SlideShare uma empresa Scribd logo
1 de 28
Baixar para ler offline
© 2020 TrustArc Inc. Proprietary and Confidential Information.
Cookie Consent Regulatory Updates:
How to Maintain Compliance
“A bite at a time…”
September 30, 2020
1
Speakers
2
Ralph T O'Brien
CIPM, CIPT, CIPP/E, BSi LA,
CISMP (Dis), FIP
Principal Consultant, Europe
TrustArc
Matt Ferrell
Sr. Product Manager
TrustArc
Agenda
3
● Recent EEA rulings and legal commentary
(CJEU ruling, German Court, EDPB, Belgian DPA, Ireland DPA, and CNIL)
● Upcoming regulatory requirements
(CCPA, ePrivacy regulation)
● Industry framework updates
(IAB EU and CCPA)
© 2019 TrustArc Inc Proprietary and Confidential Information
EEA:
Recent rulings and legal commentary
ePrivacy is a directive not a regulation…
…Therefore although most member state have
adopted a law in the spirit of the ePrivacy
directive, definitions, laws, guidance and
enforcement differ from country to country across
the EEA…
…A new ePrivacy regulation has been proposed
to arrive in conjunction with the 2016 GDPR, but
has stalled through multiple EU presidencies.
Wide scale non-compliance, and little
enforcement.
The trouble with cookies…
A number of judgements…
● Summary and legal context
● Planet49 use case judgement
● CJEU holding
○ Opt-in versus opt-out
○ Specific consent
○ Consent for non-personal data cookies
● Telemedia Act interpretation
Website operators should…
● Disclose information about all cookie operations
requiring consent, including the duration and third
parties as well as their roles and functions.
● Obtain consent through an affirmative opt-in
action.
● Avoid bundling consent. Users should be given
the ability to make granular decisions.
● Implement a zero-cookie load solution.
● Provide a method for a user to withdraw consent
at anytime.
● Keep a record of consent for accountability
purposes.
6
Bundesgerichtshof & Court of Justice of the European Union
In Practice
● May 4, 2020 EDPB adoption of consent
guidelines
● Elements of valid consent
● Differences from Article 29 Working Party
consent guidelines (April 2018)
○ Cookie walls
○ Implied consent from ambiguous actions
(are not consent)
● Key takeaways and recommendations
Key takeaways and recommendations
● Tear down that (cookie) wall!
● Consent manager cannot deem scrolling,
swiping, or continued browsing of a
webpage or use of a mobile app to
constitute consent.
European Data Protection Board (EDPB)
In Practice
‘GDPR experience’ for EEA
CCPA Banner
9
Mobile Apps
July 2019
● Disclose all third-party recipients before
obtaining consent.
● Provide granular consent for each purpose
of processing.
● Provide an easy way to withdraw consent.
● Limit cookie lifespan to 13 months for
analytics cookies and other cookies to 25
months.
● Keep a record of consent.
January 2020, CNIL draft consent recs.
1. Use simple consent UI, including a UI to
decline cookies.
2. Use a neutral design. No nudging users to
consent.
3. Record; (1) individual user consent, and
(2) proof that consent mechanism is valid.
4. Transparency;
a. Level One: purposes of the cookies,
complete list of companies using the
cookies and their roles, and a mechanism
to enable the user to opt in or decline the
use of non-essential cookies.
b. Level Two: Describe the scope of the
consent given, including whether the
consent covers other websites.
CNIL - French Data Protection Authority
French Council of State held in June 2020 that CNIL cannot
ban cookie walls altogether, but that doesn’t make cookie
walls legal for data subjects in France.
In Practice
√
X
April 2020 cookie sweep, enforcement Oct…
● Analytics cookies require prior consent.
● Zero cookie load.
● Consent via a cookie banner or pop-up is
acceptable, if...
○ Notice given for specific purposes of non-
required cookies and allows for rejecting
non-required cookies,
○ No "nudging" a user into accepting
cookies.
○ Checkboxes or toggles clearly marked as
ON or OFF.
● Users must be able to change their cookie
preferences at any time.
● A cookie used to store user's consent
should have a lifespan of 6 months.
● No implied consent. No pre-checked
boxes and or sliders set to ‘on’.
● A cookie consent banner must not obscure
the text of the privacy or cookie notice.
Users must always be able to read the
cookies and privacy notices without any
cookies being set (except for essential
cookies).
● Accessibility must be taken into account in
designing interfaces to accommodate
