Web Analytics Illegal in UK after 26 May? Crazy
h30565.www3.hp.com
h30565.www3.hp.com
---
We only use analytical cookies – if nobody consents that will seriously restrict the amount of information we can get to improve and develop our website
The Regulations do not distinguish between cookies used for analytical activities and those used for other purposes. We do not consider analytical cookies fall within the ‘strictly necessary’ exception criteria. This means in theory websites need to tell people about analytical cookies and gain their consent.
In practice we would expect you to provide clear information to users about analytical cookies and take what steps you can to seek their agreement. This is likely to involve making the argument to show users why these cookies are useful. Although the Information Commissioner cannot completely exclude the possibility of formal action in any area, it is highly unlikely that priority for any formal action would be given to focusing on uses of cookies where there is a low level of intrusiveness and risk of harm to individuals. Provided clear information is given about their activities we are highly unlikely to prioritise first party cookies used only for analytical purposes in any consideration of regulatory action.
---
My interpretation of that is: tell your web site users clearly what you do with analytics and why and we are very unlikely to bother coming after you.
If you'd been following this whole mess you'd know it's just a typical EU nonsense legislation that no-one knows how to implement and the UK is once again implementing it too harshly in law but giving it absolutely no teeth by creating a practically powerless and massively underfunded enforcement vehicle while our EU brethren quietly ignore it.
No big conspiracy, just your bog standard bureaucratic incompetence from the EU.
What I'm saying is that it's clear to everyone involved that the authorities (EU or UK or whatever) will never be able to enforce this law except for the largest targets, in the same way as they'll never go after anyone coupling their OS and browser except if it's as big as Microsoft.
Actually, it's to go after anyone they don't like. I suspect that Facebook and Google are better equiped to handle "go after" than you are.
No, they may not want to go after you today, mostly because they probably don't know that you exist but get their attention and things may change.
If you want to track, do it properly with a package installed on your own server. stop subjecting your users to Google's All-Seeing Eye just because using their Analytics is easier for you.
(new Image()).src="http://your.tld/track.png?ua=" + encodeURIComponent(navigator.userAgent);
and then parse your logs.Update: this is just an example, as ars notes the user agent is sent as a HTTP header. But screen resolution etc is not.
How does this help? The UserAgent is already sent in the headers - what's the point in sending it in a query string?
So, no, these workarounds are not the right answer; we need mechanisms that let users control their data and let them choose to share it. It's up to us as product makers to give them a good reason.
As for mechanisms, to what end, if nobody bothers to use them? Especially things like "randomize User-Agent string" that'd break a great many "non-evil" sites?
Third parties may wish to store information on the
equipment of a user, or gain access to information
already stored, for a number of purposes, ranging
from the legitimate (such as certain types of
cookies) to those involving unwarranted intrusion
into the private sphere (such as spyware or
viruses). It is therefore of paramount importance
that users be provided with clear and comprehensive
information when engaging in any activity which
could result in such storage or gaining of access.
The purpose of the directive is to be as broad as possible to cover collection of any type of information without express permission or "strictly necessary and legitimate purpose".[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...
So in theory all cookies are the same, in practice they're not - first party analytical cookies are mostly safe.
That's true. While I'd welcome clearer law it's important to point out that it's the ICO who'll be enforcing the law, so if they say they're not going to go after people it's safe to say they won't.
If anything people want the ICO to be a bit tougher - there are plenty of actually dodgy privacy invading practices going on the the ICO seems to be powerless to stop.
> knee-jerk reactions
This law has been a long time in the making. Self-regulation would be ideal. But there are too many operators who are willing to ignore sensible privacy standards for self-regulation to be possible. Unfortunately some of those bad actors are going to ignore any laws.
Until some group puts pressure on them to enforce against analytics sites. Or the top brass at ICO are switched out. Or a politician makes it their mission for a little while. Or...
"We are making this illegal, but we won't enforce it, really!" is not a trustworthy statement.
That may not be as true as you think.
I don't really know how the modern UK legal system works in this regard, but in the US, the courts would A) defer to the interpretation of the agency (in this case the ICO) as to what a statute means, and B) greatly frown on any attempt to prosecute without warning people who reasonably relied on the agency's declarations.
Sure we can follow the ICO and put a pop-up on the site asking to accept cookies or not (which if you select 'not' ironically creates a cookie), but as other people have pointed out that's laughable (for a huge number of reasons) and would push online trade away from uk sites. Easiest option for me would be to shift hosting outside the EU, take the SEO location hit and get back to work as usual (EDIT: it appears I am a little behind on the legislation as last time I read it hosting overseas was a loophole, looks like I need to refresh things).
