Overview of the current legal basis for consent processes when storing cookies

When is a consent layer really mandatory? We explain which cookies require explicit consent and how you can strike the balance between legal certainty and valuable marketing data.

Contents

  1. What are cookies?
  2. What types of cookies are there?
  3. How can you find out whether a website uses cookies, and which ones?
  4. Legal implications of using cookies
  5. What legal bases are there?
  6. What does this mean for consent layers?
  7. Which type of consent layer do I need for which cookies?
  8. Conclusion

1. What are cookies?

 

Cookies are small text files stored on the user's computer, which the website accesses via the browser to read information. For example, whether the current user is logged in (session cookies), which pages they have already visited (performance or advertising cookies) or which products they have added to their shopping cart.

2. What types are there?

 

Cookies perform different tasks. Depending on their purpose, they can be categorized as follows:

  • Technically “necessary” cookies: These cookies are used for functions that (currently) could not be implemented technically without cookies at all. For example, logging in to a customer or user account, or shopping cart functions.
  • Functional cookies: These cookies improve a website's usability, for example by saving settings so users don't have to choose them again and again. A classic use case is a language switcher that remembers the selected language and applies it to all subsequent page views. Functional cookies can also be used to store form data.
  • Tracking cookies: If you want to find out which channel users came from, how they interact with the website, how long they stay and which content performs particularly well, you can use analytics programs to create statistics and reports on website visits. Tracking cookies are used for this purpose to distinguish individual users and build movement profiles. Depending on the system used, users are “only” counted, assigned or profiled.
  • Advertising cookies: These cookies are used to serve users relevant ads based on their movement profile, i.e. cross-website “retargeting”.
  • Cookies can also be distinguished by how long they remain valid:
  • Session cookies are only stored for the duration of the current browser session. When the browser is closed, the cookie is deleted as well.
  • Persistent cookies remain stored on the user's computer for a predefined period, regardless of the browser session, unless they are deleted manually.

Cookies also differ in who sets them:

  • First-Part
  • y cookies are set by third-party companies whose services are embedded in the website (such as YouTube, Facebook or Google Maps). These can be services that are visible to the user, or invisible ones that only run in the background.

3. How can a user find out whether a website uses cookies, and which ones?

 

Because cookies are stored and read in the background when you visit a website, you can't immediately tell which ones a page uses. To find out, you need special tools that are either provided by the browser or installed as a plug-in. These include the Chrome browser's developer tools, the Firefox Developer Edition and the Ghostery plug-in, which in many cases shows not only the names of the cookies but also their function and storage period.

4. Legal implications of using cookies

 

In other EU countries, consent layers have been standard for much longer than in Germany. That's because the EU Cookie Directive was never transposed into applicable law here: Section 15(3) of the German Telemedia Act (TMG) already existed, and the EU Commission considered it sufficient. Yet that provision actually only referred to information and a notice of the right to object – without requiring explicit consent. When it comes to cookies, the legal situation in Germany is therefore even less clear than in other EU countries.

Now, however, the GDPR also applies in Germany. And it prohibits any storage and processing of personal data in principle – unless there is a legal basis that permits such storage and processing. This construct is known as “prohibition subject to permission”.

Do cookies fall into the category of “personal data”?

 

Since the GDPR, yes, because they serve to recognize the user or the device they use. They are personal if, for example, they store login data for a user account or e-mail addresses from a form field. Since the GDPR explicitly counts “online identifiers” as personal data, it is enough for a cookie to be able to identify a website user as a “unique user” for it to be classified as “personal”. This is why so-called pseudonymous data – data that does not establish a direct link to a person but does make it possible to identify a person, for example as the recipient of an advertising measure – is also subject to the rules for personal data.

If you use cookies that can be classified as personal data, you need a legal basis to use them. As described above, since the GDPR, storing and processing personal data without an appropriate legal basis is prohibited.

5. What legal bases are there?

 

Art. 6 GDPR defines six different conditions under which the storage and processing of personal data is lawful. Two of them are particularly relevant to our question:

  • consent and
  • so-called “legitimate interest”.

And which legal basis applies to which cookies?

 

  • For technically necessary cookies as well as functional cookies, the website operator's legitimate interest generally applies.
  • IT lawyers now largely agree that for pure analytics/tracking cookies, the operator's legitimate interest also prevails – provided the data is pseudonymized, for example by truncating IP addresses. A privacy-friendly configuration of tracking tools such as Google Analytics or IntelliAd should therefore be a matter of course. However, a position paper by the Data Protection Conference (DSK) published shortly before the GDPR deadline, along with an update from March 2019, takes a different view and requires prior user consent whenever tracking mechanisms are used. This interpretation drew a lot of criticism, partly because both the recitals of the GDPR and the current draft of the ePrivacy Regulation argue against such a strict assessment. Here, then, choosing the legal basis also comes down to your own risk assessment. The DSK's position is not legally binding; it merely expresses an opinion. Judges will likely decide on this “gray area” in upcoming proceedings. Until then, it is the website operator's responsibility to make their own classification.
  • For advertising cookies, the interpretation is straightforward: for retargeting to work, for example, the user must be uniquely identified. Until specific individual rulings or the ePrivacy Directive provide more clarity, the safest option – and the one most IT lawyers recommend – is likely to obtain the appropriate consent.