people with vision impairments or color
blindness.
DPC - Irish Data Protection Authority
13
5 October Deadline
In Practice
14
Belgian Data Protection Authority (the "DPA") cookie guidance, Apr 2020
Cookie Lifespan
● No unlimited lifespan.
● Delete essential cookies once their purpose has been achieved.
Consent
● Obtain consent for all non-essential cookies (including analytics and social media plugins).
● Obtain consent prior to use of cookies.
● Offer granular consent options.
● Keep a record of consent.
● Consent should be as easy to withdraw as it is to give.
● “Cookie walls” are not permitted.
● Consent must be from unambiguous affirmative action.
Belgian Data Protection Authority
Transparency
● Give all relevant information prior to obtaining consent, including...
○ The entity responsible for the use of cookies,
○ The cookies’ purposes,
○ The data collected through cookies, and
○ The cookie lifespan.
● Must give notice of users’ rights, including the right to withdraw consent.
● Have a cookie notice which discloses...
○ The types of cookies used
○ Cookie purposes and lifespan
○ Whether third-parties have access to such cookies
○ Information about how to delete cookies;
○ The legal basis for the use of cookies
○ Individuals’ rights and the ability to make a complaint to the
supervisory authority; and
○ Information about any automated decision making, including profiling.
Belgian Data Protection Authority
In Practice
Stand-alone
Embedded
17
© 2019 TrustArc Inc Proprietary and Confidential Information
Upcoming Regulatory Requirements
● Are the CCPA Regulations final
yet?
● When will the CCPA Regulations
be enforced? (Oct. 1, 2020…
probably)
○ https://oal.ca.gov/july-1-effective_date/
○ https://oal.ca.gov/october-1-effective_date/
Key takeaways and recommendations
● Interpret browser privacy settings as a
valid request to opt out of the sale of
personal information
● For users opting in after having opted out,
a second confirming step is required. This
means that a user must clearly request to
opt-in and then, in a separate step, confirm
their choice to opt in.
CCPA
In Practice
DNT is back!
Are you sure?
20
© 2019 TrustArc Inc Proprietary and Confidential Information
Industry Framework
IAB EU/CCPA
IAB EU
IAB CCPA
© 2019 TrustArc Inc Proprietary and Confidential Information
Simplify Global Cookie Compliance
Deliver a branded
experience
Customize the full consent
experience from design to
delivery, all tailored to your brand
Take control of GDPR, CCPA, and beyond
Demonstrate
compliance
Receive a detailed report that
provides an audit trail on the
consent behaviour of your
users
Meet global
regulations
Configure the consent experience
to display the applicable consent
banner based on user's location
Understand
website’s tracking
behaviour
Automatically detect and
categorize tracker changes
through scheduled website
scans, reflecting updates in your
Cookie Policy
With 7 years of proven success, our industry-leading
Cookie Consent Manager provides a configurable
solution that enables organizations to meet cookie
compliance requirements across the globe while
delivering a branded consent experience.
24
Deliver a customized consent experience
Meet global consumer consent requirements and display the applicable consent banner based on
user’s geolocation.
Configure the
consent approach
Customize the full consent
experience, from design to
delivery, all tailored to your
brand
Deploy with ease
Add a simple JavaScript
tag to the website for quick
deployment
Integrated solution
Integrate with your tag
management system and
meet different consent use
cases, including “zero-
cookie load”
Multi-Language Support
Detect browser language
preference and support any
languages including 45
default languages
25
© 2019 TrustArc Inc Proprietary and Confidential Information
Q&A
Upcoming Webinars
27
Past Webinars
Building Consumer Trust through Data
Subject Rights / DSAR Management
October 14, 2020 @ 9:00
PST
The Brazilian LGPD is Here: What You Need
to Know
Free Download
How to Leverage Your GDPR Compliance for
CCPA, Privacy Shield & More New
Requirements
Free Download
© 2019 TrustArc Inc Proprietary and Confidential Information
Thank You!
See http://www.trustarc.com/insightseries for the 2020
Privacy Insight Series and past webinar recordings.
If you would like to learn more about how TrustArc can support you with compliance,
please reach out to sales@trustarc.com for a free demo.

