Europe’s top court says active consent is needed for tracking cookies

Comment

Image Credits: joyosity (opens in a new window) / Flickr (opens in a new window) under a CC BY 2.0 (opens in a new window) license.

Europe’s top court has ruled that pre-checked consent boxes for dropping cookies are not legally valid.

Consent must be obtained prior to storing or accessing non-essential cookies, such as tracking cookies for targeted advertising. Consent cannot be implied or assumed.

It’s a decision that — at stroke — plunges websites into legal hot water in Europe if their cookie notices don’t ask for consent first. As many don’t, preferring not to risk their ability to track users for ad targeting.

Now they could be risking a big fine under EU privacy laws if they don’t obtain valid consent for tracking.

Sites that have relied upon opting EU users into ad-tracking cookies in the hopes they’ll just click okay to make the cookie banner go away are in for a rude awakening.

Or, to put it another way, the ruling should put a stop to some, er, ‘creative’ interpretations of the rules around cookies that manage to completely miss the point of the law…

ehem

The decision is also likely to influence the ongoing reform of ePrivacy rules — which govern online tracking.

While the outcome of that very heavily lobbied piece of legislation remains to be seen today’s ruling is clearly a win for privacy.

Planet49 case

The backstory to today’s ruling is that a German court asked the CJEU for a decision in a case relating to a lottery website, Planet49, which had required users to consent to the storage of cookies in order to play a promotional game.

In an earlier opinion an influential advisor to the court also took the view that affirmative action not simple inaction must be necessary to constitute consent.

Today the CJEU agreed, handing down a final judgement which makes it plain that consent can’t be assumed — it requires an active opt-in from users.

In a punchily brief press release the court writes:

In today’s judgment, the Court decides that the consent which a website user must give to the storage of and access to cookies on his or her equipment is not validly constituted by way of a prechecked checkbox which that user must deselect to refuse his or her consent.

That decision is unaffected by whether or not the information stored or accessed on the user’s equipment is personal data. EU law aims to protect the user from any interference with his or her private life, in particular, from the risk that hidden identifiers and other similar devices enter those users’ terminal equipment without their knowledge.

The Court notes that consent must be specific so that the fact that a user selects the button to participate in a promotional lottery is not sufficient for it to be concluded that the user validly gave his or her consent to the storage of cookies.

Furthermore, according to the Court, the information that the service provider must give to a user includes the duration of the operation of cookies and whether or not third parties may have access to those cookies.

So, to sum up, pre-checked consent boxes (or cookie banners that tell you a cookie has already been dropped and pointlessly invite you to click ‘ok’) aren’t valid under EU law. 

Furthermore cookie consent can’t be bundled with another purpose (in the Planet49 case the promotional lottery) — at least if that fuzzy signal is being used to stand for consent.

There’s also an interesting new requirement which looks set to shrink the ability of service operators to obfuscate how persistently they’re tracking Internet users.

For consent to cookies to be legally valid the court now says the user must be provided with some specific information on the tracking, namely: How long the cookie will operate, and who their data will be shared with. So, er, awkward…

“Extending information requirement to include cookie configuration details is an interesting twist that will provide more information to users,” Dr. Lukasz Olejnik, an independent cybersecurity advisor and research associate at the Center for Technology and Global Affairs at Oxford University, told us.

“Sites will need to be wary to be sure that the user-facing text matches the actually used values of max-age or expires attributes. It is also interesting to wonder if sites will want to provide similar information about other cookie attributes.”

Safe to say, there will be some long faces in the ad industry today.

“The Court has made clear that consent should always be manifested in an active manner, and may not be presumed. Therefore, online operators should ensure that they do not collect consent by asking users to unclick a pre-formulated declaration of consent,” said Luca Tosoni, a research fellow in computers and law at the University of Oslo, also commenting on the court ruling.

ePrivacy reform

As we’ve reported before very many sites and services in Europe have, at best, been playing lip-service to EU cookie consent requirements — despite the advent of tighter rules coming into force last year under the General Data Protection Regulation (GDPR), which says that consent must be specific, informed and freely given to be a valid legal basis. And despite — more recently — further guidance from DPAs clarifying the rules around cookie consent.

So the CJEU ruling should lift a fair few heads out of the sand.

“Before the entry into force of the GDPR, the conditions for consent were interpreted differently across Europe. Today’s judgment is important as it brings some clarity on what should be considered valid consent under EU data protection law,” Tosoni also told us, saying he expects the ruling to result in changes to many cookie notifications.

