Resources - power2Cloud

Cookies and Consent Registry Important for GDPR - power2Cloud

Written by power2Cloud | 21/10/21

 

Recently, we addressed the topic ofonline compliance to understand what aspects we cannot overlook in order to protect users' sensitive data and not incur unpleasant penalties.

We return to this topic to tell you about an update, a new requirement mandated by the Privacy Authority. Did you know that you must now also keep detailed track of your users' expressed preferences for the use of Cookies?

In this article we will explain not only what the Cookie Preference Registry is, but also try to shed light on the use of Cookies more generally. 

If you don't have a Preference Registry you are violating the GDPR. TheCookie consent you acquire will not be considered valid, so you can risk penalties and fines of up to 20,000,000 euros.

power2Cloud as a partner of iubenda can activate the Cookie Preference Registry in short order on your site, eCommerce or Mobile App. Read on to learn more.

 

What is the Cookie Preference Registry

Allowing users to express their consent for the use of Cookies is no longer enough, it is now mandatory to register these consents as well, and to do so in the right way.

If required, your company must be able to prove at any time that the user who visited your site actually offered consent (the burden of proof will be on the Data Controller).

Here is what the register must include:

  • who provided consent;
  • when and how the individual user's consent was acquired;
  • the consent collection form presented to the user when collecting consent;
  • a reference to the legal documents and conditions in place at the time the consent was acquired.

To be compliant with regulations one must keep complete information: the user's unique identifier along with the date -- certified with a time stamp -- when the form was filled out, a copy of the version of the form itself, the legal documents used at the time the user gave consent.

We don't want to discourage you, but this is not an activity you can do manually and occasionally or without specific technical skills.

power2Cloud is helping many businesses like yours manage the legal aspects with iubenda. It is a solution chosen by more than 80,000 customers in more than 100 countries to comply with all regulations, including GDPR. 

Thanks to the iubenda Consent Solution, for example, power2Cloud can help you easily record, manage, and export evidence of consent for any of your users at any time. 

 

How to enable Cookies?

After sharing the update regarding the Consent Registry, let's take a step back. Maybe you have an eCommerce, you're doing marketing automation, but you don't know in detail about the data protection guidelines. What are Cookies, how should they be enabled and configured? 

Cookies are text files that are saved in the memory of the user's browser when browsing online, they allow the site that issued it, but also third parties, to recognize the user and aspects related to the user's characteristics, preferences and behaviors. 

You can imagine why they are useful: they allow a site to recognize a user's device to improve the browsing experience, while at the same time helping to ensure that the advertising content displayed online is on target with the user's interests.

What is the difference between first-party cookies and third-party cookies:

  • First-party cookies are created and used only by the site owner. The information collected and stored serves a variety of purposes and is usually not shared with third parties. They allow saving preferences, such as language or products added to the shopping cart, even between sessions.
  • Third-party cookies on the contrary are created by companies other than the one that owns the site the user is visiting and most often are used for research purposes, statistics or  to propose relevant and personalized advertisements.

If reading this article made you realize that you are not compliant, if you already have an advocate assisting you but it's been a while since you updated your policies, or you simply want to know in detail all the iubenda features, you can confront our team.

 

GDPR and Cookie Law, the requirements for European legislation

You will understand well that the processing of user data and the installation of tracking technologies necessarily require you to follow existing regulations, a subject as complex as it is delicate, not least because they change from country to country.

If you operate within the European Union or target European users, check that your site is compliant not only with GDPR but also with the Cookie Law (ePrivacy Directive).

With regard to Cookies the European legislation obliges you to:

  • provide a cookie policy
  • show a cookie banner when a user first visits your site
  • store proof of preferencesof your users, as required by the GDPR
  • block non-technical cookies (such as those from Google Analytics, AdSense etc.) before consent is given
  • release cookies only after collecting consent(prior consent).

In response to this need, here are two iubenda solutions that we recommend because they can help you right away:

  • Cookie solution iubenda (for GDPR, ePrivacy/Cookie Law, CCPA) is a comprehensive solution to comply with the provisions of the European Cookie Processing Act. power2Cloud can create a fully customizable cookie banner in just a few clicks, collect consent from your users to install non-technical cookies, and configure preemptive blocking for those that require consent.
  • Consent Solution iubenda (GDPR, LGDP, General Privacy Laws) helps you store and manage your users' proof of consent and privacy preferences. You can get a detailed record of consents collected, including when consent was given and by whom.
 

What happens if you are not GDPR compliant?

What happens if your site does not comply with GDPR? You can face fines of up to 20 million or up to 4% of annual worldwide sales, whichever is greater. It doesn't end there, your company may be affected by:

  • periodic data protection audits;
  • Official recalls if violations are found for the first time;
  • Invalidation and total and permanent blocking of your databases/databases containing non-compliant data (for the erroneous manner of collection and/or maintenance)
  • Liability damages.

Users at any time may file a complaint with the regulatory authority and be entitled to compensation for any damages, thus making violators susceptible to being sued.

If illegal activities are found, in addition to the subject of the complaint, for example an email address, the company may be prohibited from using the entire database in its possession.

 

What does the iubenda Consent Solution offer?"

Let's set aside sanctions for a moment and return to the solutions mentioned a moment ago, delving into the opportunities offered by the Consent Solution. Here is what it includes:

  • allows for informing users via a cookie banner and a dedicated cookie policy page (which is automatically linked to the privacy policy and integrates what is necessary for full Cookie Law compliance);
  • save consent preferences;
  • preemptively blocks cookies before consent;
  • keeps track of consent and saves the consent settings for each user for up to 12 months after the last visit to the site, as required by law.
 

What does the iubenda Cookie Solution offer?

Next we come to the iubenda Cookie Solution with which you can easily generate a fully customizable Cookie Banner, configure preemptive cookie blocking, and set user consent before releasing cookies. 

Depending on the tracking you do of user data and the tools you use, power2Cloud will help you follow all regulations.

Iubenda Cookie solution has several advantages, let's remember some of them:

  • plugin cookies for WordPress, Joomla!, PrestaShop and Magento. Also available is a PHP class
  • optimized to work with all mobile and touch devices
  • advanced consent statistics
  • memorize evidence of your users' preferences
  • GDPR, CCPA and LGPD ready
  • compatible with Google AMP
 

How to delete Cookies?

The time has come to put ourselves in the user's shoes.

We try to understand not only what our company needs to do to be compliant, but also how these regulations affect those who browse our site. 

Transparency is definitely one of the most important aspects, here is a small recap of the main requirements that we need to ensure online: 

  • Banner display/information; through script:

  • release of technical cookies,
  • blocking third-party cookies and parts of third-party code that might drop cookies;
  • alternatively to the above blocking, release of cookies that do not profile the user unless following the user's consent;
  • checking whether the user has already expressed preferences, analyzing whether the user is on his first visit or not; saving the user's preferences within a cookie;
  • management and updating of the cookie policy.

If a user wishes to change the preferences he or she has granted, he or she should be able to do so at any time, yet many sites present Banner Cookies that do not allow this, because they are incomplete and opaque.

Regardless of whether they are more or less compliant, Banner Cookies today are consulted superficially and with little awareness, because people are in a hurry to browse content. Many users have not yet understood that accepting everything means giving up their personal data to optimize the platform or paid campaigns.

Deleting cookies, however, is possible on all browsing browsers such as Microsoft Windows Explorer, Mozilla Firefox, Google Chrome, and Apple Safari. Just select Settings, usually under Privacy and Security, and delete them. Of course, the action should be resumed as often as you wish to do so.

The same operation must be repeated on the cell phone, usually by accessing Browsing History. Be careful not to also select passwords, in which case saved browsing credentials will be permanently deleted.

 

Why turn to an iubenda partner like power2Cloud

How do you manage online compliance? power2Cloud advises against burdening your eCommerce platform or site with hard-to-manage third-party plugins or creating pages that you then have to remember to update manually. 

The legal requirements are constantly changing, so you need to have documents that meet the latest requirements, generated using the iubenda service. Choose a secure all-in-one solution that does not require large investments with a partner like power2Cloud.

Our team deals not only with Cookie Policy and Banner Cookie, but also with Privacy Policy and Terms and Conditions.

With iubenda we guarantee you constant updates, thanks to an embedding function and not copy-and-paste.Of course, this is no substitute for legal advice; you can always have your lawyers review the documents generated with iubenda.

One of our accounts is ready to follow you throughout the duration of the service, you can also compare with our team for all the solutions needed for your work with the possibility of integrating them quickly.

With regard to Cookies the power2Cloud team will help you implement the regulations, with some preliminary steps:

  • identify all categories of cookies installed its your site and their purposes (First-party cookies);
  • identify third parties that, through the owner's site, may send cookies;
  • catalog cookies according to their processing purposes;
  • identify links to the Privacy policies and consent forms of third parties with whom the owner/operator of the site has entered into agreements to send Cookies from the same site (where available).

In case it does not have direct contact with third parties or in case it is particularly difficult to identify all third parties we will insert:

- links to the privacy policies of intermediaries (usually the site's advertising concessionaire) where available,

- link to www.youronlinechoices.com/it (limited to services surveyed by that platform, i.e., at present, those of advertising profiling);

  • update privacy policies.