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

Privacy Frameworks: The Foundation for Every Privacy Program
Privacy Frameworks: The Foundation for Every Privacy ProgramPrivacy Frameworks: The Foundation for Every Privacy Program
Privacy Frameworks: The Foundation for Every Privacy Program
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
Privacy 2020: Recap & Predictions
Privacy 2020: Recap & PredictionsPrivacy 2020: Recap & Predictions
Privacy 2020: Recap & Predictions
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement action
 
CCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to KnowCCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to Know
 
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskAssessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
 
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy Update
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
 
Becoming PIPL Compliant In No Time
Becoming PIPL Compliant In No TimeBecoming PIPL Compliant In No Time
Becoming PIPL Compliant In No Time
 
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
 
COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Third-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & ActThird-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & Act
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 

Semelhante a Cookie Consent Regulatory Updates: How to Maintain Compliance

A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdfA-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
Adzappier
 
Cookies: best practice September 2012 by Fedelma Good, Barclays
Cookies: best practice September 2012 by Fedelma Good, BarclaysCookies: best practice September 2012 by Fedelma Good, Barclays
Cookies: best practice September 2012 by Fedelma Good, Barclays
theidm_quals
 
What is GDPR ? by M32
What is GDPR ? by M32What is GDPR ? by M32
What is GDPR ? by M32
Pneus Touchette Distribution inc.
 
Cookie Consent and Authorized Data Collection_Mar23.pdf
Cookie Consent and Authorized Data Collection_Mar23.pdfCookie Consent and Authorized Data Collection_Mar23.pdf
Cookie Consent and Authorized Data Collection_Mar23.pdf
Adzappier
 
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
Agenda 21   eu cookie seminar - david naylor - field fisher waterhouseAgenda 21   eu cookie seminar - david naylor - field fisher waterhouse
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
agenda21
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
Agenda21   eu cookie seminar - dominic trigg - rocket fuelAgenda21   eu cookie seminar - dominic trigg - rocket fuel
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
agenda21
 

Semelhante a Cookie Consent Regulatory Updates: How to Maintain Compliance (20)

A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdfA-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
A-Z Guide to Cookie Consent and Cookie Laws Around the World.pdf
 
The DMA conference 2012
The DMA conference 2012The DMA conference 2012
The DMA conference 2012
 
Cookies: best practice September 2012 by Fedelma Good, Barclays
Cookies: best practice September 2012 by Fedelma Good, BarclaysCookies: best practice September 2012 by Fedelma Good, Barclays
Cookies: best practice September 2012 by Fedelma Good, Barclays
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
 
What is GDPR ? by M32
What is GDPR ? by M32What is GDPR ? by M32
What is GDPR ? by M32
 
Cookie Consent and Authorized Data Collection_Mar23.pdf
Cookie Consent and Authorized Data Collection_Mar23.pdfCookie Consent and Authorized Data Collection_Mar23.pdf
Cookie Consent and Authorized Data Collection_Mar23.pdf
 
Marketing Meets Privacy_ What You Need to Know in 2023.pdf
Marketing Meets Privacy_ What You Need to Know in 2023.pdfMarketing Meets Privacy_ What You Need to Know in 2023.pdf
Marketing Meets Privacy_ What You Need to Know in 2023.pdf
 
DMA Cookies update
DMA Cookies updateDMA Cookies update
DMA Cookies update
 
Cookies and the EU privacy directive: what it means for you
Cookies and the EU privacy directive: what it means for youCookies and the EU privacy directive: what it means for you
Cookies and the EU privacy directive: what it means for you
 
Cookies and the EU privacy directive: what it means for you
Cookies and the EU privacy directive: what it means for you Cookies and the EU privacy directive: what it means for you
Cookies and the EU privacy directive: what it means for you
 
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
Agenda 21   eu cookie seminar - david naylor - field fisher waterhouseAgenda 21   eu cookie seminar - david naylor - field fisher waterhouse
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
 
Data Restart 2022: Marina Mchedlishvili - How to build strong data strategies...
Data Restart 2022: Marina Mchedlishvili - How to build strong data strategies...Data Restart 2022: Marina Mchedlishvili - How to build strong data strategies...
Data Restart 2022: Marina Mchedlishvili - How to build strong data strategies...
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 
Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011
 
DV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeDV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal Landscape
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Accelerating Your GDPR Compliance with the WSO2 Platform
Accelerating Your GDPR Compliance with the WSO2 PlatformAccelerating Your GDPR Compliance with the WSO2 Platform
Accelerating Your GDPR Compliance with the WSO2 Platform
 
