Interactive Advertising Bureau

European Data Protection Board

Guidelines 05/2020 on consent under Regulation 2016/679

ARE COOKIE WALLS ALLOWED?

The EDPB Guidelines explicitly forbid the use of cookie walls.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The EDPB Guidelines do not discuss the topic of consent-or-pay models.

HOW LONG IS CONSENT VALID FOR?

The EDPB Guidelines do not discuss the topic of consent’s validity.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The EDPB Guidelines do not specifically address online advertising, but some examples given in the text relate to online advertising use cases.

HOW DO USERS HAVE TO INDICATE CONSENT?

The EDPB Guidelines explain that consent shouldn’t be unnecessarily disruptive, but cannot simply be given through ambiguous methods, where the action could be mistaken for normal use (i.e. continuing to browse and further scrolling).

Agencia Española Proteccion Datos

Guia sobre el uso de las cookies.

ARE COOKIE WALLS ALLOWED?

The AEPD guidelines explicitly forbid the use of cookie walls, stating that they are following EDPB guidelines.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The AEPD guidelines do not mention consent-or-pay models, but it does mention that “certain situations might exist” where an alternative can be found for cookie wall approaches (i.e. take-it-or-leave-it)

HOW LONG IS CONSENT VALID FOR?

The AEPD guidelines explain that users should not be prompted for their consent too often to reduce consent fatigue. Thus, they recommend that consent for cookies could last for up to 24 months.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The AEPD guidelines include a detailed Annex outlining the various players in the online advertising ecosystem, with some specific guidance per stakeholder. The guidelines also include a reflection on the use of Consent Management Providers (CMPs).

HOW DO USERS HAVE TO INDICATE CONSENT?

The AEPD guidelines explain that there needs to be an affirmative action. Merely continuing to browse cannot be construed as an indication of consent.

Autoriteit Persoonsgegevens

Uitleg over Cookies.

ARE COOKIE WALLS ALLOWED?

The AP guidelines explicitly forbid the use of cookie walls – following EDPB guidelines.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The AP’s guidelines actually suggest, as an alternative to a consent wall, to allow users to access website content for a price instead.

HOW LONG IS CONSENT VALID FOR?

The AP’s guidelines explain that because cookies durability gets renewed each time they are accessed, any cookies with a lifespan of over 6 months will be unlikely to be able to remain valid, as the user is unlikely to be able to give informed consent to such cookies. It therefore follows that consent probably cannot be valid for more than 6 months at a time.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The AP doesn’t offer specific guidelines on online advertising.

HOW DO USERS HAVE TO INDICATE CONSENT?

The AP specifies that only a clear indication can be used to signify consent. Merely continuing to use a website cannot be counted as an active indication.

Commission Nationale de l'Informatique et des Libertés

Deliberation n ° 2019-093 of July 4, 2019 - Cookie Guidelines.

ARE COOKIE WALLS ALLOWED?

The CNIL’s guidelines do not prohibit the use of cookie walls, but they do note that making consent a condition for accessing a service is prone to infringing the principle of free consent, and must be assessed on a case-by-case basis.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The CNIL’s guidelines do not discuss consent-or-pay models.

HOW LONG IS CONSENT VALID FOR?

The CNIL’s guidelines create a lighter regime for specific audience measurement cookies. Under certain circumstances, these can be placed without consent for up to 13 months, and the data collected by those cookies can be retained for up to 25 months. However, for other tracking cookies the CNIL does not define a time limit for retaining the data, nor for the validity of consent.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The CNIL’s guidelines have specific rules for audience measurement cookies (first-party only, measuring traffic and A/B testing, broad audience segmentation, anonymized statistics). These can be placed without consent for up to 13 months.

HOW DO USERS HAVE TO INDICATE CONSENT?

The CNIL’s Guidelines call for a clear positive action; i.e. not just scrolling, continuing to browse, use of the app or website. The absence of a positive action to indicate consent must be considered as a refusal to grant consent.

Datatilsynet

Guidelines on consent for cookies.

ARE COOKIE WALLS ALLOWED?

