On January 17, 2023, the European Data Protection Board (“EDPB”) Cookie Banner Taskforce adopted a report which provides useful guidance on cookie banners. The EDPB’s report is available here.
The Cookie Banner Taskforce was established by EU data protection authorities to examine and provide a coordinated response to the complaints raised by the non-profit organization None of Your Business (NOYB), which is co-founded by Max Schrems.
The positions presented in the report reflect the “common denominator” of the EU data protection authorities’ interpretation of the e-Privacy Directive and the GDPR’s provisions regarding the use of cookies and deployment cookie banners.
Some of the key highlights include the following:
- Legal basis for subsequent processing: The report confirms that, while placing cookies to users’ devices is subject to the e-Privacy Directive, the GDPR will apply to any subsequent processing operation that is carried out after cookies are placed. This means that such subsequent operations do not necessarily have to be based on “consent” and website owners can rely on an another lawful basis under Article 6 of the GDPR. If, however, website owners rely on consent for “subsequent processing”, the report indicates that they can collect that at the same time as they collect the consent required by the e-Privacy Directive. That said, the authorities take the view that, if a website owner fails to comply with the e-Privacy Directive when dropping cookies (in particular when consent is not obtained validly), any subsequent processing will automatically result in infringement of the GDPR.
- One-stop shop: The report clarifies that the One Stop Shop mechanism under the GDPR (which allows EU based companies to deal with a single supervisory authority for most of their processing activities) is not applicable where the e-Privacy Directive applies. This means, regardless of where the relevant organization is based (whether in the EU or not) or the nature of its data processing operations (whether cross-border or not), it is possible for multiple authorities to take enforcement action in respect of alleged infringements of the e-Privacy Directive.
- Pre-ticked box: Consistent with past guidance of the EDPB and CJEU case law, pre-ticked accept boxes are not sufficient to obtain consent so should not be used, including on the second layer of the cookie banner.
- Design: The report highlights certain problematic practices when it comes to designing cookie banners. These include:
- cookie banners where the only action offered to users (other than granting consent) consists of a link behind wording such as “refuse” or “continue without accepting” embedded in a paragraph of text (and where there is no sufficient visual support to draw an average user’s attention that they can take this action);
While the positions outlined in the report do not constitute stand-alone recommendations or findings to obtain a greenlight from a competent data protection authority, the report presents a “minimum threshold” for data protection authorities and therefore provide guidances to authorities on how to handle complaints in connection with cookies.