E-Privacy and Cookies: Legal Aspects. E-Privacy Directive 2002/58, amended by 136/2009 Main amendments focus on DBN (security) and confidentiality of.

Slides:



Advertisements
Similar presentations
Council of the European Union Working Party on Data Protection
Advertisements

CHAPTER 4 E-ENVIRONMENT
I consent: search, privacy, behavioural advertising and the Cookie Directive Andrew McStay School of Creative and Media Studies, Bangor University, UK.
New Cookie Directives: What’s Crumbling? Presented by Mike Knight.
Identity Management Based on P3P Authors: Oliver Berthold and Marit Kohntopp P3P = Platform for Privacy Preferences Project.
1 Reform of the EU regulatory framework for electronic communications What it means for Access to Emergency Services Reform of the EU regulatory framework.
1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Class 13 Internet Privacy Law European Privacy.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Website Content, Forms and Dynamic Web Pages. Electronic Portfolios Portfolio: – A collection of work that clearly illustrates effort, progress, knowledge,
Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
RESPECT Guidelines regarding data protection aspects whithin socio-economic research Y. Poullet, K. Rosier, I. Vereecken CRID-FUNDP in cooperation with.
Samuvel Johnson nd MCA B. Contents  Introduction to Real-time systems  Two main types of system  Testing real-time software  Difficulties.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Using the Internet to Conduct Research What Investigators and IRB Members Should Know -- January 29, Lisa Shickle, MS Analyst, VCU Massey Cancer.
Ioannis Iglezakis Directive on privacy and electronic communications.
Cookie compliance: your 5 day emergency action plan Claire Walker.
Ide kerülhet az előadás címe CCTV operation at work Belgrade, 11 th April 2013.
Privacy, P3P and Internet Explorer 6 P3P Briefing – 11/16/01.
Introduction: Privacy Subgroup Request for Policy/Legal Feedback The W3C Digital Data Community Group is building a common data layer for web sites to.
+ Eyes in The Sky: Drones, Data and Privacy Unmanned Aircraft Association of Ireland 21 August 2015 Joseph Dalby & John Wright twitter:
Session ID: Session Classification: Dr. Michael Willett OASIS and WillettWorks DSP-R35A General Interest OASIS Privacy Management Reference Model (PMRM)
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
The Global Health Network Marijke Geldenhuys 19 September 2014 Adhering to the GCP Principles.. what does that even mean?
Legislative Texts. The legislative process in the EU Proposal, recommendation, communication from Commission, Green Paper, consultation, studies, draft.
EPrivacy & Consenting Cookies Rakuten LinkShare Symposium 2012 Liz Robertson Jones Day 17 April 2012.
U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project.
Created by: Group 6. Internet is becoming more and more popular nowadays and children are growing up with technology. Kids search engines gives parents.
Osborneclarke.de OBA Breakfast Seminar 22 January 2013 Stephen Groom OC London Action points for UK advertisers.
Organisations and Data Management 1 Data Collection: Why organisations & individuals acquire data & supply data via websites 2Techniques used by organisations.
DG Information Society The EU and Data Retention Data Retention Meeting London, 14 May 2003 Philippe GERARD, DG Information Society The positions.
INTRODUCTION TO DATA PROTECTION An overview of the Irish Data Protection legislation.
Marketing / Law / Digital Keith Arrowsmith. Court ActionPress Complaints CommissionTrading StandardsGambling Commission.
PRIVACY, LAW & ETHICS MBA 563. Source: eMarketing eXcellence Chaffey et al. BH Overview: Establishing trust and confidence in the online world.
The New Legislative Framework
Computer-made Cookies Presented by Helal Lutfi. What is a Computer Cookie?  A small text file which contains a unique ID tag.  Placed on your computer.
Privacy and Data Protection in e-Communications Sector Legislation, Codes of Practice and Standards Privacy and Data Protection in e-Communications Sector.
Privacy, data protection and connected cars Lilian Edwards, Professor of Internet Law University of Strathclyde Researcher in Residence, Digital Catapult.
Presentation Title Data Protection The new EU Regulation Insert your logo here.
Data protection—training materials [Name and details of speaker]
Protecting your search privacy A lesson plan created & presented by Maria Bernhey (MLS) Adjunct Information Literacy Instructor
COOKIES Gloria Soria Network Security COSC 356. What is a Cookie? A cookie is a piece of text that a Web Server can store on a user's hard disk. Cookies.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
Andrew Cormack Janet Who Burnt the Cookies?. One portion... Mix with... Bake into... Resulting in... Recipe for Trouble Good intentions – They’re breaching.
CS 115: COMPUTING FOR THE SOCIO-TECHNO WEB TECHNOLOGIES FOR PRIVATE (AND NOT-SO-PRIVATE) COMMUNICATIONS.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Dr. Victoria Banti-Markouti
GDPR (General Data Protection Regulation)
European app matters Charles Lowe
Museums + Heritage webinar, 30 November 2017
The European Union General Data Protection Regulation (GDPR)
Research Ethics Matthew Billington
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Unit 27 Web Server Scripting Extended Diploma in ICT
DATA e-Privacy Regulation Proposal
General Data Protection Regulation
Relocation CARNIVAL come one…come all
GDPR Workshop MEU Symposium Prague 2018
The activity of Art. 29. Working Party György Halmos
I (do not) consent to behavioural advertising
GDPR Consent Data Protection Practitioners’ Conference 2018 #DPPC2018.
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Data Protection: The new EU Regulation
EU Data Protection Legislation
Distributed Digital Rights Management
Presentation transcript:

