> Currently our website contains one cookie that we do not use, but is essential for part of the site to operate. At present we have left this in place across the site, as we’re unable to remove it from one part of the site without affecting another. This session cookie is set on a user’s arrival to the site - at which time they’re informed that the cookie has been set - and is deleted when a user leaves the site.
I'm fairly sure the advice from the ICO that I read earlier was quite blunt about cookies that were not strictly necessary: you can't set them without consent just for your own convenience.
There is a silly box at the top of their page that asks you to accept cookies and tells you off if you click "Continue" without doing so, which seems entirely contrary to the principle of this new law to me, before you even get to this mysterious cookie they apparently set anyway.
The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner, albeit that it probably shouldn't be set until you enter the part of the site that requires it.
Government IT moves at a glacial pace, and just like everyone else they're still trying to figure out how this stuff should work. That's why they've deferred enforcement for a year.
> The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner
They say that, but it is easily demonstrable that running a web site providing static content such as they do does not require the use of any cookies or similar technology at all to provide the service the user is requesting: millions of web sites manage it every day. As you say, if only part of their site requires the cookie for some genuine reason, perhaps they should only set it there. In any case, there is really no excuse for not explaining properly what the cookie is for or for cluttering up the screens of visitors who don't check your "do whatever you want" button just to make the extra panel go away.
Bottom line: the exemption is not for cookies that are required because you hired poorly trained web developers or picked an inconvenient tool somewhere on your hosting platform. It's for cookies that are essential to providing the service that visitors are expecting. The ICO themselves have been very clear on this in the guidance they published in the run up to the handover, and their own site is flagrantly violating at least the spirit of the rule if not the letter of the law -- which AIUI they have responsibility for interpreting in the UK, so if they can't get it right, what hope is there for anyone else?
Comments
From the linked page:
> Currently our website contains one cookie that we do not use, but is essential for part of the site to operate. At present we have left this in place across the site, as we’re unable to remove it from one part of the site without affecting another. This session cookie is set on a user’s arrival to the site - at which time they’re informed that the cookie has been set - and is deleted when a user leaves the site.
I'm fairly sure the advice from the ICO that I read earlier was quite blunt about cookies that were not strictly necessary: you can't set them without consent just for your own convenience.
There is a silly box at the top of their page that asks you to accept cookies and tells you off if you click "Continue" without doing so, which seems entirely contrary to the principle of this new law to me, before you even get to this mysterious cookie they apparently set anyway.
The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner, albeit that it probably shouldn't be set until you enter the part of the site that requires it.
Government IT moves at a glacial pace, and just like everyone else they're still trying to figure out how this stuff should work. That's why they've deferred enforcement for a year.
> The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner
They say that, but it is easily demonstrable that running a web site providing static content such as they do does not require the use of any cookies or similar technology at all to provide the service the user is requesting: millions of web sites manage it every day. As you say, if only part of their site requires the cookie for some genuine reason, perhaps they should only set it there. In any case, there is really no excuse for not explaining properly what the cookie is for or for cluttering up the screens of visitors who don't check your "do whatever you want" button just to make the extra panel go away.
Bottom line: the exemption is not for cookies that are required because you hired poorly trained web developers or picked an inconvenient tool somewhere on your hosting platform. It's for cookies that are essential to providing the service that visitors are expecting. The ICO themselves have been very clear on this in the guidance they published in the run up to the handover, and their own site is flagrantly violating at least the spirit of the rule if not the letter of the law -- which AIUI they have responsibility for interpreting in the UK, so if they can't get it right, what hope is there for anyone else?