COVID-19 Update: Artonezero are still operating as normal from home. Read more

Blog

Back to all blogs

How will GDPR affect your Cookie policy?

jade-wulfraat-96023-unsplash.jpg

Perhaps you haven’t thought about how GDPR compliance and cookies, but with GDPR just around the corner it is now more crucial than ever to find out how regulation changes will impact your organisation’s marketing.

In this article, we will look at how GDPR will affect the way you use web analytics tools, like cookies, in your organisation’s marketing strategy.

Cookies are familiar for most web users. Cookies and other web analytics tools allow business to monitor visitor engagement on their website and follow up with useful marketing content, such as emails and callbacks.

While Cookies are definitely useful for your marketing team, whether or not they are GDPR compliant is where the matter can get a little bit confusing.

What do GDPR guidelines say about Cookies and compliance?

Cookies mentioned only once in the GDPR guidelines:

‘Recital 30: Natural Persons may be associated with online identities…such as internet protocol addresses, cookie identifiers or other identifiers…This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.’

Put simply, this means; if you use Cookies to identify a device or the person who is using that device, it is now treated as personal data under GDPR.

While not all Cookies are used in a way that could identify website users, most of them are. This means that cookies used for analytics, advertising and functional services such as surveys and chat tools are at risk of GDPR non-compliance, a risk that comes with serious fines and penalties.

Why are cookies potentially GDPR non-compliant?

Cookies often contain pseudonymous identifiers to give them uniqueness, and under GDPR it is this uniqueness that qualifies them as personal data. So, any Cookie that is able to identify an individual, or able to treat them as unique without explicitly identifying them means that personal data is being processed.

Under GDPR, processing the personal data of EU citizens requires organisations to gain definite and provable consent. It is this factor which puts the use of cookies at risk of non-compliance.

What’s changing with consent?

One of the most crucial changes GDPR is making to the collection and processing of personal data is the need to gain valid consent. You can find more about that in our article What is GDPR and how will it impact your business? Since this is such a huge topic in itself, we will keep our focus to consent exclusively to how it applies to the use of Cookies in this article.

Implied consent is no longer enough: Previously, most organisations have relied on the ‘implied consent’, which means for example that visitors have offered an email or phone number, or they have visited your website and taken some kind of action. Under GDPR this is no longer enough. Individuals must give their consent via an affirmative action, such as clicking an opt-in box or setting preferences. A crucial point to remember is that an individual’s opt-in to one type of contact does not mean that your organisation can assume consent for all types of contact.

Withdrawal of consent must be made easy: Even after you have been given consent to process an individual’s data, you need to make it just as easy for them to change their preference. For example, if you ask for an individual’s consent via an opt-in-box, and the opt-out option must be equally as visible.

Soft Opt-in is not sufficient: No doubt you will be familiar with the “by using this site, you accept Cookies” message that pops up on websites; in fact, you most likely use a similar message on your own website. However, under GDPR, if there is no valid consent option then it does not count as consent at all. You must make it possible for the individual using your site to be able to accept or reject Cookies.

Can I continue to use Cookies under GDPR?

To put it simply, using Cookies in your organisation’s marketing strategy in an established way is going to become increasingly harder under GDPR. While Cookies are not banned under GDPR, if you can’t prove consent on an individual basis then you are at risk of non-compliance.

If you can prove that your organisation has a lawful ground to collect and process individual’s data, then you can continue to do so. However, since the majority of business rely on implied or opt-out consent it will become increasingly hard to prove lawful consent under the tighter requirements of GDPR.

In addition, The Privacy and Electronic Communications Regulations (PECR) (the ‘Cookie law’) is being updated and brought in line with GDPR. This will mean more restrictions on how and when data analytics tools like Cookies can be used.

How can I continue to get useful information about my leads?

There are still many ways for you to get information about your leads without using Cookies – it all comes down to consent.

The simple solution is to make it easy for your leads to give consent, and give them an equally easy option to opt-out. You can then continue to process their personal data, such as their name, email address etc. Moving forward this may even mean that your lead quality increases and you can begin engaging with people who are genuinely interested in what your business has to offer.

If you need more information about how GDPR affects your customer data, or if you have are concerns that your organisation is not compliant, then contact us today.

You may also like...

What to Consider when Migrating to a new CMS

What to Consider when Migrating to a new CMS

When migrating your organisation’s information to a new Content Management System (CMS), there are many factors to take into account. There are also many pitfalls to avoid, such as technical issues and poor user interfaces. To assist you and your organisation we have put together this article of important considerations to help you make an informed decision about migrating to a new CMS system.

Digital Marketing

Apr 13, 2017

Guide your users down the right path 6 website design tips to optimise user engagement

Guide your users down the right path: 6 website design tips to optimise user engagement

Website design is about far more than your site just looking nice. It’s about creating a site which optimises your users’ experience; both for them, and for you. A well designed site will allow your users to engage with you and to find out the information they need, but a really well-designed site will mean that they do it on your terms. Here are some of our top tips for enhancing user engagement via website design.

Digital Marketing

May 10, 2016

digital-marketing-1433427_1920.jpg

Five tactics to boost your digital marketing strategy in 2018

Every year the world of digital marketing keeps advancing and what worked well for you last year isn’t necessarily going to provide the same results this year. With this, if you want to stay ahead of the competition, you need to pay attention to the newest digital marketing tactics and make use of them in your own digital marketing strategy. In this article, we will take a look at some of this year’s newest digital marketing tactics and explore how you can use them to boost your own digital marketing strategy this year.

Digital Marketing

Feb 8, 2018

Some of our work

We'd love to hear from you!

Email anytime, or call us on 020 301 103 90 during office hours.