E-Privacy and Cookies: Legal Aspects

E-Privacy Directive 2002/58, amended by 136/2009 Main amendments focus on DBN (security) and confidentiality of communications / unsolicited communications (5.3 and 13) Emphasis on user empowerment, choice

E-Privacy directive: Transposition Patchy transposition (all MS: January 13) “Cookie rule” (5.3) major point of discussion (confidentiality of communications) National divergences 1) on interpretation of “consent” for the purposes of 5.3 (not only) AND 2) on the (technical) implementation of “consent”

Cookies “A short alphanumeric text which is stored (and later retrieved) on the data subject’s terminal equipment by a network provider” (WP29’s Opinion 2/2010 on Online Behavioural Advertising) Cookies may or may not contain personal information (IP Address, …) This is irrelevant for the purpose of applying Article 5.3, which only refers to storage or retrieval of “INFORMATION” in the terminal equipment of a subscriber or user

Cookies – 2002/ /46 However, if the information contained in a cookie includes personal data, than all the principles of directive 95/46 are also applicable So there is an interplay between the “consent” rule of 5.3 in directive 2002/58 (lex specialis) and directive 95/46 (lex generalis): that is to say, the rules on consent are those set out in directive 95/46 except where they are overridden by the “lex specialis” contained in directive 2002/58 (here: Article 5.3)

Cookies and Consent Article 5.3 requires that storage of or access to any “information” (including cookies) in the subscriber’s/user’s terminal equipment be subject to prior informed consent (= before cookies are set) – “Prior”: “has given… consent, having been provided… (see also Recital 66) – “informed”: “… with clear and comprehensive information”

What Consent? Article 5.3 of 2002/58 (lex specialis) sets out the specific requirements of prior informed consent for cookies BUT this “consent” is in no way different from the “consent” of directive 95/46 (article 2.h + Article 7)  see also Article 2 of 2002/58 – Specific (and informed) – Freely given – Unambiguously given

Consent: Specific Consequences 5.3: No blanket consent Purpose specification and limitation Appropriate information  WHERE: On the landing page of the website WHAT: Purposes of processing ; Right to accept/decline all or part of the cookies HOW: Layered approach (WP100) (different levels of detail)

Consent: Freely Given Consequences 5.3: Real options must be available (e.g.: accept/decline all or part of the cookies / change browser settings) No conditions to be placed on consent (WP185: Opinion 15/2011 on the definition of consent)  Continue browsing website even after declining cookies

Consent: Unambiguously Given Consequences 5.3: Active behaviour: silence/inactivity is no consent Evidence of consent must be available (to the controller) Simple scrolling of the webpage is not enough Click on a field, push a button, tick a box, or go to a third-party site where options can be exercised (trusted third party?) NOTE: Proposed DP Regulation refers to consent as signified by «clear affirmative action»  No passive acceptance

Consent: Additional Food for Thought Recital 66 of directive 136/2009: If «technically possible and effective» consent to processing may be expressed by way of browser settings or other applications BUT «in accordance with directive 95/46»  What does that mean exactly? Interesting options, technical difficulties (browsers are not info society service providers)  interoperability, technical parameters «privacy plug-ins» ?

Consent: Additional Food for Thought - Proposed EU DP Regulation (COM/2012/11)  Art. 4: “explicit” consent (rather than “unambiguous” consent) - WP29’s Opinions (in addition to “Consent” opinion): - Online Behavioural Advertising (WP171 of 2010) - Cookie Consent Exemptions (WP194 of 2012)

When Prior Consent Is Not the Rule - WP29’s Opinion on Cookie Consent Exemptions - Focuses on second part of 5.3: No prior informed consent is necessary - A) For the sole purpose of carrying out transmission of a communication over an electronic communication network - B) If storage or access is strictly necessary for provision of a service by the provider of an information society service and such service has been explicitly requested by the subscriber or user

When Prior Consent Is Not the Rule  Hence, in many cases consent is unnecessary  (technical conveyance of communications, provision of services like online shopping cart, authentication, multimedia player sessions, user interface customization,…) BUT for the duration of a session (no permanent tracking) and if cookie is strictly necessary (in the user’s perspective)  Recital 25 of e-privacy: No need to obtain consent for each reading of the cookie – providing users/subscribers are aware that such reading takes place (= once-only informed consent)

The Grey Zone  Do-not-track: discussion in progress (W3C), should mean do-not-collect (in permanence); interoperability issues, standards, …  First-party analytics cookies (audience measuring tools)  Not necessary for either technical or service provision services, but likely to cause no privacy risks (if first-party aggregated statistical purposes, adequate information, opt-out offered)  Rule of thumb? First party, session-specific cookies less likely to require consent than third-party, permanent cookies (see WP’s document on cookie consent exemption)

Fortune Cookies - /docweb-display/docweb/ (Guidance on cookies and consent, in English) - WP29’s Website ( protection/article-29/documentation/opinion- recommendation/index_en.htm) (Opinions and Recommendations of EU DPAs, also on cookies) - (Do-not-track standards from W3C)

THANK YOU - For listening - For your attention - For not asking too many difficult questions….