Related Articles
This blog post provides an update on the latest developments in cookie complaints and regulatory enforcements following our previous blog post on the surge of cookie-related complaints and the consequential regulatory enforcement actions by data protection authorities ("DPAs") in the UK and EU.
For the purposes of this blog post, cookies and similar technologies are collectively referred to as "cookies".
ICO's efforts in enforcing cookie compliance
In an effort to enforce website cookie compliance, the ICO wrote to 53 of the UK's top 100 websites in November 2023, warning them of potential enforcement actions should they fail to change their practices regarding the use of non-essential advertising cookies without user consent. Some of the ICO's concerns highlighted in the letter included the absence of cookie banners on website, the placement of non-essential advertising cookies before obtaining user consent, and the difficulty for users to reject non-essential advertising cookies as easily as they can accept them (i.e., the lack of a "Reject All" option on the first layer of the cookie banner).
Following the ICO's letter, the ICO reported in March 2024 that there was a commendable 80% success rate among the 53 organisation, with many updating their cookie banners to ensure compliance. Others are considering different approaches, such as contextual advertising and subscription models. The ICO is expected to announce further enforcement actions against non-compliant organisations.
Ongoing cookie complaints campaigns
Since our last report, NOYB (the non-profit privacy advocacy organisation founded by Max Schrems) has, since September 2022, filed a further 15 complaints with the Belgium DPA against companies for non-compliant cookie banners on their websites. To date, two organisations have since revised their cookie banners.
Regulatory enforcement
DPAs across the EU have seemingly responded to the increase in complaints from data subjects and privacy activists by increasing regulatory enforcement action in relation to unlawful cookie practices. We have set out below a summary of the recent fines issued by DPAs across the EU:
What should organisations be thinking about?
In light of the above, in particular the ICO's recent efforts in enforcing website cookie compliance, organisations should assess their own website cookie banners for compliance and to take steps to address any deficiencies.
Given the significant risk of enforcement action for failure to comply, we encourage organisations to take proactive steps, including to: