Cookies
What are Cookies?
Cookies are small text files that are stored on various devices, such as PCs, laptops, and mobile devices, to hold information about the user’s interactions with websites. They play a crucial role in web services that require user identification. For example, when a user logs into a web-based email account like Gmail, servers that host the email need to recognize that the user has successfully logged in. Upon visiting a website, a cookie is generated and saved in the user's web browser (e.g., Firefox), a process often referred to as 'dropping the cookie'.
Functions of Cookies
Cookies perform multiple functions, including:
User Recognition: They remember users and their interactions with websites.
Example: Cookies can keep track of items in an online shopping cart or retain information in an online application form.
Performance Enhancement: Some cookies expedite web page loading times.
Data Collection: Websites utilize cookies to gather information for targeted advertising, allowing them to tailor ads to individual consumers.
How are Cookies Used?
Cookies are employed in various scenarios:
Sign-in: Websites like Facebook require user sign-ups, which are facilitated through cookies.
Analytics: For instance, Google Analytics utilizes cookies to track visitor behavior on websites, aiding operators in identifying bugs and popular site areas.
Customization: Websites utilize cookies to remember user preferences such as language and font size.
Checkout Processes: Cookies are instrumental in the functionality of online shopping baskets.
Security: Websites that face hacking threats leverage cookies to identify and block potentially abusive machines.
Advertising: Cookies track user movements across the web to construct profiles, which inform the type of advertisements displayed.
Information Stored in Cookies
Cookies can store various types of information:
Personal Data: This includes IP addresses, usernames, unique identifiers, and email addresses.
Non-Personal Data: Data such as language preferences and device type are often recorded.
Advertising & User IDs: Identifiers that aid in tracking user activity.
Note:
The E-Privacy Regulations apply to all cookies, irrespective of whether the stored or accessed data is personal.
First-Party vs. Third-Party Cookies
First-Party Cookie: A cookie that is set by the website the user is visiting (the host domain).
Third-Party Cookie: A cookie set by a domain other than that of the website being visited. An example includes social media plugins like ‘like’ buttons.
Regulation of Cookies
Assignment Overview
S.I. No. 336/2011: Known as the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, commonly referred to as the E-Privacy Regulations.
The enforcement of E-Privacy regulations is overseen by the Data Protection Commission (DPC).
These regulations complement the General Data Protection Regulation (GDPR) and contain specific rules related to cookies.
Purpose of the E-Privacy Regulations
The primary aim of the E-Privacy Regulations is to safeguard the privacy of individual communications. The laws regarding cookies are designed to prevent information from being stored on or accessed from personal devices without the user’s consent, thus protecting the confidentiality of communications. Technologies like spyware, web bugs, and hidden identifiers can access personal devices without knowledge and track user activity and habits, which this regulation seeks to mitigate.
Specific Provisions on Cookies in the E-Privacy Regulations
Articles 5(3) to 5(5)
These articles cover situations where individuals use electronic networks to either store or access information on their terminal devices, which include smartphones, computers, or tablets, directly connecting to the regulation of cookies.
Cookies are inherently included in these regulations as they store information on a user’s browser, which websites then read to identify users.
ODPC Compliance Sweep (2019/2020)
The Office of the Data Protection Commissioner (ODPC) conducted a compliance sweep in 2020, assessing the adherence of business websites to E-Privacy regulations concerning cookie usage. Out of 38 businesses reviewed, only two were compliant.
Significant issues arose as companies, particularly in the health sector, were found sharing special category personal data with third parties in the advertising technology industry.
User Consent for Cookies
Regulation 5(3) mandates that users must:
Give explicit consent for cookie usage.
Receive clear and comprehensive information about the purpose of cookies.
Regulation 5(4) requires that this information should be easily accessible and presented in a user-friendly manner, ensuring users are notified about what they are consenting to regarding cookie use, with means to grant or refuse consent.
E-Privacy Regulations vs. GDPR
The E-Privacy Regulations are applicable whenever information is stored or accessed from a device, regardless of the personal nature of that information. Where cookies include identifiers that can target individuals, or if the information is utilized for profiling, this qualifies as personal data, thereby falling under GDPR guidelines.
Consent Requirements
The regulations necessitate that consent is required to access or store data on a person’s device, implying that consent must be obtained for both set cookies and data storage, irrespective of whether the data is classified as personal.
Planet 49 Case, ECJ 2019:
In this case, a German consumer organization took action against an online gambling website that pre-checked boxes for cookie consent during the login section for a lottery site.
The European Court of Justice (ECJ) ruled that websites must secure explicit, specific consent under EU privacy laws, establishing that pre-ticked checkboxes alone do not suffice to meet legal consent requirements.
