Europe’s Cookie Problem

European Cookie Issue

The Making of a (Cookie) Monster:

Back in the bright optimistic days of 2016, G7 world leaders debated the best way to protect people’s data in this new age of information. They came up with something called GDPR (General Data Protection Regulation). This new regulation was to tighten the grip on big data companies and give people back control over which information they’re willing to share for the sake of privacy, including but not limited to  location data, website pages visits and any online identifiers such as IP/Mac addresses.

What does GDPR actually mean?

  1. It gives your website visitor a choice of what data you can collect about their website visit with any violation meaning swift justice from the ICO (United Kingdom’ Information Commissioner’s Office) – this actually rarely happens
  2. Companies who do not comply could face huge fines of a max £18 Million OR 4% of annual global turnover (whichever is greater) for reference, Apple is a 2 TRILLION dollar company, a violation would cost them $800,000,000.00 (800 million USD) . However in normal day use very few companies are approached by the ICO.
  3. Compliance is non-negotiable if you want to operate within Europe, that’s a lot of pennies for your privacy. The IK is still under ICO rules but as we will see is working to extract itself.

So what is a Cookie Banner?

When you visit a website, you’ve probably seen something like this:

Cookie Banner

This is called a cookie consent banner. They’re used to track and save information of a user’s visit to your website, which may include – time on the site, pages visited, your general location, actions taken on the site and so on. What the G7 leaders wanted was to give you a way to control how much information you allow a website to collect about you. If you close your browser you may see the banner again, this is somewhat of a consequence of GDPR.

In principle this is a good idea but in practice it has not really worked.

Ideally websites are required to give you a choice between declining or accepting cookies in an easy way. The easiest way would be to offer you a ‘Decline’ as well as an accept button. However, businesses are not making it that easy, often requiring you to go into their cookie settings to indicate which cookies you would not like to work on your visit.

 It’s ridiculously annoying and also ultimately useless because hardly any sites offer a straight forward Accept / Decline option.

We conducted research on 30 local Northamptonshire websites. Mainly from Market Harborough, Kettering and Corby to see how many of them were GDPR compliant and we weren’t surprised at the results:

Cookie Compliance Scores

As you can see from the infographic above most sites in Kettering, Corby and Market Harborough did attempt to comply with GDPR but didn’t make it easy for visitors to simply click a ‘Decline’ or ‘No’ button. Most offered the option to go into the cookie setting and make a choice of which cookies they were happy to have live on the website.

Of the 30 sites visited only 3 were fully GDPR compliant to the letter of what is expected. They offer simple Accept or Decline options. The others took advantage of the ICO’s vague terminology and allowed the visitors to do the footwork knowing that most would simply click Accept.

To see for yourself ICO’s multi page compliance rules on website cookies and understand why they are so easy to circumnavigate, grab a cuppa and check them out at:

https://ico.org.uk/for-organisations/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies/how-do-we-comply-with-the-cookie-rules/#comply1

The ICO of course understands what they are trying to achieve with an honest cookie policy. The ICO website cookie banner looks like this:

ICO Cookie Banner

The problem with cookie banners is that so many of them are so tedious that people are rarely going to read the policies and hence end up handing over more data than they thought they were agreeing to.

Who can really blame them when many people often visit hundreds of sites in a day.

So What is the solution the UK has come up with and will it work?

On Tuesday 7th of September Elizabeth Denham, the British Information Commissioner, announced that she will meet with her G7 counterparts to discuss the frustration of cookie banners and pop-ups.  She is coming armed with a simple idea that could bring drastic change to an intrusive industry.

Using the privacy settings in web browsers to set what information you want to share with every website you interact with, thus completely negating the need to accept cookies every time you visit, will once more give power back to the website visitor. Basically, your browser will tell the website what information it can take instead of the visitor having to input what information a website can have each time they visit.

This idea isn’t new, in fact it has been around for a good few years. The main issue was and still is getting big tech to play ball and rewrite their browsers to comply. Companies such as Google have a vested interest in data being easily collectable. Google’s analytics software is a major collector of website data often feeding into the Google Adwords campaign. Restricting the collecting of this data directly within their own browser settings may prove too much for them – without a legal fight.

Conclusion/Final Thoughts:

The world is online more than ever, during the pandemic around 400,000 new businesses were started in the United Kingdom alone (Source: Sky News).  Assuming most of these have websites, that’s 400,000 useless cookie clicks and a multitude of data that needs to be handled within GDPR compliance.

Building GDPR cookie settings into a browser is not only good practice, it just makes so much sense. Search engines like Google practically own the internet with their Chrome browser. Building a cookie profile into a browser would certainly simplify things but at what cost for these big companies?

One issue  Elizabeth Denham realised she will have to overcome is that her suggestions give even more power to internet browser companies. Getting the balance right will be tricky and may include the courts.

Whatever the outcome at the moment, asking every website to confirm your data collection preferences has created a cookie monster that nobody wanted.