Cookie-tracking deadline: Sites pressed to meet deadline
bbc.com
bbc.com
To be on the safe side we are putting up a notice on the log-in page - and accepting the user's decision to continue to log-in as explicit permission to set the cookie.
On the plus side I am looking forward to not seeing ads for anything I have viewed on certain retail sites popping up wherever else I go on the Internet.
The guidance document is here and is fairly helpful http://www.ico.gov.uk/for_organisations/privacy_and_electron...
Those who wish to circumvent it will do, easily & by far more insidious means, meanwhile the rest of us who just want google analytics have tough choices to make.
Hopefully x-do-not-track will gain momentum instead, that will at least save the honest website owners some work & leave the nefarious ones to do whatever they wish like present.
(1) Subject to paragraph (4), a person shall not store or gain access to
information stored, in the terminal equipment of a subscriber or user
unless the requirements of paragraph (2) are met.
(2) The requirements are that the subscriber or user of that terminal
equipment-
(a) is provided with clear and comprehensive information about the
purposes of the storage of, or access to, that information; and
(b) has given his or her consent.
(3) Where an electronic communications network is used by the same person to
store or access information in the terminal equipment of a subscriber or
user on more than one occasion, it is sufficient for the purposes of
this regulation that the requirements of paragraph (2) are met in
respect of the initial use.
(3A) For the purposes of paragraph (2), consent may be signified by a
subscriber who amends or sets controls on the internet browser which
the subscriber uses or by using another application or programme to
signify consent.
(4) Paragraph (1) shall not apply to the technical storage of, or access to,
information—
(a) for the sole purpose of carrying out the transmission of a
communication over an electronic communications network; or
(b) where such storage or access is strictly necessary for the provision
of an information society service requested by the subscriber or user.
No mention of cookies, and "information stored, in the terminal equipment of a subscriber or user" would seem to apply to solutions that use HTML5 local storage, ETag headers, Flash LocalSharedObjects or any other similar technologies.[1]: http://www.legislation.gov.uk/uksi/2003/2426/contents/made
[2]: http://www.legislation.gov.uk/uksi/2011/1208/contents/made
First SOPA, now this.