hello@newnorth.nl+31 (0) 85 401 31 62
/Journal

Cookies, the GDPR and ePrivacy: how it actually fits together

GuidePrivacy2023.02.13
Freek Kampen
Freek KampenCo-founder, New North Digital

The cookie banner comes from the ePrivacy Directive, not the GDPR. The types of cookies, what the law asks, and what belongs in your policy and banner.

What a cookie is

A cookie is a small file a website stores on your device through your browser. On your next visit the browser sends it back, so the site can remember something: that you're logged in, which language you want, what's in your basket.

That's the useful side. The other side is that the same mechanism can follow your behaviour across sites and build a profile of you. Hence the legislation.

The types of cookies

Cookies are classified on three things: how long they persist, who sets them, and what they're for.

  • Session cookies last only as long as the visit. They disappear when the browser closes or after a set period.
  • Persistent cookies survive the browser closing, and are used for preferences or to follow someone across visits.
  • First-party cookies are set by the site you're on and readable only by that site.
  • Third-party cookies come from a domain other than the one you're visiting. These are the notorious ones, almost always for tracking and advertising.
  • Secure cookies travel only over an encrypted connection, intended for sensitive data.
  • HTTP-only cookies are unreachable from JavaScript and readable only by the server, which protects against cross-site scripting.

The cookie law is not the GDPR

This is the most common misconception. The obligation to ask for consent does not come from the GDPR but from ePrivacy Directive 2002/58/EC, commonly called the cookie law.

Legally that directive takes precedence over the GDPR because it is lex specialis: a specific rule that overrides the general one. If you use cookies, you look at ePrivacy first and the GDPR second.

The core of it: visitors must give explicit consent before you set non-essential cookies.

What happens if you breach it

A directive is not a law. The EU text carries no penalties of its own; each country translates it into national law with its own sanctions. In practice a regulator does one of these:

  • Request further information before anything changes.
  • Ask you to make changes if your site is found non-compliant.
  • Enforce, with specific actions inside a set period.
  • Fine you, where both the grounds and the maximum amount differ per country.

What you have to satisfy

Consult a legal advisor for your own situation. Broadly, the cookie law and the GDPR require this:

  • Only set cookies with the visitor's consent.
  • Explain clearly and completely why you collect data, what each cookie tracks and why.
  • Make withdrawing consent as easy as giving it. This is where most banners fail.
  • Keep your site working for people who refuse. Non-essential cookies are by definition not essential.
  • Record and store the consent you received, so you can demonstrate it.
  • Link to your privacy and cookie policy, where the detail lives.

What belongs in your cookie policy

A cookie policy explains how your company tracks data and protects visitors' privacy. The applications differ per business: retargeting, remembering a basket, web analytics, language preferences.

The requirements don't differ. Every cookie policy must:

  • State which cookies are set and of what type.
  • State which third parties set and read cookies through your site, with links to their policies.
  • Explain what each cookie is for.
  • Be available in every language you offer the service in.

What your banner has to do

The banner tells visitors cookies are in use, which kinds and what for. It links to your privacy policy, and offers the choice to accept, refuse, or set preferences per category.

  • Inform people that cookies are used.
  • Give a real refuse option, as reachable as accepting.
  • Make it unambiguous which action counts as consent.
  • Make the banner prominent enough to be noticed.
  • Give access to the cookie policy or to information on purposes and third parties involved.

The takeaway

These are minimum requirements. Individual regulators can take a stricter view of what a banner must show and how consent may be asked.

Practically: if your banner has a big green accept and refuse sits two clicks deep, you don't comply, however complete your cookie policy is.

Want to talk about this?

Let's talk data.

Tell us about your stack, your goals, the data you wish you had.

Takes 1 minute