“National courts and data protection authorities across the EU will need to follow the Court’s interpretation when assessing whether controllers have validly obtained consent. In turn, this should lead to more harmonization in enforcement across Europe, in particular with regard to cookie notices. Thus, I would expect many operators to change their non-compliant consents to conform with the ruling.”

EU law on cookie consent dates back much earlier than the GDPR — to the prior Data Protection Directive and the still in force ePrivacy Directive — Article 5(3) of which specifies that for cookies to be used users must give opt-in consent after being provided with clear and comprehensive information (with only a limited exception for ‘strictly necessary’ cookies).

Although European legislators have been trying for years to agree on an update to the ePrivacy Directive.

A draft proposal for an ePrivacy Regulation was introduced by the Commission at the start of 2017. But negotiations have been anything but smooth — with a blitz of lobbying from the adtech and telecoms industries pushing against a firm requirement for opt-in consent to tracking.

The CJEU’s clarity that consent is required to store and access cookies pushes in the opposite direction. And that firm legal line protecting individual privacy from background tracking technologies should be harder for legislators to ignore.

“Today’s ruling is likely to have a significant impact on the ongoing negotiations on the ePrivacy Regulation which is set to regulate cookie usage, an issue on which European legislators are struggling to find an agreement,” Tosoni said, adding: “In the past, the Court’s rulings have had an important impact on the development of the GDPR.”

In the meanwhile, the judgement should at least force some of the more cynical and/or stupid cookie banners to be quietly replaced with something that at least asks for consent.

Cookie walls

That said, the ruling does not resolve all the problems around cookie consent.

Specifically the court has not waded into the contentious forced consent/cookie wall issue. This is where a site requires consent to advertising cookies as the ‘price’ for accessing the sought for service, with the only other option being to leave.

Earlier this year the Dutch DPA deemed cookie walls to be illegal. But the agency’s interpretation is open to legal challenge. Only the CJEU can have the final word.

In the Planet49 case the court sidestepped the issue — saying the referring court did not ask it to rule on the question of “whether it is compatible with the requirement that consent be ‘freely given’, within the meaning of Article 2(h) of Directive 95/46 and of Article 4(11) and Article 7(4) of Regulation 2016/679, for a user’s consent to the processing of his personal data for advertising purposes to be a prerequisite to that user’s participation in a promotional lottery, as appears to be the case in the main proceedings”.

“In those circumstances, it is not appropriate for the Court to consider that question,” it wrote.

Likely it’s doing so because another case is already set to consider that question. Tosoni says he expects the Orange Romania case — which is pending before the court — to further clarify the requirements of valid consent in the context of it being ‘freely given’.

“Some uncertainty on the requirements of valid consent remains. Indeed, in today’s judgment, the Court has primarily clarified what constitutes unambiguous and specific consent, but the Court has, for example, not clarified what degree of autonomy a data subject should enjoy when choosing whether or not to give consent for the latter to be considered “freely given”,” he said.

“Today’s judgment does not provide an answer on the legality of cookie walls, which require consent to access the underlying service.  The Court found that it was unable to address this point, as the referring German court had not asked the ECJ to assess the legality of making participation in a lottery — the service at issue in the case — subject to giving advertising cookie consent.  Further clarity on this issue may come from the Orange Romania case, which is currently pending before the ECJ.”

IAB Europe response

Responding to the ruling the Interactive Advertising Bureau (IAB) Europe’s CEO Townsend Feehan told us: “It’s interesting that the court are taking the view that the ePrivacy Directive provision appear to require users to be told how long a cookie will be functioning. That’s something that’s qualitatively a little bit new.”

She also agreed the CJEU ruling will likely require some changes to some existing cookie consent notices, saying: “If now the court is taking the view that users have to have precise information about the persistence of a cookie that would definitely require changes to UIs.”

“The idea that you couldn’t have preticked boxes/don’t constitute active consent is not really a surprise to anyone, and the idea that the ePrivacy Directive requirement applies to non-personal data as well as personal data is also not surprising,” she also said, further claiming the IAB’s Transparency and Consent Framework (TCF) discourages the use of pre-ticked boxes.

The TCF was introduced last year by the ad industry standards body, ahead of GDPR, when the IAB made a big push to encourage publishers to use its framework to gather consents for processing visitors’ personal data in Europe.

