The Register® — Biting the hand that feeds IT

Feeds

ICO sets cookie-law flouters deadline - to open an HTML editor

'C'mon guys, make some sort of effort... please?'

What you need to know about cloud backup

The Information Commissioner's Office (ICO) has set some website operators a deadline to begin efforts to comply with UK regulations that set out rules for the use of cookies.

Dave Evans, the ICO's group manager for business and industry, said that some website operators had failed to "engage" with the watchdog about their use of cookies. He said that the ICO would be "likely" to pursue enforcement action against operators that failed to comply with a deadline they have been set to work towards cookies compliance.

In 2009, the EU's Privacy and Electronic Communications (e-Privacy) Directive was changed to state that storing and accessing information on users' computers would only be lawful "on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information ... about the purposes of the processing".

Consent must be "freely given, specific and informed". An exception exists where the cookie is "strictly necessary" for the provision of a service "explicitly requested" by the user – for example, to take the user of an online shop from a product page to a checkout.

The EU laws were implemented in the UK through amendments to the Privacy and Electronic Communications Regulations (PECR) last year and the ICO was tasked with enforcing the new law and handed the power to fine those that failed to comply up to £500,000.

Evans said that the ICO had managed to balance education about the new consent requirements for serving cookies and enforcement of PECR. He said that businesses should now "know they have to respond to the law."

"It might be a law they wish didn’t exist, but the simple fact is that it is here to stay," Evans said in an ICO blog. "The EU passed the legislation, the Department for Culture, Media and Sport (DCMS) implemented it, and it’s now the ICO’s job to regulate the organisations that have to comply with the law."

"Broadly speaking, there’s two ways we go about this: an education programme to inform the industry, and enforcement work to ensure compliance," Evans said. "So we’ve issued guidance and press releases, spoken at conferences, held meetings and workshops and even written to 75 of the most visited websites, asking what steps they had taken to achieve compliance and offering our help. We are working through the intelligence we have gathered to see if websites are taking action to increase the visibility of information about cookies, and already a fair number have.

"But we’re balancing that with enforcement: for example, some sites have failed to engage with us at all, and they’re now being set a deadline to take steps towards compliance, with formal enforcement action likely if they fail to meet this deadline. Failure to act on an enforcement notice is a criminal offence," he added.

Evans admitted that some may view the ICO as not being "strict enough" with its enforcement of PECR since it had yet to issue a single enforcement notice to a website operator, but he defended the watchdog's behind-the-scenes activities which he said would "ensure any action taken is credible and proportionate."

Online businesses are still unsure about rules around "implied consent", but the ICO is continue to educate on the issue, Evans said. He added that the ICO had received 380 notifications from internet users expressing concern about the use of cookies by websites. The ICO is due to publish an update on its work regarding cookies in November.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

Agentless Backup is Not a Myth

Crack down on this evil....

Something must be done about all these sodding pop-ups warning us about the bleeding obvious.

19
0

Consent must be "freely given, specific and informed"

Has anyone seen a popup *anywhere* that says anything more than the syntactic equivalent of 'we use cookies, click here to say you're happy'?

I'm still looking for the site that tells me which cookies are used, what they're used for, by whom they're used, and which allows me to accept or deny their storage on an individual and non-volatile way.

10
0

An idea

Can we get browser manafacturers to add an optional "X-Cookies-Please: yes" that sites can read and stop displaying the stupid do you want cookies things?

9
0

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
 breaking news
NSA whistleblower to tech firms, Obama: 'Grow a pair!'
Ed Snowden: Email tracking grabs 'IPs, raw data, content, headers, attachments, everything'
 breaking news
Ecuador: All right, Julian, you CAN stay on our sofa - it's your human right
Minister and Wikileaker share cosy chat in tiny London flat
Google flings another £1m at online child sex abuse vid CRACKDOWN
See, see, we're trying, ad giant tells Daily Mail UK.gov
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
BBC lied to Parliament about doomed £100m IT monster, thunder MPs
Axed DMI ballooned and burst while watchdogs sang Kumbaya
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights