Cookie Consequences
As we all know, the deadline for businesses to comply with the EU’s Directive on electronic data privacy came into force last Saturday 26th May. In essence, the ICO (Information Commissioner’s Office) have said that every organisation that stores cookies on their website must ask their users for consent for their information to be stored. For example, Channel 4 (below) have asked visitors to their site to be aware that they use cookies on their site and visitors have the choice whether or not to accept it.
Even if the entire process hasn’t yet been completed, each organisation must, at the very least, show the steps that they’ve taken to comply with the legislation or they will be forced to accept the fines and consequences of falling foul of the law. Websites that break the rules can be fined as much as £500,000.
But what actually happened on the 26th? Did the axe fall on companies who didn’t comply? Did officers visit company HQ’s demanding explanations as to why they haven’t at least carried out an audit on cookies and handed out thousands of pounds worth of fines? In a word, no.
The ICO have said that they will send out 50 letters to the UK’s biggest websites this week. They will then wait for complaints to come in from members of the public about cookies on specific sites before investigating these organisations for flouting the data protection law.
Below are the options which the ICO are able to take “to change the behaviour of organisations and individuals that collect, use and keep personal information”. (www.ico.gov.uk)
It’s main options are:
- serve information notices requiring organisations to provide the Information Commissioner’s Office with specified information within a certain time period;
- issue undertakings committing an organisation to a particular course of action in order to improve its compliance;
- serve enforcement notices and ‘stop now’ orders where there has been a breach, requiring organisations to take (or refrain from taking) specified steps in order to ensure they comply with the law;
- conduct consensual assessments (audits) to check organisations are complying;
- serve assessment notices to conduct compulsory audits to assess whether organisations processing of personal data follows good practice (data protection only);
- issue monetary penalty notices, requiring organisations to pay up to £500,000 for serious breaches of the Data Protection Act occurring on or after 6 April 2010 or serious breaches of the Privacy and Electronic Communications Regulations;
- prosecute those who commit criminal offences under the Act; and
- report to Parliament on data protection issues of concern.
Considering that the majority of the Government’s websites haven’t complied either, I doubt very much that many organisations will face the £500,000 fine in the near future!