Alternatively if I could dispense with cookies and shift tracking upstream to a CDN that would also save me the problem and at that point I should be getting even more data such as IP addresses.
Users need to take control of their browsing and privacy, they need to be aware of what they are giving away when they join a site or go online in general. Currently they are clueless and that is what needs to stop, force a prompt for all cookies regardless of country, evens the playing field and make people think for a change (if you're a chrome user "Edit this cookie" is an invaluable plugin for monitoring and removing what each site is placing on your machine).
It's also a bit rich saying that tracking cookies are bad whilst trying to pass a law attempting to track almost all communication:
https://www.eff.org/deeplinks/2012/04/uk-government-proposes...
Governments hate competition.
I am in 100% support of this law. Even if it impacts my ability to analyze users.
* It's hosted in a way that precludes putting your own analytics in there (github pages, s3 etc.)
* The users lack the technical sophistication to install and manage their own analytics.
I've just finished moving my wife's site to github pages. It's awesome. The mac github client is pretty friendly, I set up the repo and jekyll and put a shortcut on her desktop to fire up a local server. She knows enough HTML to be able to update content on it. Analytics would be massively useful but it just won't be sensible for me to put them in.
I'm hoping what happens is that Google releases it's UK friendly analytics which does the following:
* Stops dropping cookies on UK based browsers
* Attempts to get consent through a different channel and then enables cookies for those users across the board
If they are not skilled enough to install their own counter, I doubt they need analytics.
* I know a large number of business minded folk who could not operate without analytics but are not qualified to install any of the software in this list: http://en.wikipedia.org/wiki/List_of_web_analytics_software#...
Or ask (pay ?) your hosting company to give you analytical tools (like a simple log !). It used to be the norm.
If this goofy law is more than sporadically enforced, future analytics probably won't use cookies at all - they'll just combine browser fingerprinting with server-side logs that get automatically sent to a third-party for processing. Individual end-users won't have any way of knowing whether it's there or not.
In other words, don't piss us off or we'll use this to screw you.
You may trust the current administration to leave you alone on this but they won't be in office forever.
Regulating Internet technologies to this level of pedantic granularity will ensure that spammers, scammers, crackers and fraudsters have an effective monopoly on privacy-busting technology. The incentive for software to implement correct technological solutions will be taken away if an honesty box Do-not-track approach is considered adequate. I want my browser to have a maximal number of reasons (including a multi billion dollar advertising industry) to address the technical concerns highlighted by Panopticlick[1] or privacy experts that "get it"[2]. These technical problems will be exploited by unwanted parties on the Internet. Exploitation will occur legally in other jurisdictions out of reach of EU laws.
The full text of the directive can be found at §66 on page 20 of Directive 2009/136/EC at [3].
[1] https://panopticlick.eff.org/
[3] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...
It's a pain I admit, but such is the burden of maintaining your privacy online. Whenever I set up a computer for friends or family I always do this (as well as blocking flash and javascript as standard) and explain what it entails, because without that they cannot know what they are giving away.
If you are really serious about protecting your privacy online, I imagine you already have your browser configured to deny all cookies except those which you explicitly accept. The tools to solve this problem already exist - either built in to the browser, or easily available as extensions.
I'm genuinely curious about this - what do you think gets done with a browser cookie that actually causes real harm to the user? Perhaps that should be regulated instead of the mechanism for it.
This is just supposed to be like the signs you are required to have if you use cctv, letting people avoid it if they wish to.
Our company doesn't track users off the site, we anonymise data so it cannot be tracked back to an individual... as far as we are concerned the law shouldn't apply to how we make use of cookies.
The fine is up to £500k. Realistically.. the fine for a small company is more likely to a few thousand. It would be better to pay a few k a month in fines than lose 90% of our user data. If we implement this we might as well stop developing our product.
Thanks for the warning though.
However, what about the other direction? Suppose your company comes to their attention through some other means, and they start investigating. At some point, you could find yourself answering questions under oath. It's conceivable the questioner might go on a fishing expedition, and ask "Have you ever posted on HN under the alias Johnny Flash?" (he might ask that at every company he investigates).
Then you've got the annoying choice between telling the truth and making your company's case for accidental violation much worse, or lying under oath which, if that is discovered, could bring serious penalties.
Check out the analytics for 26th of May 2011:
Its tracking people outside of a website's scope that should be allowed only with consent, such as facebook tracking people when they go to sites with a like button and so on
Now, should e.g. Wal-Mart be able to put an RFID tag on you so that they know who you ware the next time you come in? And more importantly, should they be able to contract a third-party, which can then know when you enter any store with which they have a contract?