6. What does this mean for consent layers?

 

Consent layers, also known as cookie banners, are meant to handle communication between the website (or its operator) and the user. They should inform users about the cookies used and their purpose and, where the operator has no legitimate interest, give users the choice to accept or reject a procedure.

However, most consent layers in use today merely inform users that cookies are being used. Often, cookies are already loaded in the background. Users have no choice, and the usefulness of these consent layers is debatable.

The ideal: opt-in

 

But there are also consent layers that genuinely give users a choice, and even let them make it BEFORE anything has happened. Asking users whether they agree to the use of cookies before the first cookies are actually set is, of course, the best solution. This opt-in approach is recommended and legally sound, but it is still used too rarely. First, no doubt, because it is technically more complex. It requires a consent management platform (CMP) that processes and stores the user's settings and then passes on to the tag manager which cookies may be loaded. Second, because many marketers fear they will lose user data if they really give users a choice.

The fine-tuned version of opt-in doesn't just offer a choice between “Yes” and “No”. It distinguishes between different types of cookies. This way, a user can, for example, allow functional cookies that make browsing more convenient while switching off advertising cookies.

The compromise: opt-out

 

Letting users choose not to accept cookies only AFTER cookies have already been set doesn't sound very logical at first. Even so, this approach is quite widespread and is standard practice for tracking cookies in particular.

7. Which type of consent layer do I need for which cookies?

 

A consent layer only really makes sense if it obtains valid consent. Clicking an “OK” button with no alternative after the generic notice “This website uses cookies” is no more valid consent than continuing to use the site by clicking or even just scrolling.

Since no consent is required for processing personal data based on the operator's legitimate interest as the legal basis, no consent layer is needed in such cases either.

This means:

  • Technically “necessary” cookies (such as session cookies or shopping cart cookies) don't require a consent layer.
  • The same applies to functional cookies that make the site easier to use (e.g. language switchers).

Important: For both, however, you should provide the relevant information in your privacy policy.

Opinions differ when it comes to tracking and analytics cookies. According to the Data Protection Conference's view described above, the common opt-out mechanisms for Google Analytics, IntelliAd & Co. would not be sufficient. The user would have to explicitly opt in BEFORE tracking begins.

So every website operator has to make this decision based on their own assessment: Do you want to be overly correct and follow the Data Protection Conference's assessment (which is disputed and, as mentioned, not legally binding)? Or do you go with the majority and stick with the usual opt-out option in your privacy policy? In that case, a consent layer that points out the opt-out option may be a good idea. Whether that is necessary is another question – if in doubt, a notice in the privacy policy is enough. Depending on your appetite for risk and your usability preferences, you have three options when using tracking cookies:

  • use no consent layer at all, and simply provide information and an opt-out in your privacy policy;
  • use a consent layer that points out the opt-out option;
  • use a consent layer that allows an explicit opt-in, and only set tracking cookies after this opt-in.

That leaves advertising cookies. As shown above, the current legal assessment is that their use requires consent, so you should probably use a consent layer here. We recommend offering an opt-in solution that only sets advertising cookies once the user has agreed.

8. Conclusion

 

To be on the safe side legally, use a consent layer and inform your users about your cookies and their purpose.

In it, distinguish between technically necessary cookies, for which you don't need to offer users an opt-out, and cookies that are not strictly technically necessary.

For marketing cookies, you need an opt-in before they are fired. This opt-in must be processed and documented accordingly, and it must be possible to withdraw it.

For tracking cookies, it is currently up to you to decide which ones require an opt-in and which ones you offer an opt-out for. Keep an eye on current and future proceedings and case law (e.g. the ruling expected on 1 October 2019 in the case CJEU – C-673/17, Planet49).

My current personal recommendation is to split tracking cookies into two categories. For those that “only” count users anonymously and attribute them to marketing channels, you should offer an opt-out. Those that build profiles, execute tracking codes or even call third-party codes should require an opt-in.

Beyond assigning cookies to opt-ins and opt-outs, the design of your consent layer should play a key role. It determines how high your consent conversion rate is – a figure that is crucial for your marketing.

Related posts
/ NEXT STEP

Feed the ad platforms better signals.

Your campaigns are only as good as the data you feed them. Use our server-side infrastructure to supply Meta CAPI and Google Enhanced Conversions with 100% real data – fully automated. Server-side tag manager included.
book a demo
integrations