The application of the European cookie law in Spain

“This website uses cookies”. This is the message that every user encounters when browsing the Internet. This is how website administrators comply with the obligation to provide information about the storage of so-called “cookies” on users’ devices when they visit a website. According to the European Directive on Privacy and Electronic Communications ePrivacy, in force since 2002 and colloquially known as the “cookie law”, the installation of these files is only permitted if the user has given their express consent. In practice, however, non-express forms of consent (opt out) have become widespread, which a recent judgment of the CJEU has deemed invalid, at least in the case of tracking cookies.

With the entry into force of the new European General Data Protection Regulation (GDPR) in May 2018, the Regulation on Privacy and Electronic Communications, known as the ePrivacy Regulation, was also due to be launched, since it constitutes a concretisation of the GDPR with regard to the use of cookies, but its publication has been delayed. The draft was officially presented by the EU on 10 January 2017 and the project is currently still pending approval in the European Parliament. Its entry into force is expected over the course of 2019 and it is to replace the previous ePrivacy Directive. What is the current situation?

Note

What is the difference between a regulation and a directive? A regulation is legally binding on all EU countries from its entry into force, whereas a directive must be transposed into the regulatory frameworks of each country.

The CJEU on the installation of cookies

On 1 October 2019, the Court of Justice of the European Union (CJEU) ruled on users’ consent to the installation of cookies on their devices. In effect, it confirms the Regulation in force since May 2018, which establishes the obligation for companies to duly inform the user about the use of cookies on their platform and to obtain their express consent.

According to the current CJEU judgment, consent “presumed” by means of a pre-ticked checkbox cannot be regarded as express consent. What is correct, by contrast, is to inform the user of which cookies are going to be installed, for what purpose, which third parties will be given access to those files and for how long they will remain active on the device, so that, on the basis of this information, the user can decide in a conscious, active and explicit manner whether to consent to their installation. The CJEU does not differentiate according to whether these cookies have access to personal data or not, since it considers that all files stored on a user’s device belong to their private sphere and EU law protects the user from any interference with their private sphere.

This judgment responds to a request for a preliminary ruling from Germany’s Federal Court of Justice, referred to the CJEU for an interpretation of Union law on the protection of privacy in the electronic communications sector, specifically arising from the complaint filed by the German Federation of Consumer Organisations against the online gaming platform Planet49. This company requested the user’s permission to install cookies by means of a pre-ticked checkbox. This step was necessary in order to take part in the games. These cookies collected information to advertise products of the company’s business partners.

What are cookies and what are they for?

Cookies are text files or storage devices that the browser installs on the user’s device when they visit a page. These files store data about the visit to a page, such as, for example, login or authentication information and language settings, which make subsequent visits more convenient, as this information does not have to be provided each time. This useful aspect of cookies is countered by the criticism that they are incompatible with the protection of user privacy. Indeed, there are many cookies that record certain aspects of browsing habits, in such a way that they allow advertising in browsers to be personalised. In this respect, it is above all tracking and targeting cookies that generate the most conflict.

A cookie generally contains indications about its own lifespan, as well as a randomly generated number used to recognise the computer (or whichever device is used). Data storage via cookies takes place anonymously. Personal data is only stored when the page requires authentication, and it is worth knowing that only the browser that created the cookie can read this data.

Fact

The data stored in a text file can only be read by the web server that set the cookie.

The European Union’s cookie law

The Directive 2009/136/EC of 25 November 2009 was launched by the European Parliament with the intention of guaranteeing and strengthening the protection of the personal data of users, and had to be integrated into the respective legal frameworks of the Member States.

The ePrivacy Directive, the so-called cookie law, provides that the user visiting a page must be informed in a clear and unequivocal manner about the use of cookies and must explicitly accept the recording of their personal data. The only exception is constituted by those cookies that are technically necessary for the operation of the page, such as those required for the implementation of a service requested by the user. These are, for example, session cookies for language settings, login details and the shopping cart, or flash cookies for playing multimedia content.

In order to deploy the majority of cookies, the user’s approval is required. This includes all those cookies that are not technically necessary for the operation of the website, such as tracking cookies used in the context of retargeting, analytics cookies or social media cookies. The European directive did not indicate, however, how these instructions were to be applied. Particularly with regard to the declaration of consent by website users, the directive leaves countries a wide margin of implementation.

What will change with the new ePrivacy Regulation

The new Regulation on Privacy and Electronic Communications will be responsible for regulating the application of these instructions. The current draft prohibits all cookies that are not technically necessary, unless the user has given prior approval. The first draft only refers to web applications, but the new version of 22 March 2018 includes all types of machine-based communication, such as applications, email and the collection of metadata for VoIP calls. In addition, it also applies to communication between two machines, known as M2M.

The ePrivacy Regulation will also affect international communication service providers, since it stipulates that its rules will apply to all terminal devices located within the borders of the EU. In this respect, it is irrelevant where the data processing of these services takes place.

For example, in the case of the US, data protection rules are far less strict. In the so-called Microsoft-Ireland case, a US court sought to compel the tech giant to make the data of its European customers accessible to the US government. Microsoft is headquartered in the United States and is therefore subject to the legislation applicable in that country. However, the company’s data is stored and protected in Germany through a Deutsche Telekom subsidiary called T-Systems. Taking into account that US legislation only applies within its own territory, the claim could initially be avoided, but the truth is that the proceedings are still ongoing. It remains to be seen to what extent European and US legislation will interfere with each other in the future.

