In January 2023, the European Data Protection Board (EDPB) published a report on cookie banners (Report). The Report provides practical guidance to companies doing business in the EU on how to comply with the EU cookie rules. It deals with issues such as reject-all buttons, pre-ticked boxes, banner design, and withdrawal icons. The Report is helpful for companies looking to implement a baseline approach to cookie compliance across the EU.
Background
Under EU law, the use of cookies and similar tracking technologies involving the storing of information, or the gaining of access to information already stored on a user’s device (e.g., web beacons, pixel tags, local storage) (collectively, “cookies”) is subject to strict requirements. In particular, EU cookie rules require companies to obtain users’ opt-in consent to access any information stored on the user’s device unless the cookies are only used i) to carry out the transmission of a communication over a network or ii) for the functioning of the website or app (“essential cookies”).
Since May 2021, the privacy nongovernmental organization None of Your Business (NOYB) brought more than 700 complaints against website operators whose cookie banners allegedly violated the EU cookies rules.[1] As a result, the EDPB set up a “Cookie Banner Taskforce” which prepared the Report in order to promote cooperation and best practices between the various regulators involved.
Main Takeaways
Conclusion
The Report describes the current consensus among the EU privacy regulators as to which cookie practices are to be regarded as lawful. However, the EDPB underlines that the recommendations of the Report may not be sufficient, since additional requirements may apply under the national laws of each EU country.
Wilson Sonsini Goodrich & Rosati routinely advises clients on GDPR and ePrivacy compliance issues, and helps clients manage risks related to the enforcement of global and European data protection laws. For more information, please contact Cédric Burton, Laura De Boel, or another member of the firm’s privacy and cybersecurity practice.
[1] According to NOYB’s own statements, available here.
[2] See WP29 Opinion 04/2012 on Cookie Consent Exemption adopted on une 7, 2012, available here.
[3] CJEU, Case C‑673/17, Bundesverband der Verbraucherzentralen und Verbraucherverbände — Verbraucherzentrale Bundesverband eV v Planet49 GmbH, available here.