The Datatilsynet Guidelines do not discuss cookie walls.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The Datatilsynet Guidelines do not discuss consent or pay models.

HOW LONG IS CONSENT VALID FOR?

The Datatilsynet Guidelines does not provide a time limit for consent, stating that in principle consent does not expire. However, data controllers must ensure that consent can be withdrawn at any time, as easily as it was given.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The Datatilsynet Guidelines do not have specific guidance for online advertising.

HOW DO USERS HAVE TO INDICATE CONSENT?

The Datatilsynet Guidelines require that both accept and reject options must be displayed with equal prominence. Furthermore these guidelines have additional requirements that consent must be able to be ticked per purpose, and there needs to be a list of identified data controllers on the first layer of a consent interface.

Information Commissioner’s Office

Guidance on the Use of Cookies and Similar Technologies

ARE COOKIE WALLS ALLOWED?

The ICO Guidance on Cookies page has a detailed section on Cookie Walls, concluding that they are unlikely to lead to valid consent, noting that not all cookie tracking is necessarily intrusive or high risk.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The ICO Guidance on Cookies does not discuss the consent or pay models.

HOW LONG IS CONSENT VALID FOR?

The ICO Guidance on Cookies provides plenty of guidance here - first, consent must be refreshed as often as is appropriate, depending on the situation, but leaves it to websites to figure out the right interval. For cookie duration, they should last as long as is ‘appropriate’ and not be disproportionately long.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The ICO has a specific section of the website dedicated to their work on AdTech. IAB Europe has cooperated with the ICO in their investigation into the AdTech industry.

HOW DO USERS HAVE TO INDICATE CONSENT?

The ICO Guidance on Cookies explains that a user must have taken an action to signify consent. Furthermore, the Guidance warns that users must not be ‘nudged’ into accepting by making it harder to see the reject or settings options - implying that they must be given equal prominence.

Gegevensbescherming Autoriteit/Autorité de Protection des Données

Website page on Cookies and other tracking methods.

ARE COOKIE WALLS ALLOWED?

The Belgian data protection authority’s guidelines explicitly state that the use of a cookie wall is are not allowed as they consider this not to be valid consent under the GDPR.

CAN YOU CHARGE USERS WHO DO NOT CONSENT?

The Belgian data protection authority’s guidelines do not discuss the consent or pay models.

HOW LONG IS CONSENT VALID FOR?

The Belgian data protection authority’s guidelines state that the retention period for cookies need to have a limited duration, and the cookie policy needs to explain this retention period. However, no specific time limits are suggested for how long such retention may be, nor how long consent is valid for.

IS THERE GUIDANCE SPECIFIC TO ONLINE ADVERTISING?

The Belgian data protection authority’s guidelines do not specifically address online advertising, but do explain that audience measurement cookies require consent, even if they are first party cookies. They also clarify that social media plugins (i.e. like-buttons, or tweet-buttons) require consent of the user before being activated as well.

HOW DO USERS HAVE TO INDICATE CONSENT?

The Belgian data protection authority’s guidelines explain that simply continuing to browse a page cannot count as valid consent. Consent has to be indicated through an action from the user.
Links:

European Data Protection Board (EDPB), Guidelines 05/2020 on consent under Regulation 2016/679.

Agencia Española Proteccion Datos (AEPD), Guia sobre el uso de las cookies.

Autoriteit Persoonsgegevens (AP), Uitleg over Cookies.

Commission Nationale de l'Informatique et des Libertés (CNIL), Deliberation n ° 2019-093 of July 4, 2019 - Cookie Guidelines.

Data Protection Commission (DPC), Guidance Note: Cookies and other tracking technologies.

Datatilsynet (Denmark), Guidelines on consent for cookies.

Information Commissioner’s Office (ICO), Guidance on the Use of Cookies and Similar Technologies

Gegevensbescherming Autoriteit/Autorité de Protection des Données (GBA/APD), Website page on Cookies and other tracking methods.

IAB Europe
Rond-Point Robert
Schuman 11
1040 Brussels
Belgium
Sign up for our newsletter
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram