Tracking cookies: how to avoid common mistakes

Data Protection Authority says most issues are unintentional

Close-up of a finger over a smartphone screen showing the accept button of a cookie policy.

Just put up a cookie banner and you’re sorted? In practice, there’s often a little more to keeping a website compliant. The Data Protection Authority (DPA) therefore actively scans websites to check that they’re following the rules on cookies and tracking. The regulator also provides advice on the correct way to obtain consent from visitors to your site.

The rules on the use of cookies have been around for years. Yet a lot of website operators find it hard to know exactly what cookies and other tracking techniques their websites are using.

And that’s not simply an administrative problem. Online tracking can lead to the compilation of detailed profiles of internet users. In The price of a free internet, the Rathenau Institute explains how data is gathered, combined, analysed and traded – with potential implications for privacy, autonomy and security.

Lars de Bie
Lars de Bie, Senior Inspector at the Dutch Data Protection Officer

Lars de Bie works in the System Monitoring Department, where he seeks to help organisations apply the rules correctly. Enforcement and education go hand-in-hand. “You can fine people who do things wrong. And you can try to persuade people to do things right in the first place.”

The first cause of confusion is that there are various different types of cookies. Functional cookies – the ones that do things like remember the contents of a shopping basket or keep a user logged in – don’t require consent. Nor do certain analytical cookies, as long as they have no significant privacy implications.

However, the situation with tracking cookies is different. Tracking cookies can be used to follow a visitor across multiple websites or apps to build up a profile and personalise the adverts that the visitor gets to see, for example. Cookies like that can’t be used without the user’s prior consent.

In the Netherlands, there are 2 important pieces of legislation. First there’s the Telecommunications Act, which lays down rules on recording and retrieving information on a user’s device. If any of the information counts as personal data, the EU’s General Data Protection Regulation (GDPR) comes into play as well.

A further complication is that the technology is changing. It’s increasingly common for browsers to block third-party cookies – cookies installed by someone other than the website owner. So tracking firms are switching to techniques such as server-side tracking, where data is forwarded via the website’s server, and fingerprinting, where the characteristics of the user’s device and browser are used to compile a profile. However, the rules still apply. Even if alternative tracking techniques are used, you still need to establish whether your website visitors’ personal data is being collected and whether consent is required.

Website owners often unaware of tracking

One of the main reasons why the rules get broken is surprisingly simple: many website operators don’t actually know what’s happening on their sites. An embedded video, map or chat interface can load third-party scripts, as can a plug-in or analysis tool. With the result that data may be collected, even though the site operator isn’t actually using it.

And, in some cases, the scale of data collection involved can be very considerable, according to Lars de Bie. “In practice, you sometimes find that literally hundreds of third parties are gathering data. They might even include, say, Japanese or Korean advertising firms that have very little interest in data from a Dutch site. Yet your visitors’ personal data is potentially going to those firms. What that reveals is mainly how some organisations barely stop to think about what they’re installing on their websites.”

Larger organisations too can sometimes lose their oversight. One department will instal an analysis tool and another will add a marketing tool, without the team that manages the organisation’s cookie banner knowing anything about it.

Three common issues

Ilja van Gog
Ilja van Gog, Senior Inspector at the Dutch Data Protection Officer

Working in the Primary Investigation Department, Senior Inspector Ilja van Gog sees a number of recurring problems with websites.

The first is tracking cookies being installed before the visitor has consented. “One of the things that can cause that to happen is if a third-party tool or embedded feature is activated immediately when the page loads.”

Problems with the ‘Reject’ button are also common. Sometimes there’s no ‘Reject’ button in the cookie banner’s top layer, or it doesn’t work properly. It should be just as easy to reject cookies as to accept them. So an obvious ‘Accept all’ button and less prominent or less accessible ‘Reject’ button doesn’t meet the requirements.

Often, what happens after consent has been given isn’t right, either. It should be easy for a visitor who has given consent to later withdraw it. A website therefore has to make it clear how consent can be withdrawn – a link to the cookie settings might be provided in the footer, for example.

According to the DPA, shortcomings with websites are rarely deliberate. More typically, the website operator believes that their cookie banner satisfies the rules, or assumes that the default software settings are fine. Sometimes the DPA even comes across cookie banners on sites that only use functional cookies and a few analytical cookies without privacy implications. Whereas a site like that doesn’t actually need a cookie banner.

Website owner is always responsible

Many organisations use consent management platforms (CMPs) for their cookie banners. Such platforms check what cookies and other trackers a site uses and control what scripts should and shouldn’t be loaded, in line with the visitor’s preference settings. A CMP may also provide a mechanism for withdrawing consent previously given.

Using a CMP is a technically convenient approach, especially for smaller organisations. However, a website operator can’t simply enable a CMP and assume that everything’s taken care of. According to the DPA, the default settings of many CMPs don’t satisfy Dutch and European rules. After all, some platforms were developed for markets where the privacy laws are very different.

And it’s always the organisation behind the website that’s responsible for making sure that the rules are complied with. If shortcomings are discovered, it’s no good saying that the website builder or another service provider set up the cookie banner.

So it’s important to check for yourself how your website is actually working. You can do that using your browser’s developer tools or using special analytical tools. Advice on the available resources is available on the DPA website, where you’ll also find info about the criteria a good cookie banner should meet.

Collecting less data is also an option

Another way of simplifying things is to ask yourself what data you actually need to collect. After all, if you can avoid using tracking cookies, you can save yourself the trouble of getting consent. Functional cookies and narrow-scope analytical cookies are all that some websites need.

Even for advertising, other approaches are possible. The Rathenau Institute suggests contextual advertising as an option, for example. That involves aligning the advertising on a site with the content of the page – say, an ad for running shoes to go with an article about running. The advantage of contextual advertising is that it removes the need for visitor profiling.

So it’s very much in line with a simple rule of thumb that Lars de Bie uses: “We always say that data you haven’t got can’t be leaked or stolen.” If you’re not gathering data, there’s no danger of it being resold or falling into the wrong hands any other way.

Support comes first, with enforcement as a fallback option

The DPA actively monitors the use of cookies and tracking. Where possible irregularities are detected, the first step is often to send a warning letter, advising the organisation in question to rectify the situation. The DPA also provides guidance and organises information sessions.

Failure to respond to a DPA warning letter is liable to result in an investigation and ultimately a penalty. For example, the DPA has previously issued fines for installing tracking cookies without valid consent.

Wherever possible, though, the DPA prefers website owners to take corrective action themselves. And many do just that: according to Lars de Bie, three quarters of warning letter recipients fix their websites before the deadline date.

The first thing that a website operator should do, therefore, is straightforward: regularly check what cookies, scripts and other tracking techniques your website is actually using. Next, check whether any of them require user consent, and whether your cookie banner clearly offers visitors the choice of giving or refusing consent. Guidance on creating a clear cookie banner and information about available tools and resources are available from the Data Protection Authority’s website.