and it's going to get more complicated under GDPR and the ePrivacy directive:
https://www.informationweek.com/big-data/cookie-law-vs-gdpr-...?
GDPR is NOT limited to the EU, but is focused on protecting EU data subjects no matter where they are, so US companies may be affected. Many US companies are signing up for Privacy Shield, which is updated annually, so it will spread beyond the EU in the years to come.
As an aside I do find it funny how 'bosses' insist on the cookie notice to make their website official looking.
Absolutely! How else does it know to store the cookie on the user's machine.
So how would the browser differentiate those cookies from ones which are being used for data collection and tracking, which do require the warning message? It would require some sort of intent-signalling protocol between the website and the browser, which is probably more complicated than just requiring the site operator to include a bit of HTML.
Cookie banner frustration to be tackled by EU
The law is explicitly about 3rd party cookies, something that is harder to classify.
The intent of the law was to get website owners to stop leaking data to 3rd parties.
The result was everyone slapping a poorly understood warning label on everything.
The correct way to shield oneself from liability in Germany is to have appropriate insurance plus paying a lawyer to continuously check the business for compliance.
However, there is case law (law made by judges who hear cases and issue opinions) that says that sometimes contracts can be implicitly formed. For example, if you as a website visitor are given proper notice of a website's terms of use, and then you continue to the use website, you have implicitly agreed to the terms of the use. Even if you didn't sign anything, or check any box somewhere saying you agree. No explicit action has to take place.
Except, that is not exactly worldwide statutory law (laws passed by government and written down in the books with codes like Law #1234.56). While the issue of formation is mostly settled, there is still some room for creative legal maneuvering. Aka lawyering the shit of things. Aka screwing things up because someone with deep pockets is paying you to win using any angle you can get.
This cookies notice and agreement probably falls right into this category. And while it is generally settled law that the contract is formed even without this agreement, some schmuck somewhere still thinks there is wiggle room, but it is merely case law and not exactly authoritative, especially not in the international setting.
When in doubt, lawyers adhere to CYA. Cover your ass. Use the narrowest, most conservative, safest interpretation of the law. In this case, there is this tiny bit of doubt, so CYA. Just in case.
I personally believe you can make a good argument that contract is implicitly formed merely from continued use, and the notion of requiring express consent is outdated. The law is catching up to how things are done online, the trend is rather obvious, and anyone whining about it is probably just some established cash cow business that somehow wants to manipulate the market to further extend its antiquated business practices and is willing to spend millions on dollars on go screw yourself legal teams.
So, yes, you could theoretically get in trouble. But you are not likely to, and anyone suggesting otherwise probably has an ulterior motive.
....The cookie notice is mandated by EU Law...
Is your contract still existing. Have really all your customers signed it?
It's possible an obscure case might have slipped through the cracks (ie as part of a larger case) but unlikely since it'd be great clickbait on a story.