software development disputes

Selling into the EU – what do the cookie laws mean for your website?

HomePrivate: BlogTechnology lawInternet lawSelling into the EU – what do the cookie laws mean for your website?

by

reviewed by

Malcolm Burrows

Reading Time:

2–4 minutes

In May 2012, the United Kingdom’s statutory adoption of the  European Union (EU’s) Cookie Laws came into force.  The effect of the law is that website operators must obtain the express consent for a cookie to be saved and used on a users computer.  The law applies to organisations that host websites from within the EU and also to organisations based in the UK that host outside the jurisdiction.

According to wikipedia “a cookie  also known as an HTTP cookie, web cookie, or browser cookie, is a small piece of data sent from a website and stored in a user’s web browser while a user is browsing a website”.  The principle behind a cookie is that it assists the operator of the website to store information on a users use of a website which enhances the users experience, by for example remembering information which may have been added to a shopping cart.

In essence Directive 2009/136/EC of the Eurpoean Parliament and of the Council is a Privacy Law aimed at protecting consumers aninomity whilst browsing websites.  The UK’s adoption of Directive 2009 has received legislative recognition in the The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR Regulations).  The defininition contained in the PECR Regulations is somewhat broader in that it includes similar technologies for storing information, which, in effect is a catch all.

How to comply with the PECR Regulations?

At first glance there appears to be several ways to comply:

  • stop your webite’s use of cookies;
  • obtain consent in the form of an explicit Privacy Policy or Terms of Use; or
  • obtain implied consent;
  • obtain consent through ensuring that users have appropriate browser privacy settings;
  • obtain an express consent through the use of an express “I agree” link to an explanation of what information the cookie collects and how it operates.

Anyone with any experience in running a website will acknowledge that the last option is likely to be a barrier to adoption.  That said, the First Information Commissioner has issued a guide to compliance which provides a useful assistance for those wishing to comply with the PECR requirements.

What are the Penalties?

The UK’s First Information Commissioner has the power to issue penalties of up to 500,ooo pounds – so it’s far from a toothless tiger!

Does it apply to your website?

If you are an Australian company targetting the UK market it is not settled whether the PECR Regulations will apply to you.  The First Information Commissioner’s Guide provides that:

Organisations based outside of Europe with websites designed for the European market, or providing products or services to customers in Europe, should consider that their users in the UK and Europe will clearly expect information and choices about cookies to be provided“.

Therefore, it is unclear (other than on a choice of laws argument) whether the Cookie Laws apply to Australian organisations selling into the European market.

Further the PECR Regulations may have broader implications for developers of CMS Systems who may inadvertantly omit functionality which may allow for compliance with the Cookie Laws.

Further information

The UK’s Information Commissioner’s Office has provided a guide entitled “Guidance on the rules on use of cookies and similar technologies” to assist organisations to comply with the new cookie laws, contact us for a confidential and obligation-free discussion:


Related insights about technology law

  • What are Software Development Agreements?

    What are Software Development Agreements?

    Having a Software Development Agreement (SDA) is essential for any successful software development project. Learn more about the key clauses involved and how to avoid potential issues.

    Read more …

  • Legal risks in the in-app purchase model

    Legal risks in the in-app purchase model

    Software developers and publishers are offering users the chance to make In-App Purchases within their software, but there are legal risks involved. Learn how to protect yourself and your business by understanding the requirements of distribution platforms and Australian consumer law.

    Read more …

  • App developers – take care with Apple Developer License

    App developers – take care with Apple Developer License

    Creating apps for Apple devices requires adherence to Apple’s Developer Agreement, Program Licence Agreement, and App Store Review Guidelines. Learn about your rights and obligations when it comes to agreeing to Apple’s terms and conditions, and the consequences of ignoring them.

    Read more …

  • Data security – the increasing burden

    Data security – the increasing burden

    The consequences for an Australian business victim for a breach of cyber security are forecast to exponentially increase. In February 2015 the Parliamentary Joint Committee on Intelligence and Security (Committee) recommended the introduction of mandatory data breach notification scheme (Scheme) by the end of 2015.[1] Whilst the details of the incoming Scheme are currently scant,…

    Read more …

  • Proposed anti-bullying laws to target social media platforms

    Proposed anti-bullying laws to target social media platforms

    The Federal Government is introducing legislation to protect children from online bullying on social media. Find out more about the powers the Children’s e-Safety Commissioner will have to address this issue.

    Read more …

  • Cupid Media risks privacy of the dateless

    Cupid Media risks privacy of the dateless

    The Privacy Act 1988 (Cth) (Privacy Act) requires entities to take reasonable steps to secure personal information.

    Read more …


Posted

in

, ,
Send this to a friend