Outcome of the Planet 49 Case
The ruling emphasized that pre-checked boxes and sliders are non-compliant with EU law.
Consent does not need individual approval for each cookie; however, it is essential for the specific purposes for which cookies are utilized. If multiple purposes necessitate consent with a single cookie, consent must be clearly obtained for all those purposes separately.
Third-Party or Tracking Cookies
Tracking cookies follow a user’s web activity across multiple websites for targeted advertising, necessitating a prominent notice on the homepage informing users about cookie practices with links to a detailed Cookie Statement. This should enable informed choices and the ability to manage and disable cookies.
Cookies and Expiry Dates
Session Cookies: These are temporary and exist only for the duration of the browser session.
The expiration of a cookie should align proportionally with its purpose. For example, a session cookie meant to hold items in an online cart should expire once that function is fulfilled, without extending indefinitely.
Other Tracking Technologies
Besides traditional browser cookies, various other tracking technologies exist, including:
Local Storage Objects (LSOs) or flash cookies
Software Development Kits (SDKs)
Pixel Trackers (often seen in pixel GIFs)
Social media sharing tools and buttons
Device fingerprinting technologies
These technologies are also subject to cookie laws due to their access and storage capabilities on user devices.
Exemptions from Consent Requirements
Two main exemptions exist:
Communications Exemption: Refers to cookies necessary for transmitting communications over a network, such as load-balancing cookies for server traffic distribution.
Strictly Necessary Exemption: Applies to Information Society Services (ISS), which must be explicitly requested by users, with cookies limited to what is strictly necessary for providing the service. For example, a shopping site's session cookie tracking product choices is acceptable without consent, but advertising-related cookies require it.
Do Analytics Cookies Require Consent?
Yes, analytics cookies that account for visitor volumes and page interactions necessitate consent.
First-party cookies with analytics performed by the controller require clear information in the privacy policy, including opting out of data collection, while third-party analytics can introduce greater privacy risks.
Multiple Purposes Consent
Consent cannot be bundled for multiple purposes. Best practices involve:
First Layer: Informing the user about consent for cookies used for specific purposes.
Second Layer: Providing detailed information regarding the types of cookies and technologies employed, along with the option to opt-in or accept.
User Consent Withdrawal
Users must possess the capability to withdraw consent as easily as providing it. Implied consent cannot be accepted as valid in cookie use; users cannot be considered consenting simply due to using default browser settings that enable data collection. Cookie banners should not disappear depending on user activity, such as scrolling.
User Browser Settings and Consent Inference
Consent cannot be inferred from default browser settings, as users may not be fully cognizant of how to manipulate such settings to deny cookie permissions. According to the Art 29 Working Party Opinion 2/2010 regarding Online Behavioral Advertising, average users may lack understanding related to effective browser rejection of cookies.
Designing Accessible Interfaces
It is vital to ensure cookie banners and options are accessible to all users, including those with disabilities, ensuring interface confusion is minimized through contrasting color schemes not leading into invisibility against the site background.
Joint Controllers
Entities utilizing third-party tools (like 'like' buttons, plugins, or pixel trackers) must assess their data relationships with such third parties and recognize their role as data controllers regarding the personal data they collect and share. Contracts between controllers and processors must also be established under GDPR requirements.
Special Category Data under GDPR
Article 9 of the GDPR classes the following as special category data:
Racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health information, and sexual orientation classified data.
General regulations prohibit the processing of such data unless specific exemptions, including explicit consent, apply, which may be unattainable through standard cookie banners.
Location Tracking and Consent
Cookies must not be employed to track user locations or devices without explicit consent. The ECJ has acknowledged the sensitive nature of tracking data, reflecting individuals' daily activities and movements.
Copyright
Governing Legislation
The Copyright and Related Rights Act 2000 regulates copyright laws in Ireland.
Amendments through the Copyright and Other Intellectual Property Law Provisions Act 2019 updated the legal framework for intellectual property rights in the digital era, enhancing enforceability in courts.
Nature of Copyright Rights
Copyright represents an exclusive right to copy, utilize, and deal with certain works, typically covering literary, dramatic, musical, or artistic content.
Copyright as a Property Right
According to S.17(1) of the 2000 Act, copyright is classed as a property right. The creator or copyright owner retains the authority to permit reproductions through various forms, such as publishing or marketplace performances.
Automatic Copyright Arising
Copyright arises automatically upon creation and does not necessitate registration. A key case Phonographic Performance (Ireland) Ltd v William Cody and Princes Investments Ltd [1994] established that copyright derives from constitutional rights protecting private property.