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
Agenda21   eu cookie seminar - dominic trigg - rocket fuelAgenda21   eu cookie seminar - dominic trigg - rocket fuel
Agenda21 eu cookie seminar - dominic trigg - rocket fuel
 
Cookies and European Union Law
Cookies and European Union LawCookies and European Union Law
Cookies and European Union Law
 
eBusiness Club "Demystifying the EU Cookie Law presentation, Geldards
eBusiness Club  "Demystifying the EU Cookie Law presentation, GeldardseBusiness Club  "Demystifying the EU Cookie Law presentation, Geldards
eBusiness Club "Demystifying the EU Cookie Law presentation, Geldards
 

Mais de TrustArc

TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 

Mais de TrustArc (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 

Último

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

Cookie Consent Regulatory Updates: How to Maintain Compliance

  • 1. © 2020 TrustArc Inc. Proprietary and Confidential Information. Cookie Consent Regulatory Updates: How to Maintain Compliance “A bite at a time…” September 30, 2020 1
  • 2. Speakers 2 Ralph T O'Brien CIPM, CIPT, CIPP/E, BSi LA, CISMP (Dis), FIP Principal Consultant, Europe TrustArc Matt Ferrell Sr. Product Manager TrustArc
  • 3. Agenda 3 ● Recent EEA rulings and legal commentary (CJEU ruling, German Court, EDPB, Belgian DPA, Ireland DPA, and CNIL) ● Upcoming regulatory requirements (CCPA, ePrivacy regulation) ● Industry framework updates (IAB EU and CCPA)
  • 4. © 2019 TrustArc Inc Proprietary and Confidential Information EEA: Recent rulings and legal commentary
  • 5. ePrivacy is a directive not a regulation… …Therefore although most member state have adopted a law in the spirit of the ePrivacy directive, definitions, laws, guidance and enforcement differ from country to country across the EEA… …A new ePrivacy regulation has been proposed to arrive in conjunction with the 2016 GDPR, but has stalled through multiple EU presidencies. Wide scale non-compliance, and little enforcement. The trouble with cookies…
  • 6. A number of judgements… ● Summary and legal context ● Planet49 use case judgement ● CJEU holding ○ Opt-in versus opt-out ○ Specific consent ○ Consent for non-personal data cookies ● Telemedia Act interpretation Website operators should… ● Disclose information about all cookie operations requiring consent, including the duration and third parties as well as their roles and functions. ● Obtain consent through an affirmative opt-in action. ● Avoid bundling consent. Users should be given the ability to make granular decisions. ● Implement a zero-cookie load solution. ● Provide a method for a user to withdraw consent at anytime. ● Keep a record of consent for accountability purposes. 6 Bundesgerichtshof & Court of Justice of the European Union
  • 8. ● May 4, 2020 EDPB adoption of consent guidelines ● Elements of valid consent ● Differences from Article 29 Working Party consent guidelines (April 2018) ○ Cookie walls ○ Implied consent from ambiguous actions (are not consent) ● Key takeaways and recommendations Key takeaways and recommendations ● Tear down that (cookie) wall! ● Consent manager cannot deem scrolling, swiping, or continued browsing of a webpage or use of a mobile app to constitute consent. European Data Protection Board (EDPB)
  • 9. In Practice ‘GDPR experience’ for EEA CCPA Banner 9 Mobile Apps
  • 10. July 2019 ● Disclose all third-party recipients before obtaining consent. ● Provide granular consent for each purpose of processing. ● Provide an easy way to withdraw consent. ● Limit cookie lifespan to 13 months for analytics cookies and other cookies to 25 months. ● Keep a record of consent. January 2020, CNIL draft consent recs. 1. Use simple consent UI, including a UI to decline cookies. 2. Use a neutral design. No nudging users to consent. 3. Record; (1) individual user consent, and (2) proof that consent mechanism is valid. 4. Transparency; a. Level One: purposes of the cookies, complete list of companies using the cookies and their roles, and a mechanism to enable the user to opt in or decline the use of non-essential cookies. b. Level Two: Describe the scope of the consent given, including whether the consent covers other websites. CNIL - French Data Protection Authority French Council of State held in June 2020 that CNIL cannot ban cookie walls altogether, but that doesn’t make cookie walls legal for data subjects in France.
