UK regulator ICO is set to play cookie cop for the digital ad industry

This week, U.K. data protection authority the Information Commissioner’s Office issued a blunt reminder of how cookies should be used under the Privacy Electronics Communications Regulation. The reason: The law has now been updated to mirror the General Data Protection Regulation’s rules on consent.

Since last year, the wide interpretation of GDPR and a lack of standardization of consent management platforms, which relay consent-request messages to users — have resulted in a messy consumer experience.

The ICO wants to bust any misunderstandings around how and where cookies can be used in advertising and other online services. But it has only vetoed cookies that are “non-essential.” That means any cookie necessary for the delivery of the service a person has requested to use doesn’t need user consent.

“Cookie compliance will be an increasing regulatory priority for the ICO in the future,” wrote Ali Shah, head of technology policy for the ICO in the update. He added that all future action will be proportionate, but that businesses should run cookie audits.

The ad tech industry has already been on red alert since the ICO warned that current ad-targeting practices weren’t legal under GDPR, last month. Others believe this latest guidance takes that up another notch.

“The new guidance on use of cookies will have a significant impact on publishers, advertisers and ad tech vendors alike,” said Ryan Gracey, solicitor and technology law expert at law firm Gordons. “It’s a significant update which brings the use of cookies in line with the GDPR standard of consent and will ultimately change the way in which companies track people online.”

Here is a look at what the ICO has vetoed:

Farewell implied consent
Thanks to GDPR, (this was legal under PECR previously) implied consent can no longer be relied on for cookies or for processing personal data. That means users must give explicit consent to cookies which are deemed non-essential to their website visit or intentions for using an online service (like a purchase). Pre-ticked boxes (of which there are still many) or any tactic that means users are opted in by default are not allowed for non-essential cookies. Users must be given absolute control over what non-essential cookies are dropped on them and these kinds of cookies also can’t be set on landing pages before that user has given consent. Naturally, some businesses would argue that all their cookies are essential for performing their business or service to a user. That would be a risky assumption.

Analytics cookies need consent
It looks like the trusty analytics cookies are out of luck. The ICO has deemed these should require user consent, because otherwise users aren’t aware this type of cookie is being dropped on their computer when they use an online service. For that reason, the ICO has said they are aren’t necessary for the user to be able to access a service; therefore, they must have user consent.

“Time will tell how many people give consent for non-essential cookies, but it will undoubtedly restrict the reach of advertisers,” added Gracey.

Cookie walls: dead on arrival
An idea bandied around at one point ahead of GDPR was the notion of a “tracking wall” or what the ICO refers to as a cookie wall. The concept is that any visitor to a publisher’s site that has a tracking wall installed won’t be able to continue on the site, read or watch the content until they give consent to their data being used and stored by that publisher for advertising purposes. It also applies to a lot of assumed consent strategies. Many sites have added a message to the effect that using the site means giving consent to cookies. However, the ICO has stated this is not valid consent under GDPR.

Legitimate interest
As the ICO recently stated in its latest GDPR update, relying on legitimate interest for sending targeted advertising is a hard no. Same goes for PECR. In fact, the ICO claimed this had always been the case under PECR.

“PECR always requires consent for non-essential cookies, such as those used for the purposes of marketing and advertising. Legitimate interests cannot be relied upon for these cookies,” wrote Shah.

https://digiday.com/?p=339943

More in Media

Creators are left wanting more from Spotify’s push to video

The streaming service will have to step up certain features in order to shift people toward video podcasts on its app.

Digiday+ Research: Publishers expected Google to keep cookies, but they’re moving on anyway

Publishers saw this change of heart coming. But it’s not changing their own plans to move away from tracking consumers using third-party cookies.

Incoming teen social media ban in Australia puts focus on creator impact and targeting practices

The restriction goes into effect in 2025, but some see it as potentially setting a precedent for similar legislation in other countries.