To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.
To pre-empt the typical reply, yes you must serve a cookie banner even if you are only using functional cookies.
https://eur-lex.europa.eu/eli/reg/2016/679/oj
You are required to OBTAIN CONSENT from people you want to process the personal data of. Their consent must be INFORMED by telling them who you are and what you intend to do with their data. Their consent must be FREELY GIVEN and can be WITHDRAWN at any time.
That's what's at stake; not the cookies/state themselves, but how you intend to process the data of individuals. As long as you are not profiling natural individuals, no matter how they leave traces, then you don't need to ask for their consent.
It's bad-faith people, who clearly want to process personal data, who make a huge fuss and tell you everyone needs a cookie banner. Mainly because they are raging that they can't data-mine and monetise every last byte of data they can get, without the consent of the individuals they're profiting from.
> This site uses cookies. Visit our cookies policy page or click the link in any footer for more information and to change your preferences.
And then there are two buttons: "Accept all cookies" and "Accept only essential cookies".
The banner is doing two things. 1) It is notifying you that the site uses cookies. 2) It is requesting your consent for non-essential cookies.
Think about this for a moment, why is it doing both things? Why doesn't it just say "Do you consent to non-essential cookies? Yes | No"? Do you think this website added an extra sentence to their banner just for fun?
If you want to use essential cookies, you don't need to ask for consent. That is true. But you do still need to inform the visitor that you are setting cookies. Just as this banner does in its first sentence.
Feel free to (re)read the regulation, there is no such requirement at all.
> you must serve a cookie banner even if you are only using functional cookies
Specifically, where are you getting this from? It's a misunderstanding at best, but you're spreading it like it's confirmed information.
Most businesses are not actually GDPR compliant, even to this day. I assume this is a big reason the EU is willing to take another look at what is required for compliance.
I've also helped a bunch of organization become compliant, some were easier than others. The ones that were harder were the ones that generally didn't have good processes with data in the first place, where everything was scattered all over the place and everyone had access to everything. It makes sense to me that it's harder to be compliant if you were borderline malicious with how you treated personal data before GDPR.
The banners are the result of much earlier directives that predate GDPR by a lot...
I agree with you these cookie banners are not sufficient by the text, but in practice unless EU commission and courts make lawyers believe these banners are worthless, EU legal teams will still recommend them.
> What these two lines are stating is that cookies, insofar as they are used to identify users, qualify as personal data and are therefore subject to the GDPR.
gdpr.eu is by the way not an official resource of the European Union but by the Swiss Proton AG. They note down the page that gdpr.eu doesn’t constitute legal advice. Although they are correct in this case and your misunderstanding was in reading for future internet discussions I'd recommend not using private sources.
Organizations, and typically lawyers, skew conservative and lazy. A little cookie-consent cottage industry popped up to handle GDPR, so instead of worrying about the regulations most companies pay the small monthly service charge for a third party to handle consent. The consent companies built the most compatible solution, a banner, with the most conservative options as default to prevent any legal quandary.
Most public facing sites do have analytics (usually LOTS of analytics) and ads, so the banner is mandatory for them. If you understand the regulations, and don't violate them, then consent is not necessary.
> While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.
To me, it reads as you need some kind of banner/page explaining them. What you don't need is consent to store them.
Cookie banners where sites have to say "we're sharing your details with 287 partners" are okay because they should be shameful for the industry. Cookie banners where you're explaining basic technologies of the web -- "we store a cookie to create a stateful session with your browser" -- are obnoxious noise that do only harm.