However there are examples of this TCF including pre-ticked consents — such as in a widely used implementation developed by Quantcast. An adtech veteran whose business is, as it happens, currently under investigation by Ireland’s Data Protection Commission (which is looking into whether its processing and aggregating of personal data to profile Internet users for ad targeting is in compliance with the GDPR).

Asked whether the IAB will be advising its members to make changes to how they gather consents in light of the CJEU ruling, Feehan said: “The recommendation until now has just been to comply with Article 13; the disclosure requirements in the GDPR. Now that the court has taken a different view from the letter of the law that is something indeed we could make a recommendation. We have a working group that needs to look at whether the policies ought to be amended in light of the ruling — and so that process will play out in the next few weeks.”

She also said the IAB’s wider position on the ePrivacy Regulation remains unchanged for now — which is to say it doesn’t believe updated tracking rules are necessary.

“I don’t think this ruling will affect our general approach or position on the proposed ePrivacy Regulation,” she said. “Our view on ePrivacy Regulation is basically that it’s probably not necessary. That all one needs is the GDPR. If you look at the substantive scope of the ePrivacy Regulation in relation to the cookie provisions… they’re completely redundant with what was adopted in the GDPR.”

Asked to respond to wider criticism of the adtech industry’s business model being based on consent-less tracking of Internet users Feehan rejected the critique as “complete nonsense”, adding there’s nothing in the CJEU judgement to support such a view.

“The judgement doesn’t tell us anything new about the content of the law. The advertising industry needs to obey the law, the overwhelming majority of players in the digital advertising industry obey the law. And this ruling doesn’t tell us anything new as far as I’m concerned about the law… It does introduce this perhaps more precise requirement with respect to the obligation to disclose the duration of persistence of cookies. But I don’t understand on what basis anyone would read today’s ruling and decide that based on that reading one discovers that the business model is illegal. I don’t understand the logic of that.”

This report was updated with comment from the IAB Europe

More TechCrunch

Tech enthusiasts and entrepreneurs, the clock is ticking! With just 72 hours remaining until the early-bird ticket deadline for TechCrunch Disrupt 2024, now is the time to secure your spot…

72 hours left of the Disrupt early-bird sale

Avendus, the top investment bank for venture deals in India, confirmed on Wednesday it is looking to raise up to $350 million for its new private equity fund.  The new…

Avendus, India’s top venture advisor, confirms it’s looking to raise a $350 million fund

China has closed a third state-backed investment fund to bolster its semiconductor industry and reduce reliance on other nations, both for using and for manufacturing wafers — prioritizing what is…

China’s $47B semiconductor fund puts chip sovereignty front and center

Apple’s annual list of what it considers the best and most innovative software available on its platform is turning its attention to the little guy.

Apple’s Design Awards nominees highlight indies and startups, largely ignore AI (except for Arc)

The spyware maker’s founder, Bryan Fleming, said pcTattletale is “out of business and completely done,” following a data breach.

Spyware maker pcTattletale says it’s ‘out of business’ and shuts down after data breach

AI models are always surprising us, not just in what they can do, but what they can’t, and why. An interesting new behavior is both superficial and revealing about these…

AI models have favorite numbers, because they think they’re people

On Friday, Pal Kovacs was listening to the long-awaited new album from rock and metal giants Bring Me The Horizon when he noticed a strange sound at the end of…

Rock band’s hidden hacking-themed website gets hacked

Jan Leike, a leading AI researcher who earlier this month resigned from OpenAI before publicly criticizing the company’s approach to AI safety, has joined OpenAI rival Anthropic to lead a…

Anthropic hires former OpenAI safety lead to head up new team

Welcome to TechCrunch Fintech! This week, we’re looking at the long-term implications of Synapse’s bankruptcy on the fintech sector, Majority’s impressive ARR milestone, and more!  To get a roundup of…

The demise of BaaS fintech Synapse could derail the funding prospects for other startups in the space

YouTube’s free Playables don’t directly challenge the app store model or break Apple’s rules. However, they do compete with the App Store’s free games.