In terms of workarounds, here are a couple that I have found:
* Don't be a UK based company
While non UK companies are encouraged to respect these guidelines, they are not required to do so. From the guidelines:
"An organisation based in the UK is likely to be subject to the requirements of the Regulations even if their website is technically hosted overseas. Organisations based outside of Europe with websites designed for the European market, or providing products or services to customers in Europe, should consider that their users in the UK and Europe will clearly expect information and choices about cookies to be provided."
Anyone care to guess what happens if a US company has a US based website but also a based UK presence?
* Get the 3rd party to get the consent. The following wording says that if the 3rd party cookie provider has gained consent from the user, it's the website will not also need to. As in:
"The key point is not who obtains the consent but that valid, well informed consent is obtained."
i.e. Facebook may only have to gain consent for it's Like button once for any particular user, same for Google analytics etc.
This is going to be bad for a whole bunch of folk:
* Display advertisers
* Sites that need analytics
* Sites that use 3rd party widgets that require state and those 3rd party providers (discus, Facebook like buttons, etc.)
"The person setting the cookie is therefore primarily responsible for compliance with the requirements of the law."
and
"Where third party cookies are set through a website both parties will have a responsibility for ensuring users are clearly informed about cookies and for obtaining consent."
It opens up an interesting liability issue. I suspect terms of service agreements for companies that provide services based on 3rd party cookies may be updated shortly.
Facebook is legally an Irish company in Europe so cannot ignore this.
Just because said stalking is automated, used for commercial purposes and has been renamed with cool souding euphemisms doesn't suddenly make it acceptable. Neither is the fact that it currently happens on such a large scale that it affects virtually every website.
These laws aren't crazy, they are a gradual return to sanity. The EU isn't crazy either. The directive sets the baseline for what is and what isn't allowed in principle, allows for plenty of wiggle room and the way it is actually implemented and enforced will be a gradually process.
All this over the top ranting without showing any self-reflection or attempt at self-regulation is exactly why this is now forced upon us from above in the first place. The EU and various government en consumer organisations have repeatedly called for the industry to keep itself in check.
Instead, the industry has gone completely mental under the motto "we do it because we can", and as a result we now have a commercial surveillance network that surpasses anything any totalitarian government could have ever dreamed of. And which on top of that blatantly violates already existing privacy laws.
Congrats. Well done. We've awoken the beast of government regulation, and we only have ourselves to blame. You can't keep pissing all over consumers and civil rights without it resulting in some kind of backlash.
Not much. A few government-related sites have started showing an explanation about what a cookie is and does, and gives the choice of accepting or declining the cookie.
Other sites, despite the law, continues to function like normal. It's simply unenforceable on a large scale.
The ICO would have website owners pop up a box to new users asking them to give consent to using cookies.
Which if they refuse has to create a cookie so that their selection is remembered.
(Edited for clarity)
BT have a nice implementation of this, or at least would have if they’d turned off tracking cookies by default (hah). I assume that their code flexible enough that they can do this on the deadline. Look at the bottom right of http://www.bt.com/ (or any page on the same domain).
[1] http://www.international-chamber.co.uk/components/com_wordpr...
If you can't log them on, well... I guess you should try to guess their country, and if it's UK, you don't track.
This is another case of well-intentioned but probably unenforceable legislation by our detached European elites.
But like all good jokes there's an element of truth since I suspect that's exactly what some websites will do.
Take a look at what the ICO themselves do - they show a consent box at the top of every page unless and until you opt in:
That's true, but only (or at least, partly) because the sites can just ignore the header. If this became a standard HTTP hear and there was a requirement for it to be respected, browsers will quickly start supporting it.
>and it's not the default policy in any, AFAIK. It'd hardly have the same effect.
That's the whole point. It would still allow for analytics to be collected and made use of to improve web experience, while giving concerned users an easy way to opt out without being constantly hassled with "Will you allow us to track you?" question from each and every site they visit.
Where it is technically possible and effective,
in accordance with the relevant provisions of
Directive 95/46/EC, the user’s consent to
processing may be expressed by using the
appropriate settings of a browser or other
application.
[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...http://www.dlapiper.com/files/Uploads/Documents/DLA_Piper%20...
Who are screwed: Austria, Latvia, Lithuania, Sweden and the UK.
The actual law says that any non-strictly-needed cookie (or whatever you use to track users) MUST receive PRIOR opt-in from the user. It also clarifies that non-strictly-needed must be read in the narrowest sense possible, so that even saving user preferences is considered non-essential. As far as I can tell this means that even normal use of session cookies is outlawed.
