Addressing cookie compliance issues with your website
A technical approach to website cookie compliance
To help reduce your risk of receiving a lawsuit, we recommend adding several components to your website. These include a consent management platform, cookie consent banner, and a tool that generates privacy-related policies that explain how your site attempts to protect personal information.
A consent management platform requests, captures, and stores user consent for data collection, cookies, and tracking pixels. One component of the platform is the visible cookie consent banner that appears on the site, requiring visitors to clearly indicate their choice to opt-in or opt-out.
The cookie consent banner enables a visitor to opt-in or opt-out to the use of cookies and tracking pixels on your site.
For our clients, we are deploying a cookie management platform from Usercentrics, a leading company in the space.
Types of cookies
Essential cookies: Necessary for the website to function properly, such as security, session management, login authentication, and shopping cart cookies. These cannot be turned off by the user as they are required for the site to work.
Marketing cookies: Used to track visitors and deliver targeted advertising, such as Google Ads, Meta Pixel, remarketing, and conversion-tracking cookies.
Functional cookies: Enhance the website experience by remembering preferences and enabling added features, such as language settings, embedded videos, live chat, and personalization.
More details on how we are approaching the issues surrounding compliance
The key question: Should "Accept" be the default state or should it be "Deny"?
One of the biggest debates is whether or not to leave cookies on – thus being served or ‘firing’ – before the visitor grants consent. In essence, do we assume the visitor’s answer is “Do not do it without my permission – unless I opt-in,” or do we assume the answer is, “I am okay with it as long as I don’t say no – unless I opt-out.”
This is known as an Opt-in consent model (“Do not do it without my permission”) vs. an Opt-out model (“I am okay with it as long as I don’t say no”). Stricter regulations like the EU’s GDPR require Opt-in consent, meaning a visitor must click Accept before a cookie can be served. That means upon arrival, all cookies must be turned off. If this does not happen, the site is in violation. If the visitor does not click Accept, no cookies can be served at any point during the session.
The other model is Opt-out consent. In this case, cookies are allowed to fire unless and until the visitors specifically clicks Deny. The problem with this model from a pure privacy perspective is that the visitor’s privacy rights were already impacted because cookies fired upon arrival, before they’d ever had an opportunity to select Deny.
We recommend Opt-in for increase the level of protection
Because an Opt-in model is stricter and more protective of visitor privacy, we recommend that approach. That is what we are deploying for clients out-of-the-box. However, there are cases when other factors could outweigh the additional legal protection an Opt-in model provides.
For example, if paid ads, in-depth site analytics, or embedded video are crucial to your business an Opt-out model may be the right option. Similarly, e-commerce businesses may be better served by an Opt-out model.
We can discuss options with you if you fall into one of those categories.
What is a consent management platform?
A consent management platform requests, captures, and stores user consent for data collection, cookies, and tracking pixels. One component of the platform is the visible cookie consent banner that appears on the site, requiring visitors to clearly indicate their choice to opt-in or opt-out.
How consent works with our recommended solution
Step 1:
When a visitor comes to your site – whether they enter at the home page or any other page – they will see a banner like this.
By default, “Marketing” and “Functional” cookies are turned off. This is considered the strongest mode of privacy protection. “Essential” cookies cannot be turned off by the user as they are required for a site to function. These do not share data with third-party services, so they do not pose problems.
At this point, the user can toggle one or both “Marketing” and “Functional” settings on, or they can leave both alone and select “Deny” or “Accept All.”
Step 2:
If the user chooses “More Information,” they will see the following screen. It includes a description of the three types of cookies and gives them the option to toggle their choices. Even after they have made a selection to “Deny” or “Accept All,” they can always change their selections by clicking the “Privacy Settings” link at the bottom of the page.
Step 3:
From here, they can drill down deeper to see the full list of cookies served. By expanding one of the categories by clicking the down arrow on the right side, the full list of cookies within that category are displayed. This allows visitor to have finite controls over what to accept or deny.
Once the visitor chooses Accept or Deny the website now knows what it can do. For those opting to Accept, the site will function as usual. It will serve all cookies and tracking pixels necessary to make services work and enable marketing and analytics.
If the visitor chooses Deny, no Marketing or Functional cookies can be served.
Step 4:
If the visitor chooses Deny, certain services on the site may not work. Some will be invisible to the visitor, such as tracking for analytics and marketing. Others, however, will be visible. For example, if the site uses embedded video, social media feeds, or Google Maps, a dialog box like the one shown will appear explaining why the service is not functional.
From this dialog box, the visitor can choose Accept to enable the specific service to function, thus overriding the previous request to Deny.
Who is ultimately responsible?
Compliance is ultimately the responsibility of the website owner. It is the company that owns the website that is the party named in, and responsible for, litigation. Our agency is not a law firm and cannot provide legal advice or guarantee that a particular website configuration will satisfy every applicable privacy law.
More details on how we are approaching the issues surrounding compliance
This article provides general educational information and is not legal advice. Privacy requirements vary by jurisdiction and circumstance. Website owners are responsible for determining and meeting the legal requirements applicable to their businesses and should consult qualified legal counsel when appropriate.
VISIT OUR OFFICE
LET'S TALK
Call: 850-391-8745
Text: 850-391-8743