Given that the scope of application of the ePrivacy Regulation extends to all terminal devices accessing communication services in Europe, US companies will have to consider whether to localise their offerings for Europe, thereby limiting their options for placing targeted advertising, or whether to make their customers “pay up”.

Content of the current European cookie law

Through the directive, the European Union provides greater protection for the personal data of Internet users and distinguishes between technically necessary and non-necessary cookies:

  1. Technically necessary cookies: necessary data storage includes cookies that are key to the operation of a website. This means, for example, saving login details, the shopping cart or the language selection by means of so-called session cookies (which are deleted when the browser is closed).
  2. Technically non-necessary cookies: text files are considered non-necessary cookies when they not only serve no purpose for the functionality of the website, but also collect other data. These include:
  • Tracking cookies
  • Targeting cookies
  • Analytics cookies
  • Social media cookies

According to the cookie law, necessary cookies can be set from the outset, that is, without the user’s prior consent. By contrast, visitors to a website must give their consent before cookies store non-necessary data. Therefore, the EU cookie directive requires an opt-in solution for non-necessary cookies.

This is the difference between opt out and opt in:

  • Opt out: cookies are set from the outset; users can only object to the storage of cookies later.
  • Opt in: cookies are not set from the outset, but only once the user agrees to the storage of data.
Note

The CJEU judgment of 1 October 2019 dismantles this differentiation de facto, by deeming opt in mandatory even where no personal data is handled. It is not yet clear whether it will also be mandatory in the case of technical cookies.

The current status of the ePrivacy Regulation

The first draft of the ePrivacy Regulation required manufacturers to set the highest level of privacy in browser settings. In this way, the browser would not accept third-party cookies and the banners that are currently so widely used would be eliminated, as users would have to actively decide to accept cookies each time they install software. This requirement was based on the principle of “privacy by design” already established in the GDPR. However, a more recent draft softens the rules on browser settings. The user will then have to continue deciding on a domain-by-domain basis whether or not to accept cookies.

The so-called prohibition of tying states that the use of a website may not depend on whether users agree to the use of cookies. However, there are legitimate purposes that may require the use of cookies. For example, if a user needs to identify themselves to carry out online banking transactions or wishes to use the shopping cart of an online store, cookies are often required. If website operators clearly inform users of the purpose, consent and use may be linked.

Opt in, opt out: what is recommended?

The European cookie directive applicable until now did not make it very clear whether the user has to confirm the use of cookies before they record their data (opt in), or whether they can be used from the outset without any problem (opt out). Owing to this ambivalence, it was applied in different ways across all the member countries, until the entry into force of the GDPR. Most European Union states integrated the directive into their national legal frameworks, although some opted for opt in and others for opt out, and there were even countries that never quite made a decision on the matter. In short, the application of the cookie law in the European Union is anything but uniform.

Application of the cookie law in Spain

The cookie law is contained in Royal Decree-Law 13/2012 of 30 March 2012, published in the Official State Gazette (BOE) on 31 March 2012 and in force since 1 April of that same year (compliance is mandatory under penalty of sanction). Reflecting the 2009 European Directive, this decree-law is integrated into Law 34/2002 of 11 July on information society services and electronic commerce, expanding its Article 22 with the European cookie directive. It makes clear the need to obtain the user’s consent regarding the use of their data through the installation on the terminal device of storage mechanisms such as cookies, and the need to notify the user in advance. Only those cookies necessary for the operation of the page are excluded.

A year later, in 2013, the Spanish Data Protection Agency published its Guide on the use of cookies, which sets out, on the basis of the European law, what must be disclosed, when and how.

It specifies the procedure to be used to explain the use of cookies to the user and request their consent (welcome page, pop-up window, header or footer, a prior acceptance step before downloads or playback), as well as which storage mechanisms are excluded from the rules, such as login, authentication, personal settings or session (token) cookies.

In general, the storage of cookies not necessary for the page must be consented to by the user, who must be informed about their intended use, what information they store, and whether or not they can identify the user, even if the user has configured the browser to accept a certain type of cookie. It is common to include a link to the data protection page containing a Cookie Policy with the following information:

  • What data is collected
  • Why this data is stored
  • For how long it will be stored
  • Who is responsible for storing the information
  • How consent can be withdrawn

It is important to provide information about cookies in the privacy policy in a clear, unequivocal and always accessible manner. Whether to use a banner, a pop-up window or a separate page depends on several criteria, mainly technical ones. A pop-up window could be incompatible with some browsers and therefore be blocked, while a separate web page could confuse the user and increase the bounce rate.

Cookies and data protection: what will happen in the future?

Website administrators will need to closely follow developments in the application of the so-called cookie law, since the legal situation will change definitively with the ePrivacy Regulation. Although it is not yet clear how strict it will be, this new regulation contains further provisions on the security of users’ personal data. But as long as the ePrivacy Regulation is not yet legally binding, cookies fall within the sphere of personal data as defined in Chapter 1 of the GDPR, since they collect data that makes the user identifiable in any way (identification number, user profile, etc.).

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.