There seem to be some posters here who think the law only matters for analytics, and hence as users it's not their problem. You couldn't be more wrong, there is no such restriction in the law! This will effectively make the internet unusable unless websites start grouping login/cookie access. Like with Google/Facebook/Twitter account login systems. If the intent of the law was to hamper those companies, it will effectively achieve the opposite by hurting the smaller players disproportionally.
And of course, you might not have to care because this will likely end up mostly unenforced. But as a site operator, it's still a Damocles' Sword hanging above your head if you ever get Kafka'ed. The fines are not small.
Are you going to ban in store CCTV and Footfall analysis next?
It's basically the same as keeping track of the number of customers a physical store gets in a day, or maybe the time customers spends in the store. This type of analytics is essential to offline and online businesses.
As a citizen of the UK I'm extremely disappointed.
You don't see how this is a major pain?
You can already get this behavior in your browser by changing user settings. Just try to surf like that for a while. It's horrendous, and what's worse, it doesn't make the user any wiser, really.
That is a grey area at best.
For one thing, a cookie that has a dual purpose, controlling both logging in and analytics, appears to give up any exemption on the grounds of strict necessity that a cookie used only for logging in would be granted. You would probably be required to provide all kinds of explicit information about your use of the cookie to anyone before allowing them to log in and setting that cookie, adding at least one extra step to your sign-up process (or making use of a single sign-in service much less convenient for your visitors).
For another thing, that still restricts your analytics to cases where someone is already logged in or otherwise actively using your site. Often the more interesting things to know relate to visitors to your site who are not (yet) so active: what are your best traffic sources/keywords, where do new people come into your site and where do they go next, and where do they give up if they don't convert?
I suspect most companies, other than those with the budgets and public visibility to run scared, will just ignore this law until it becomes a problem. Indeed, they haven't done a good job of promoting it either - it's been in a few news stories.. woopty woo, I bet the majority of webmasters haven't even heard of it.
The ICO has the power to force browser vendors with a UK presence to implement this at the browser level. I wonder why they didn't? Short-sightedness? Or perhaps they knew that Google/Mozilla/Microsoft are more capable of presenting a unified front to fight this, compared to however many thousands of web developers are affected.
"An organisation based in the UK is likely to be subject to the requirements of the Regulations even if their website is technically hosted overseas. Organisations based outside of Europe with websites designed for the European market, or providing products or services to customers in Europe, should consider that their users in the UK and Europe will clearly expect information and choices about cookies to be provided."
So, as a UK-registered business, you will be subject to this law.
My startup is registered in the UK, but all servers are outside of the UK. I am actually planning to just ignore this ruling and see what happens. If it looks like they are seriously going to go after startups that don't follow these rules, I will simply register the business in a location with less idiotic rules.
Information Commisisoner's Office - Enforcing the revised Privacy and Electronic Communications Regulations (PECR) of 25/5/2011 http://www.ico.gov.uk/~/media/documents/library/Privacy_and_...
Information Commissioner's - Office Guidance on the rules on the use of cookies and similar technologies of 13th December 2001: http://www.ico.gov.uk/news/latest_news/2011/%7E/media/docume...
"Check what type of cookies you use and how you use them"
"If the information collected about website use is passed to a third party you should make this absolutely clear to the user. You should review what this third party does with the information about your website visitors. You should tell people what you are collecting and how you are using this information."
"Even where the clear cookie rules do not apply you must consider the DPA [Data Protection Act] whenever you are collecting information that builds up a picture that could allow you to identify an individual."
"... the Commissioner is therefore unlikely to prioritize, for example, first party cookies used for analytical purposes and cookies that support the accessibility of sites and services, in any consideration of regulatory action."
"... we would expect you to provide clear information to users about analytical cookies and take what steps you can to seek their agreement."
Directive 2002/58/EC of the European Parliament of 12 July 2002: http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
"(25) However, such devices, for instance so-called "cookies", can be a legitimate and useful tool, for example, in analysing the effectiveness of website design and advertising, and in verifying the identity of users engaged in on-line transactions. Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using. Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for the use of various devices to be installed on the user's terminal equipment during the same connection and also covering any further use that may be made of those devices during subsequent connections. The methods for giving information, offering a right to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose."
Directive 2009/136/EC of the European Parliament of 25 November 2009: http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...
"(66) Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere (such as spyware or viruses). It is therefore of paramount importance that users be provided with clear and comprehensive information when engaging in any activity which could result in such storage or gaining of access. The methods of providing information and offering the right to refuse should be as user-friendly as possible. Exceptions to the obligation to provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user. Where it is technically possible and effective, in accordance with the relevant provisions of Directive 95/46/EC, the user’s consent to processing may be expressed by using the appropriate settings of a browser or other application. The enforcement of these requirements should be made more effective by way of enhanced powers granted to the relevant national authorities."