Cookies and similar technologies

While cookies are the most commonly-known method, any technology used to store information on a user’s device or gain access to information on a user’s device, is subject to the same requirements.

Broadly speaking these requirements currently are:

  1. The user is told why you want to store information, or access information, on their device; and
  2. The user must have given their consent to such storage or access.

These are requirements under the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended – these Regulations are often referred to as the PECR.

Are there any exemptions?

Yes, if:

  1. The cookie (or similar tech) is required for the sole purpose of carrying out the transmission of a communication over an “electronic communications network” (such as a network for phone calls, text messages, emails or internet messaging; examples include wireless networks and mobile phone networks); or
  2. The storage or access is strictly necessary for the provision of an “information society service” (most online services) requested by the subscriber or user.

In essence, if you need the cookie (or similar tech) to provide the service to the user – for example, to remember the goods a user wishes to buy when they add goods to their online basket – you will probably be able to rely on these exemptions.

It is important however to note that the cookie (or similar tech) must be essential, it cannot just be convenient or preferable.

What does this mean in practice?

  1. Before a cookie is placed onto a device you should ensure that individuals provide their consent. This means, when someone lands on a webpage, cookies are not placed on the user’s device until their consent is provided.
  2. You should make sure suitable detail is provided to individuals to allow them to understand what you are placing on their device and why.
  3. Any consent should require a positive action from the individual, for example you should not used pre-ticked options.

Consent to the use of cookies is usually sought using a pop-up or cookie banner.

What happens if we don’t comply

Compliance with the rules on the use of cookies (and similar tech) is enforced by the Information Commissioner’s Office. A failure to comply could result in a fine and reputational damage in the event you fail to properly implement cookie technology.

What about data protection?

The rules on cookies (and similar tech) apply to the storage of, or access to, any information using that type of technology. It does not need to be personal data.

Often data collected by cookies is personal data. If it is, then as well as comply with the requirements under the PECR, you will also need to comply with the Data Protection Act 2018 and the UK GDPR. It is therefore key that you check what information is being collected, whether it is personal data and whether you have complied with your wider data protection obligations.

Potential changes to the law

Some people consider the website cookie requirements to be onerous. In June 2022, the UK Government published its intention to legislate to remove the need for websites to display cookie banners to UK residents.

The Government has also announced that it intends to move to an opt-out model of consent for cookies placed by websites. In practice, this would mean cookies could be set without seeking consent, but the website must give the web user clear information about how to opt out (although this model is not expected to apply to websites likely to be accessed by children).

Please keep an eye out for future announcements about the laws applicable to cookies and similar technologies – we will publish details of changes here on our Data Protection Hub.

Your main contact

  • Paul Knight

    Partner

    Paul Knight

    Partner

    • +(44)(0)16234 8702
    • Contact Paul

      Contact Paul Knight

      * = required

      Mills & Reeve will use the information you provide in this form in accordance with our privacy policy. We may from time to time send you general updates by email or post that we think you will find of interest. This includes notification of upcoming event and updates or alerts containing relevant legal news. You can update your preferences at any time and will be able to easily unsubscribe from anything that you do not wish to receive.

      Thank you

      Thank you for your enquiry. We will be in touch shortly.

    • Manchester
  • Peter Wainman

    Partner

    Peter Wainman

    Partner

    • +(44)(0)1223 222408
    • Contact Peter

      Contact Peter Wainman

      * = required

      Mills & Reeve will use the information you provide in this form in accordance with our privacy policy. We may from time to time send you general updates by email or post that we think you will find of interest. This includes notification of upcoming event and updates or alerts containing relevant legal news. You can update your preferences at any time and will be able to easily unsubscribe from anything that you do not wish to receive.

      Thank you

      Thank you for your enquiry. We will be in touch shortly.

    • Cambridge
  • Jagvinder Singh Kang

    Partner, International & UK Head of IT

    Jagvinder Singh Kang

    Partner, International & UK Head of IT

    • +(44)(0)12456 8470
    • Contact Jagvinder

      Contact Jagvinder Singh Kang

      * = required

      Mills & Reeve will use the information you provide in this form in accordance with our privacy policy. We may from time to time send you general updates by email or post that we think you will find of interest. This includes notification of upcoming event and updates or alerts containing relevant legal news. You can update your preferences at any time and will be able to easily unsubscribe from anything that you do not wish to receive.

      Thank you

      Thank you for your enquiry. We will be in touch shortly.

    • Birmingham
Mills & Reeve Sites navigation
A tabbed collection of Mills & Reeve sites.
Sites
My Mills & Reeve navigation
Subscribe to, or manage your My Mills & Reeve account.
My M&R

Visitors

Register for My M&R to stay up-to-date with legal news and events, create brochures and bookmark pages.

Existing clients

Log in to your client extranet for free matter information, know-how and documents.

Staff

Mills & Reeve system for employees.