Subject-Matter of Copyright
As stated in S.17(2), copyright protects:
Original literary, dramatic, musical, or artistic works.
Sound recordings, films, broadcasts, or cable programs.
The typographical arrangement of published editions and original databases.
Expression of Ideas
Copyright law safeguards only the expression of ideas, not the underlying concepts or principles. (University Press Ltd v University Tutorial Press Ltd [1916]).
Recording Requirement for Copyright
As provided in S.18(1), copyright protection is not applicable to literary, dramatic, or musical works unless expressed in writing or recorded.
Additionally, copyright in sound recordings is not valid until the initial fixation occurs.
Originality in Copyright
Original works must result from the author's creativity, skill, and effort, rather than being derivatives of existing works. (Macmillan & Co. Ltd v K & J Cooper [1924]).
Definition of Literary Work
According to S.2 of the Copyright Act, a literary work encompasses any work expressed in writing, but not including dramatic, musical, or original database works.
Examples of Literary Work
Examples of works that have not received copyright protection include:
Names (Exxon Corporation v Exxon Insurance Consultants International Ltd [1982])
Titles (Dicks v Yates [1881])
Single words (Wombles Ltd v Wombles Skips Ltd [1975])
Court Cases and Literary Work
Various legal precedents illustrate what constitutes a literary work, including:
Books: Folens v O’ Dubhghaill and Joyce (1973).
Newspaper reports: Hall v Crosbie & Co. (1931).
Legal reports: Hodges v Walsh (1840).
Literary Merit Not Required
Works do not need to possess literary merit to be protected; examples include exam papers or business correspondence (University Press case).
Definition of "Written" in Copyright Context
The term 'written', as defined in S.2(1), includes notation or code, regardless of recording medium.
Definition of Artistic Work
According to the Copyright Act S.2(1), artistic works comprise:
Photographs, paintings, drawings, and architectural works.
Artistic merit isn't a stipulation for protection, as demonstrated in various cases (Allibert v O’Connor [1981]).
Secondary Artistic Works
Copyright can be assigned to secondary artistic works that are original, although derived from others, requiring tangible alteration or embellishment (Interlego AG 1989).
Protection of Computer Programs
Copyright grants protection to computer programs as literary works since they can be represented in written form, highlighting the overlap between copyright and patent law.
Neighboring or Related Rights
These rights relate to sound recordings, films, and broadcasts, which don’t arise solely from authorship but exploit literary or artistic works instead.
Film Definition
The term film, as defined in S.2, encompasses any medium capable of producing or communicating moving images in a technology-neutral manner.
Broadcasts Definition
The term broadcast involves transmitting information wirelessly for public reception, thus providing copyright protection for media organizations like RTE in their broadcasts.
Sound Recordings Definition
Sound recordings are defined similarly to films, whereby the fixation of sounds must be reproducible regardless of medium.
Database and Typographical Arrangement Copyright
Databases and hypothetical constructions (like telephone directories) may also be protected, introducing a new property right under parts II and V of the Act.
Ownership of Copyright
Copyright ownership theoretically lies with the creator of the work (author) as per S.21, yet exceptions exist, such as where an employee creates a work within employment (S.23).
The author must be a 'qualified person', meaning they are an Irish citizen or domiciled resident.
Infringement of Copyright
Based on s.37(2), copyright infringement occurs when someone performs restricted acts without the copyright owner's consent. S37(3) stresses that infringement relates to the work's entirety or its substantial parts, whether acts occur directly or indirectly.
Secondary Infringement
Infringement can also be secondary, involving:
Handling infringing copies.
Facilitation of infringement.
Permitting infringing performances.
Exception to Infringement Conditions
s.38 permits playing sound recordings publicly without prior permission of the copyright owner, under specific statutory payments to licensing entities.
Techniques for Infringement Proof
Evidence must establish sufficient similarity between the copyrighted work and the alleged infringing work, necessitating:
Objective similarity is determined by volume, quality, intent, and market competition.
Difficulties in Proving Infringement
Challenges in demonstrating copyright infringement are displayed in News Datacom v David Lyons (1994), which highlighted that convergence could arise without necessitating copying.
Remedies for Infringement
Civil remedies include damages, profit accounts, and injunctions. The 2000 Act establishes that innocent infringement lacks entitlement for damages.
Moral Rights in Copyright
Recognized for the first time in Irish law under the 2000 Act, moral rights include:
Paternity Right: Right to be identified as the work's creator.
Integrity Right: The ability to object to derogatory treatment of the work.
Privacy Right: The right to privacy concerning commissioned works for domestic purposes.