(C) Alec Muffett's DropSafe blog.
Author Name: Alec Muffett
This story was originally published on allecmuffett.com. [1]
License: CC-BY-SA 3.0.[2]
Dr. Carlo Piltz on LinkedIn: Entscheidungsdatum
2025-01
๐๐๐๐๐ฟ๐ถ๐ฎ๐ป ๐๐ฒ๐ฑ๐ฒ๐ฟ๐ฎ๐น ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ถ๐๐ฒ ๐๐ผ๐๐ฟ๐ ๐ฐ๐ผ๐บ๐บ๐ฒ๐ป๐๐ ๐ผ๐ป ๐๐ต๐ฒ ๐๐๐ฒ ๐ผ๐ณ ๐๐ต๐ฒ ๐๐๐ฃ๐ฆ ๐ช๐ฒ๐ฏ๐๐ถ๐๐ฒ ๐๐๐ถ๐ฑ๐ฒ๐ป๐ฐ๐ฒ ๐๐ผ๐น๐น๐ฒ๐ฐ๐๐ผ๐ฟ & ๐ผ๐ฝ๐๐ถ๐ผ๐ป ๐๐ผ ๐ฟ๐ฒ๐ณ๐๐๐ฒ ๐ฐ๐ผ๐ป๐๐ฒ๐ป๐ ๐ผ๐ป ๐๐ต๐ฒ ๐ญ๐๐ ๐๐ ๐ฃ ๐น๐ฎ๐๐ฒ๐ฟ The Austrian Federal Administrative Court has clarified in its decision of 31 July 2024 that a cookie banner must also contain a visually equivalent option to refuse the use cookies & other technologies in addition to the option to accept them on the 1st layer. The Court also found that the European Data Protection Supervisor's (EDPS) Website Evidence Collector can be used to prove the use of cookies in legal proceedings. -Facts of the case- Following a complaint from a data subject, the authority had investigated the use of cookies on the website of the plaintiff and found that the use of cookies could only be rejected within the cookie banner by clicking on the buttons โShow purposesโ and in the second step โReject allโ. In contrast, consent could be given in one step by clicking on the โAcceptโ button. According to the authority, this design of the cookie banner violated Art. 6 and 7 GDPR and therefore instructed the plaintiff to modify the cookie banner so that a visually equivalent option to deny consent was available on the first layer of the cookie banner. The supervisory authority has collected the relevant evidence for the use of cookies on the plaintiffs website using the Website Evidence Collector. -Court decision- In the opinion of the Court, not giving consent must be just as simple as consenting. The possibility to refuse cookies on a second layer, while being able to accept them on the first layer of the cookie banner does not fulfil this requirement. Remarkably, this requirement was deducted from Art. 7 (3) GDPR, making the argument debatable as the mentioned provision regulates the question of withdrawal of consent and not giving one. The Court had no objection concerning the use of the Website Evidence Collector. On the contrary, based on the evidence collected with the tool, it considered the use of cookies to be proven. The acceptance of the evidence collected with it implies that in the eyes of the Court, the Website Evidence Collector represents a technical standard for website analysis tools. -Consequences for the practice- Refusing or denying consent should be as easy as consenting. Companies should review cookie banners on their websites or in Apps, if an option to refuse consent exists on the first layer of the CMP. Controllers can also consider the use of the Website Evidence Collector in order to check their website. The fact that its results have proven to be reliable in court also establishes a technical standard for tracking analysis. Decision (German):
https://lnkd.in/dN-Geicr #GDPR #eprivacy #Cookies #Tracking #dataprotection
[END]
[1] URL:
https://www.linkedin.com/posts/dr-carlo-piltz-631571b_entscheidungsdatum-activity-7270422586419761153-9YgE
[2] URL:
https://creativecommons.org/licenses/by-sa/3.0/
DropSafe Blog via Magical.Fish Gopher News Feeds:
gopher://magical.fish/1/feeds/news/alecmuffett/