I just loaded up the home page of The New York Times (a random example), and it had placed 23 cookies on my laptop before the "Your tracker settings" window finished loading. Now I still haven't clicked "ACCEPT", and we're up to 43.
I just loaded up the home page of The New York Times (a random example), and it had placed 23 cookies on my laptop before the "Your tracker settings" window finished loading. Now I still haven't clicked "ACCEPT", and we're up to 43.
my understanding is no consent = no tracking cookies. session cookies are okay.
IANAL, though, so I could be incorrect.
To be fair, though, that's pretty clearly a bug; at a minimum, any site that's just serving content should be fine with no cookies. Of course, any site that's just content should also be at least 95% functional with no JS and barely any CSS, and we all know how that worked out...
No doubt. I was just making a statement about the current state of the web. Not applauding it in the least. :)
For exemple, as I said in another post, is explicitely allowed:
* Cookies for login/session
* Cookies for shopping carts
* Cookies for interface personnalisation (language, etc.)
* Cookies for load balancing
* Cookies to retain user choice regarding cookies
And quite a few other. So really you can run your website without consent notice if you care enough. One grey area is analytics, it varies amongst european DPAs. That I know of:
* In France it is allowed if you respect a few rules (no cross-processing, no localisation, etc..)
* In the UK, it is not per say allowed, but the ICO said they would not prosecute on those grounds.