appears that the Article 29 Working Party is saying that for all services that can work 'at all' without cookies, the service provider must obtain consent before placing any cookies in relation to that service. What about where this would result in significant wasted time and costs in order for a service to operate without a cookie? Does this mean that developers must find expensive or difficult to implement workarounds whenever it is conceivably possible that a service can work without a cookie? This would seem to be an unreasonable expectation to place on business," Scanlon said.

The Article 29 Working Party is a committee made up of representatives from each of the EU national data protection authorities.

Websites can track user behaviour during individual visits to sites (session cookies) or over multiple visits (persistent cookies) and serve one or a number of different purposes (multipurpose cookies). They can also be served by the websites themselves (first-party cookies) or on behalf of other internet firms, such as advertising networks that use (third-party) cookies to track users' online activity in order to serve them with targeted ads they consider more relevant to those users.

Cookies can also be used by social networks to track user interaction with 'plug-ins', such as Facebook's 'like' button, on other website platforms. Websites sometimes use flash cookies to store information that helps to play back video or audio content, while other cookies can be used to authenticate user passwords to content hidden on websites.

Websites also sometimes use cookies that remember users' preferences on sites, such as how information is displayed or the language it is displayed in. Websites also often use first-party data analytics cookies to measure visitor numbers and those individuals' interaction with their sites.

Under the e-Privacy Directive a further exception to the consent requirement exists where the cookies is used "for the sole purpose of carrying out the transmission of a communication over an electronic communications network."

The Working Party said that in order to qualify under this consent exemption, cookies must be pivotal to the transmission of the communication and that transmission "must not be possible without the use of the cookie."

"Simply using a cookie to assist, speed up or regulate the transmission of a communication over an electronic communications network is not sufficient," it added.

The Article 29 Working Party said that only 'load balancing session cookies', that allow for the processing of web server requests to be spread over a number of computers instead of just one, would definitely not require consent in order to be served on the basis of the 'transmission' exemption.

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
Sysadmin Day 2014: Quick, there's still time to get the beers in
He walked over the broken glass, killed the thugs... and er... reconnected the cables*
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
SHOCK and AWS: The fall of Amazon's deflationary cloud
Just as Jeff Bezos did to books and CDs, Amazon's rivals are now doing to it
BlackBerry: Toss the server, mate... BES is in the CLOUD now
BlackBerry Enterprise Services takes aim at SMEs - but there's a catch
The triumph of VVOL: Everyone's jumping into bed with VMware
'Bandwagon'? Yes, we're on it and so what, say big dogs
Carbon tax repeal won't see data centre operators cut prices
Rackspace says electricity isn't a major cost, Equinix promises 'no levy'
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.