Culture secretary says move could lead to an end to irritating cookie popups and consent requests online
No it won't. Unless you ban EU citizens visiting your website and your website doesn't make business with other businesses in EU.
Britain will attempt to move away from European data protection regulations as it overhauls its privacy rules after Brexit, the government has announced.
Other countries like Canada implemented GDPR directive. EU required this from Canada, Japan and other countries to make some custom/tariff -free deals. Looks like UK wants to break away from dealing with EU at all?
Unless you ban EU citizens visiting your website and your website doesn't make business with other businesses in EU.
You can simply break the law and ignore the EU. The cookie popup sanctions are not criminal and unless you are very high profile business, nobody cares about you. Nobody is going to come after you.
The only regulator that international developers need to worry is the SEC from United States, because they pursue for US victims cross border. But the get on the bad side of the SEC you need to do something really stupid.
The maximum fines for breaking the GDPR is up to 4% of your global turn over. If it gets to that they can seize any assets in the EU, including any revenue earned in the EU up to the amount of the fine. Potentially directors can attract criminal risk by refusing to pay the fine(s), leading to an international arrest warrant. Obviously this is the most extreme case, but it is generally is easier to just comply with the law like a reasonable person.
I filed several complaints with unauthorized newsletters and failing to comply to my GDPR requests. German officials went after the companies and asked them to provide the necessary information. For sure it took its time but it worked and for the companies it's been a warning shot.
Irritating cookie popups are not mandated by GDPR; the opposite is true and most cookie popups are non-compliant with the legistration.
If the ICO (UK regulator) actually did its job then this would be solvable under the existing powers, but it's done very little:
Also, the cookie popups are not an immediate consequence of GDPR, but rather of its interplay with another directive from 2002 [0]. The EU has of course taken notice of the irritation of the public and is trying to improve on the state of affairs with the proposed ePrivacy Regulation [1].
Practically the UK must maintain an adequacy agreement with the European Commission so any changes would necessarily be constrained by that. Given that much of what became the GDPR was developed by British civil servants and in line with what the UK wanted to achieve at the time I suspect there is more than a little showboating going on here from HMG.
No it won't. Unless you ban EU citizens visiting your website and your website doesn't make business with other businesses in EU.
I strongly dislike the move too but this is true. The popups are often based on geolocation by ip. Jurisdictions with GDPR get the pop up and those without don’t. If you want to test this go to the Washington Post on an EU/UK ip and an American ip, clearing cookies in between visits and see the difference for yourself.
Comments
No it won't. Unless you ban EU citizens visiting your website and your website doesn't make business with other businesses in EU.
Other countries like Canada implemented GDPR directive. EU required this from Canada, Japan and other countries to make some custom/tariff -free deals. Looks like UK wants to break away from dealing with EU at all?
You can simply break the law and ignore the EU. The cookie popup sanctions are not criminal and unless you are very high profile business, nobody cares about you. Nobody is going to come after you.
The only regulator that international developers need to worry is the SEC from United States, because they pursue for US victims cross border. But the get on the bad side of the SEC you need to do something really stupid.
The maximum fines for breaking the GDPR is up to 4% of your global turn over. If it gets to that they can seize any assets in the EU, including any revenue earned in the EU up to the amount of the fine. Potentially directors can attract criminal risk by refusing to pay the fine(s), leading to an international arrest warrant. Obviously this is the most extreme case, but it is generally is easier to just comply with the law like a reasonable person.
You should doubt this.
I filed several complaints with unauthorized newsletters and failing to comply to my GDPR requests. German officials went after the companies and asked them to provide the necessary information. For sure it took its time but it worked and for the companies it's been a warning shot.
But you know that with asking the right questions you are able to receive evidence that the company is committing a criminal offense.
Irritating cookie popups are not mandated by GDPR; the opposite is true and most cookie popups are non-compliant with the legistration. If the ICO (UK regulator) actually did its job then this would be solvable under the existing powers, but it's done very little:
https://www.enforcementtracker.com/
Also, the cookie popups are not an immediate consequence of GDPR, but rather of its interplay with another directive from 2002 [0]. The EU has of course taken notice of the irritation of the public and is trying to improve on the state of affairs with the proposed ePrivacy Regulation [1].
[0] https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
[1] https://en.wikipedia.org/wiki/EPrivacy_Regulation
Practically the UK must maintain an adequacy agreement with the European Commission so any changes would necessarily be constrained by that. Given that much of what became the GDPR was developed by British civil servants and in line with what the UK wanted to achieve at the time I suspect there is more than a little showboating going on here from HMG.
This will partly depend on whether the EU also decide to change regulations around cookie consent.
You might be interested to follow the EU's ePrivacy Regulation proposals, described here: https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r... (and in particular, the top-level item related to cookies).
I strongly dislike the move too but this is true. The popups are often based on geolocation by ip. Jurisdictions with GDPR get the pop up and those without don’t. If you want to test this go to the Washington Post on an EU/UK ip and an American ip, clearing cookies in between visits and see the difference for yourself.
Anything to do with the EU has become toxic to the governing party.