YouTube’s free games catalog ‘Playables’ rolls out to all users

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the first months of 2024. Smaller-sized…

15 hours ago
A comprehensive list of 2024 tech layoffs

OpenAI has formed a new committee to oversee “critical” safety and security decisions related to the company’s projects and operations. But, in a move that’s sure to raise the ire…

OpenAI’s new safety committee is made up of all insiders

Time is running out for tech enthusiasts and entrepreneurs to secure their early-bird tickets for TechCrunch Disrupt 2024! With only four days left until the May 31 deadline, now is…

Early bird gets the savings — 4 days left for Disrupt sale

AI may not be up to the task of replacing Google Search just yet, but it can be useful in more specific contexts — including handling the drudgery that comes…

Skej’s AI meeting scheduling assistant works like adding an EA to your email

Faircado has built a browser extension that suggests pre-owned alternatives for ecommerce listings.

Faircado raises $3M to nudge people to buy pre-owned goods

Tumblr, the blogging site acquired twice, is launching its “Communities” feature in open beta, the Tumblr Labs division has announced. The feature offers a dedicated space for users to connect…

Tumblr launches its semi-private Communities in open beta

Remittances from workers in the U.S. to their families and friends in Latin America amounted to $155 billion in 2023. With such a huge opportunity, banks, money transfer companies, retailers,…

Félix Pago raises $15.5 million to help Latino workers send money home via WhatsApp

Google said today it’s adding new AI-powered features such as a writing assistant and a wallpaper creator and providing easy access to Gemini chatbot to its Chromebook Plus line of…

Google adds AI-powered features to Chromebook

The dynamic duo behind the Grammy Award–winning music group the Chainsmokers, Alex Pall and Drew Taggart, are set to bring their entrepreneurial expertise to TechCrunch Disrupt 2024. Known for their…

The Chainsmokers light up Disrupt 2024

The deal will give LumApps a big nest egg to make acquisitions and scale its business.

LumApps, the French ‘intranet super app,’ sells majority stake to Bridgepoint in a $650M deal

Featured Article

More neobanks are becoming mobile networks — and Nubank wants a piece of the action

Nubank is taking its first tentative steps into the mobile network realm, as the NYSE-traded Brazilian neobank rolls out an eSIM (embedded SIM) service for travelers. The service will give customers access to 10GB of free roaming internet in more than 40 countries without having to switch out their own existing physical SIM card or…

23 hours ago
More neobanks are becoming mobile networks — and Nubank wants a piece of the action

Infra.Market, an Indian startup that helps construction and real estate firms procure materials, has raised $50M from MARS Unicorn Fund.

MARS doubles down on India’s Infra.Market with new $50M investment

Small operations can lose customers by not offering financing, something the Berlin-based startup wants to change.

Cloover wants to speed solar adoption by helping installers finance new sales

India’s Adani Group is in discussions to venture into digital payments and e-commerce, according to a report.

Adani looks to battle Reliance, Walmart in India’s e-commerce, payments race, report says

Ledger, a French startup mostly known for its secure crypto hardware wallets, has started shipping new wallets nearly 18 months after announcing the latest Ledger Stax devices. The updated wallet…

Ledger starts shipping its high-end hardware crypto wallet

A data protection taskforce that’s spent over a year considering how the European Union’s data protection rulebook applies to OpenAI’s viral chatbot, ChatGPT, reported preliminary conclusions Friday. The top-line takeaway…

EU’s ChatGPT taskforce offers first look at detangling the AI chatbot’s privacy compliance

Here’s a shoutout to LatAm early-stage startup founders! We want YOU to apply for the Startup Battlefield 200 at TechCrunch Disrupt 2024. But you’d better hurry — time is running…

LatAm startups: Apply to Startup Battlefield 200

The countdown to early-bird savings for TechCrunch Disrupt, taking place October 28–30 in San Francisco, continues. You have just five days left to save up to $800 on the price…

5 days left to get your early-bird Disrupt passes

Venture investment into Spanish startups also held up quite well, with €2.2 billion raised across some 850 funding rounds.

Spanish startups reached €100 billion in aggregate value last year

Featured Article

Onyx Motorbikes was in trouble — and then its 37-year-old owner died

James Khatiblou, the owner and CEO of Onyx Motorbikes, was watching his e-bike startup fall apart.  Onyx was being evicted from its warehouse in El Segundo, near Los Angeles. The company’s unpaid bills were stacking up. Its chief operating officer had abruptly resigned. A shipment of around 100 CTY2 dirt bikes from Chinese supplier Suzhou…

2 days ago
Onyx Motorbikes was in trouble — and then its 37-year-old owner died