  • 12. April 2020 cookie sweep, enforcement Oct… ● Analytics cookies require prior consent. ● Zero cookie load. ● Consent via a cookie banner or pop-up is acceptable, if... ○ Notice given for specific purposes of non- required cookies and allows for rejecting non-required cookies, ○ No "nudging" a user into accepting cookies. ○ Checkboxes or toggles clearly marked as ON or OFF. ● Users must be able to change their cookie preferences at any time. ● A cookie used to store user's consent should have a lifespan of 6 months. ● No implied consent. No pre-checked boxes and or sliders set to ‘on’. ● A cookie consent banner must not obscure the text of the privacy or cookie notice. Users must always be able to read the cookies and privacy notices without any cookies being set (except for essential cookies). ● Accessibility must be taken into account in designing interfaces to accommodate people with vision impairments or color blindness. DPC - Irish Data Protection Authority
  • 15. Belgian Data Protection Authority (the "DPA") cookie guidance, Apr 2020 Cookie Lifespan ● No unlimited lifespan. ● Delete essential cookies once their purpose has been achieved. Consent ● Obtain consent for all non-essential cookies (including analytics and social media plugins). ● Obtain consent prior to use of cookies. ● Offer granular consent options. ● Keep a record of consent. ● Consent should be as easy to withdraw as it is to give. ● “Cookie walls” are not permitted. ● Consent must be from unambiguous affirmative action. Belgian Data Protection Authority
  • 16. Transparency ● Give all relevant information prior to obtaining consent, including... ○ The entity responsible for the use of cookies, ○ The cookies’ purposes, ○ The data collected through cookies, and ○ The cookie lifespan. ● Must give notice of users’ rights, including the right to withdraw consent. ● Have a cookie notice which discloses... ○ The types of cookies used ○ Cookie purposes and lifespan ○ Whether third-parties have access to such cookies ○ Information about how to delete cookies; ○ The legal basis for the use of cookies ○ Individuals’ rights and the ability to make a complaint to the supervisory authority; and ○ Information about any automated decision making, including profiling. Belgian Data Protection Authority
  • 18. © 2019 TrustArc Inc Proprietary and Confidential Information Upcoming Regulatory Requirements
  • 19. ● Are the CCPA Regulations final yet? ● When will the CCPA Regulations be enforced? (Oct. 1, 2020… probably) ○ https://oal.ca.gov/july-1-effective_date/ ○ https://oal.ca.gov/october-1-effective_date/ Key takeaways and recommendations ● Interpret browser privacy settings as a valid request to opt out of the sale of personal information ● For users opting in after having opted out, a second confirming step is required. This means that a user must clearly request to opt-in and then, in a separate step, confirm their choice to opt in. CCPA
  • 20. In Practice DNT is back! Are you sure? 20
  • 21. © 2019 TrustArc Inc Proprietary and Confidential Information Industry Framework
  • 23. © 2019 TrustArc Inc Proprietary and Confidential Information Simplify Global Cookie Compliance
  • 24. Deliver a branded experience Customize the full consent experience from design to delivery, all tailored to your brand Take control of GDPR, CCPA, and beyond Demonstrate compliance Receive a detailed report that provides an audit trail on the consent behaviour of your users Meet global regulations Configure the consent experience to display the applicable consent banner based on user's location Understand website’s tracking behaviour Automatically detect and categorize tracker changes through scheduled website scans, reflecting updates in your Cookie Policy With 7 years of proven success, our industry-leading Cookie Consent Manager provides a configurable solution that enables organizations to meet cookie compliance requirements across the globe while delivering a branded consent experience. 24
  • 25. Deliver a customized consent experience Meet global consumer consent requirements and display the applicable consent banner based on user’s geolocation. Configure the consent approach Customize the full consent experience, from design to delivery, all tailored to your brand Deploy with ease Add a simple JavaScript tag to the website for quick deployment Integrated solution Integrate with your tag management system and meet different consent use cases, including “zero- cookie load” Multi-Language Support Detect browser language preference and support any languages including 45 default languages 25
  • 26. © 2019 TrustArc Inc Proprietary and Confidential Information Q&A
  • 27. Upcoming Webinars 27 Past Webinars Building Consumer Trust through Data Subject Rights / DSAR Management October 14, 2020 @ 9:00 PST The Brazilian LGPD is Here: What You Need to Know Free Download How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requirements Free Download
  • 28. © 2019 TrustArc Inc Proprietary and Confidential Information Thank You! See http://www.trustarc.com/insightseries for the 2020 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.