惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Martin Fowler
Martin Fowler
I
InfoQ
腾讯CDC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
Microsoft Security Blog
Microsoft Security Blog
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
F
Fortinet All Blogs
N
Netflix TechBlog - Medium
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
D
Docker
博客园 - 三生石上(FineUI控件)
Y
Y Combinator Blog
博客园 - Franky
Engineering at Meta
Engineering at Meta
B
Blog
罗磊的独立博客
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
V
Visual Studio Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
The European Data Protection Board Publishes Examples of ...
Jessica Ryder · 2023-02-16 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

The European Data Protection Board (EDPD) has released a new set of examples of non-compliant practices to help website managers ensure they are in compliance with the General Data Protection Regulation (GDPR).

Photo:

Further to the report adopted by the EDPD on the work undertaken by the Cookie Banner Task Force a few weeks ago, the EDPD has now published examples of non compliant practices to better assist website managers in attaining compliance. In response to the EDPD’s publications, the French Data Protection Authority, 

“strongly encourages organizations to review their cookie banners in light of the recommendations contained in the report.”

This report is the outcome of collaboration between the various European data protection agencies, which was put up to address complaints the NOYB organization received over cookie banners.

The research includes a number of widespread practices noticed on cookie banners of websites operating in the European region and assesses whether they comply with the various standards that are in force (in particular: the ePrivacy Directive, and the GDPR). It might be possible to use it as guidance for website and application managers when asking for the user’s permission to read or store cookies (and/or other equivalent technologies) on their device.

The report examines, among other things, the following practices:

  • The pre-checked boxes. Regardless of the level of the banner in which the checkbox is featured, pre-checked boxes do not represent a legitimate permission within the meaning of the GDPR or ePrivacy.
  • Misleading design. The taskforce called attention to many misleading banner layout practices.
  • The legitimate interest. Some websites process data further after placing or reading cookies based on legitimate interest rather than user consent. The paper reminds readers that the mere storing or reading of cookies cannot be justified by legitimate interest, and that any further processing that results from those actions must also be compliant with the GDPR.
  • The absence of a “refuse all” button at the same level as the “accept all” button. Most data protection agencies, including ODA, viewed this as a breach and believed that users of websites should have access to the choice of allowing or disabling the deposit/reading of cookies on their devices.

The ODA wants to remind readers that the GDPR and Article 5.3 of ePrivacy have a wide application and apply to a variety of technological platforms (such as, among other things, the use of “local storage”).

She also draws attention to the fact that the study simply provides examples of blatant infractions, without going farther. Therefore, it cannot be assumed that any behavior that is not specified in the report will automatically abide by the laws currently in effect.

Visit the EDPB website to read the entire report.

Organizations are strongly urged by the ODA to review their cookie banners in light of the report’s recommendations.