Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Cookie Compliance

Featured Replies

Hi Guys,

 

I have been approached by a potential client who has a recruitment website on which visitors can register and the site uses a cookie for the remember me checkbox.

 

Her current developer has said it will cost around £1000 to bring her site up to date with the 2011 cookie compliance legislation that must be corrected by the 26th of May 2012.

 

Everything I have managed to find by googling seems rather confusing so I was hoping somebody might be able to break it down into plain english for me. I must confess to not really knowing this existed until starting discussions with this client and I am a bit concerned about a couple of other sites I have developed that may need to be updated for this.

 

Any help would be greatly appreciated.

 

CyberWizard

It's not particularly clear who has to change anything to comply.

 

As I understand it you are only really on the hook if your cookies store personal information and transfer it when it's not strictly necessary for the operation of the service. Which could apply to all cookies, or no cookies. Is it strictly necessary to use cookies to have a users login name remembered? No. There are probably other ways but the one that immediately springs to mind is a much worse violation of privacy. A database of IP addresses' and associated usernames.

 

I think it's mostly people like Google/Twitter/Facebook that are liable for it. Receiving (or being tracked by) cookies that don't come directly from the site you are on but through a snippet of code that does Ads or Facebook likes or whatever. That's not immediately obvious to the user and it's not strictly necessary for the operation of your website/service. However it is strictly necessary for the operation of the Adsense system and anyone using Adsense must already have that bit of DART ToS on their site somewhere.. so is it just a case of Google updating that?

 

A tick box that says 'remember my username', that sets a cookie that doesn't get sent outside that site.. seems to fall within the realm of 'strictly necessary' AND is by it's nature asking the user for permission. So I think that's exempt.

 

Pretty much the only cookies that this law effects seems to be exactly the kind that deliberately avoid detection. The malicious types. Are the pop-up merchants really going to start asking permission before they fill your mum's computer with trash? Doubt it.

 

Exemptions from the right to refuse a cookie

The Regulations specify that service providers should not have to provide the information and obtain consent where that device is to be used:

 

for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network; or

where such storage or access is strictly necessary to provide an information society service requested by the subscriber or user.

In defining an 'information society service' the Electronic Commerce (EC Directive) Regulations 2002 refer to 'any service normally provided for remuneration, at a distance, by means of electronic equipment for the processing (including digital compression) and storage of data, and at the individual request of a recipient of a service'.

 

The term 'strictly necessary' means that such storage of or access to information should be essential, rather than reasonably necessary, for this exemption to apply. However, it will also be restricted to what is essential to provide the service requested by the user, rather than what might be essential for any other uses the service provider might wish to make of that data. It will also include what is required to comply with any other legislation the service provider might be subject to, for example, the security requirements of the seventh data protection principle.

 

Where the use of a cookie type device is deemed 'important' rather than 'strictly necessary', those collecting the information are still obliged to provide information about the device to the potential service recipient and obtain consent.

http://www.ico.gov.uk/for_organisations/privacy_and_electronic_communications/the_guide/cookies.aspx

  • Author

One word, extortion.

 

That was my initial thought they have since told her if she doesn't agree to pay they will remove her site from their server and email a zip file of the html files.

£1000 for a remember me checkbox is very OTT

 

As I understand it a "remember me" cookie isn't necessary so in this case the checkbox label would need some annotation to inform the user that if ticked a cookie will be set.

 

Simple example:

 

[checkbox] Remember me? (checking this will place a cookie on your system, do not check if you don't want a cookie)

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.