software development disputes

Selling into the EU – what do the cookie laws mean for your website?

HomePrivate: BlogTechnology lawInternet lawSelling into the EU – what do the cookie laws mean for your website?

by

reviewed by

Malcolm Burrows

In May 2012, the United Kingdom’s statutory adoption of the  European Union (EU’s) Cookie Laws came into force.  The effect of the law is that website operators must obtain the express consent for a cookie to be saved and used on a users computer.  The law applies to organisations that host websites from within the EU and also to organisations based in the UK that host outside the jurisdiction.

According to wikipedia “a cookie  also known as an HTTP cookie, web cookie, or browser cookie, is a small piece of data sent from a website and stored in a user’s web browser while a user is browsing a website”.  The principle behind a cookie is that it assists the operator of the website to store information on a users use of a website which enhances the users experience, by for example remembering information which may have been added to a shopping cart.

In essence Directive 2009/136/EC of the Eurpoean Parliament and of the Council is a Privacy Law aimed at protecting consumers aninomity whilst browsing websites.  The UK’s adoption of Directive 2009 has received legislative recognition in the The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR Regulations).  The defininition contained in the PECR Regulations is somewhat broader in that it includes similar technologies for storing information, which, in effect is a catch all.

How to comply with the PECR Regulations?

At first glance there appears to be several ways to comply:

  • stop your webite’s use of cookies;
  • obtain consent in the form of an explicit Privacy Policy or Terms of Use; or
  • obtain implied consent;
  • obtain consent through ensuring that users have appropriate browser privacy settings;
  • obtain an express consent through the use of an express “I agree” link to an explanation of what information the cookie collects and how it operates.

Anyone with any experience in running a website will acknowledge that the last option is likely to be a barrier to adoption.  That said, the First Information Commissioner has issued a guide to compliance which provides a useful assistance for those wishing to comply with the PECR requirements.

What are the Penalties?

The UK’s First Information Commissioner has the power to issue penalties of up to 500,ooo pounds – so it’s far from a toothless tiger!

Does it apply to your website?

If you are an Australian company targetting the UK market it is not settled whether the PECR Regulations will apply to you.  The First Information Commissioner’s Guide provides that:

Organisations based outside of Europe with websites designed for the European market, or providing products or services to customers in Europe, should consider that their users in the UK and Europe will clearly expect information and choices about cookies to be provided“.

Therefore, it is unclear (other than on a choice of laws argument) whether the Cookie Laws apply to Australian organisations selling into the European market.

Further the PECR Regulations may have broader implications for developers of CMS Systems who may inadvertantly omit functionality which may allow for compliance with the Cookie Laws.

Further information

The UK’s Information Commissioner’s Office has provided a guide entitled “Guidance on the rules on use of cookies and similar technologies” to assist organisations to comply with the new cookie laws, contact us for a confidential and obligation-free discussion:


Related insights about technology law

  • Electronic document execution by directors

    Electronic document execution by directors

    The Federal Government has issued a ruling allowing companies to sign documents electronically until 6 November 2020. Find out more about how this ruling affects your business.

    Read more …

  • Assigning intellectual property and the right to sue

    Assigning intellectual property and the right to sue

    This case examines Re Taypar Pty Ltd v Benko Santic [1989] FCA 543, which determined that an assignee of intellectual property rights cannot sue for pre-assignment infringements, unless the assignment explicitly assigns a right to do so.

    Read more …

  • Evidence from the Wayback Machine accepted

    Evidence from the Wayback Machine accepted

    Australian Courts are increasingly considering the use of evidence from the Wayback Machine, but questions remain as to whether they will accept such reports in practice and what will be allowed?

    Read more …

  • $750k awarded for fake online reviews

    $750k awarded for fake online reviews

    The Supreme Court of South Australia awarded $A750,000 in damages to a lawyer in the case of Cheng v Lok [2020] SASC 14, demonstrating the serious consequences of posting fake reviews online. Find out more about the implications of this case and alternative legal actions for companies that receive negative reviews.

    Read more …

  • Adaptations and computer code – copyright issues

    Adaptations and computer code – copyright issues

    An adaption in copyright is the exclusive right of the owner of the work in question.  Section 10 of the Copyright Act 1968 (Cth) (Act) defines adaption as it relates to literary works in dramatic and non-dramatic forms, in a computer program and in relation to a musical work.   The rights that apply to adaptions…

    Read more …

  • Computer code libraries and copyright ownership

    Computer code libraries and copyright ownership

    The Australian case of Redrock Holdings Pty Ltd and Hotline Communications Ltd v Hinkley [2001] VSC 91 has shed light on how the ownership of copyright in code libraries is determined. Learn more about the dispute and its implications for copyright ownership in this blog post.

    Read more …


Posted

in

, ,
Send this to a friend