Would you like a cookie – or are you absolutely sick of being asked?
When the government released its proposals for flashy new privacy plans in the UK, all eyes were on cookie consents – those annoying pop-ups that come to the fore on many websites asking if you accept cookies, tiny snippets of text can be used to track things about you, including:
- what you do on the site
- where in the world you are
- what device you are using
- where to go online afterwards
The companies behind the websites use this information for a number of reasons – ad targeting plays a big part in this.
But it also gives you a customized version of the site, they say.
If it knows you’re watching a lot of technology news, it can give you more – and less about gardening, for example.
However, if you choose not to allow cookies, the site has no other way of remembering that choice – you will need to log out each time you visit.
But now the government wants to limit those cookie consents and instead propose a one-stop privacy setting applied at the browser level.
Google tried something similar years ago, a “Do Not Track” header – but it wasn’t legally enforceable, users couldn’t verify that sites respected it, and it was mostly dropped. A note on the Mozilla developer site advises against it.
More privacy-focused tech giant Apple regularly gives owners of its products reports on how many websites and apps are trying to track them.
But like it or not, tracking and data collection has become the way a “free to use” internet is funded – by content providers who can convert it into advertising revenue.
Even for those who disagree with cookies on principle, it has become a tedious war of attrition. “Yeah, you can have my damn cookie!” tweeted a distraught Elon Musk.
Many critics consider the pop-ups pointless in their current form. A 2019 study found that most cookies are “non-compliant with EU data protection law”.
However, trade association TechUK says there are “unresolved questions” about exactly how the UK alternative would work, suggesting more consultation is needed.
And privacy activists at the Open Rights Group are outraged that it could mean opting out rather than opting in to tracking, saying it falsely places the responsibility on individuals who prevent, rather than allow, surveillance of their online lives.
The data reform bill is an attempt to move away from what the government calls the “red tape” of Europe’s General Data Protection Regulation (GDPR) – most of which has been transposed into UK law.
The GDPR places enormous emphasis on protecting the privacy and data of individuals, with heavy penalties for non-compliance, but cookie consent is not covered.
The Data Reform Act also proposes the following:
- Eliminate the obligation for small and medium-sized businesses to hire data protection officers and conduct thorough impact assessments of data collection activities
- To allow the Information Commissioner’s Office, which is currently required to investigate every privacy complaint that it receives, to “be more flexible and focus our actions on the greatest harms”, according to Commissioner John Edwards.
- Expanding data access for public services and research – For example, if you consent to the use of your health data in a specific Covid-19 study, similar future studies will currently have to ask for your consent again
All of this can be done without weakening Britain’s data protection ‘gold standard’, government says. It could save businesses £1billion over 10 years and eliminate ‘check box’ exercises.
Culture Secretary Nadine Dorries calls it “consolidating Britain’s position as a post-Brexit science and technology superpower”.
But so far, reactions have been mixed, with industry generally being more supportive than privacy advocates.
TechUK – which has been working with the government on the proposals – calls them “a welcome pack”.
“The reforms … strike a good balance between making the UK data protection regime clearer, more flexible and easier to use for researchers, innovators and smaller companies,” says Chief Executive Julian David.
But the Open Rights Group calls the bill a “bonfire” of rights.
“At a time when personal data can be used to do all sorts of wrong things, it is wrong, irresponsible and negligent to present privacy as a liability,” it said.
Meanwhile, lawyers are examining how the proposals could affect data sharing between the UK and the EU.
Vinod Bange, of law firm Taylor Wessing, said his initial reaction was “relief” that there hadn’t been a full rewrite of the existing policy.
But he adds: “The most impactful changes for UK organizations will be the unintended consequences, so changes that could affect the current adequacy of data flows with the EU need to be monitored.”
Nothing is likely to change overnight – the bill has yet to roll through Parliament – but expect a lot more debate in the coming months.
Add Comment