• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • Good Books
  • Tools
  • Blog
  • Darren
  • Contact
  • Hire Me
Small Biz Geek

Small Biz Geek

Small Business Design, Marketing & Technology Journal

Solving small business design, marketing & tech problems

  • The Internet
  • Marketing
  • Graphic Design
  • Web Dev
  • Web Design
  • Social Media
  • Privacy & Security
  • Tech
  • Misc

Cookies, Privacy and Permission: Is Your Website Legal? 👨‍⚖️

Published: February 25, 2014; Updated: September 8, 2023 Filed Under: Internet, Legal, Video, Web Development

EU Cookies Privacy All websites operating in the UK and Europe need to ensure they are complying with EU data protection legislation. The revision of the laws has been cited as the “biggest shake up in marketing for decades” and ushers in a new age of consumer privacy and a greater burden of proof on businesses. If misuse of someone’s data causes “distress” or “damage” you or your company could be fined between £1000 and £500,000. The problem is, the exact laws still are not clear and is the subject of fierce debate. ico May 2014 was set as a provisional deadline when a data protection law for the single European market would be proposed and voted on. In the meantime small business owners were being urged to at least begin implementing changes in the way they and their website gathers data. The overall theme to the data protection discussion is that certain changes DO need to be in place right now, yet a lot of small businesses either don’t know about it or are just not bothering to implement systems to cope.

  • The British Information Commissioner’s Office provides guidance on data protection.

It is also a good idea to be flexible in meeting demands of future changes, revisions or amendments to the regulations.Data Protection First, let’s look at the basic stuff where website privacy policies and cookie consent is concerned.

Privacy Policy

A website privacy policy is the small print of a site in which full disclosure about how data is collected and what exactly you use it for. Before we go any further, ask yourself this: are you even collecting data? Well, if you host adverts or have statistical visitor tracking software installed (like Google Analytics) then yes, you are collecting user data and need to make that clear as part of your privacy policy. If you have a website but do not administrate it, speak to the person who does and see what measures they are taking to make the site EU friendly. Template privacy policies can be downloaded and modified as appropriate then uploaded to your site. A link to your privacy policy (and any other disclaimers) needs to be placed at the bottom of every page of your site.

How Search Engines Regard Due Diligence Statements

Interestingly, there is speculation that taking steps to add disclaimers about due diligence, obligations and responsibilities to a site can win the favour of the Google search engine. Part of their ranking algorithm is supposedly programmed to scan for and detect legal related web content and reward those sites. This is conjecture but the idea seems plausible because Google wants to rank serious, legitimate websites and adding the legal boilerplate to a site is likely to please them. Whenever I see a website neglecting to include disclaimers, privacy statements and cookie information, I think they’re missing a trick.

Cookie Consent

Cookies are small files downloaded to a user’s computer designed to track activity on a website. These files are totally legitimate and serve only to improve a website user’s experience by storing and remembering preferences. For example: whether or not a website log in form remembers a username and password. This is common browser functionality and a standard feature of all browsers.

  • Cookie information is NOT transmitted to a website operator or web host.
  • Cookie files can be easily disabled or deleted by clearing the browser cache.

Cookies are also used by advertising networks and analytics tracking software to either deliver adverts the users is likely to want to see, or to record and report data on how a user navigated a website, how long they spent on a page, what kind of device they use to browse the site etc. No names, addresses or personal data is collected.

Cookie Opt-Out button

The ICO have requirements in place where a company, organisation or webmaster must disclose what cookies are used and give the website visitor the opportunity to opt out.

  • In the European Union tt is OK to assume cookie consent is already given but with the choice to turn off the cookies
  • A prominent link/button with instructions on removing/blocking cookies needs to be clearly displayed.

You don’t need to block cookies and then ask to allow them – you only need to provide a way to disallow cookies.

Cookie Consent Button

This is the button I have been using for websites using cookies

It is recommended that an unobtrusive pop up either at the top or bottom of the website is used to provide the necessary information and means to take steps for changing cookie settings.

Official ICO FAQ Video

This video answers some questions. It was published back in 2012 as a general forecast on privacy, data protection etc. I recommend subscribing to their channel as well.

 

Watch video on YouTube

Avoid a fine

Under The Privacy and Electronic Communications Regulations the ICO has published guidelines concerning all aspects of data protection and privacy.

  • This info is relevant as of February 2014 (revisions to their documents may occur so do not act on info in this blog without first doing your own research).

Read the ICO guidance document on monetary penalties. In the opening pages of the PDF it is said that a maximum fine of £500,000 can be imposed on a “data controller” who seriously contravenes regulations either deliberately or by failing to take action in circumstances where a privacy breach causes substantial “distress” or “damage” to another party. The document goes on to explain that the financial penalties imposed are in fact contingent on the financial resources of an individual or entity:

“The Commissioner will take into account the sector, for example, whether the person is a voluntary organisation and also the size, financial and other resources of a person before determining the amount of a monetary penalty. The purpose of a monetary penalty notice is not to impose undue financial hardship on an otherwise responsible person.”

The anecdotal example they use mentions a small business being fined £1000:

“As a general rule a person with substantial financial resources is more likely to attract a higher monetary penalty than a person with limited resources for a similar contravention of the Act or the 2003 Regulations. For example, a monetary penalty notice was served on a sole proprietor for the sum of £1,000 following representations about his financial status. When further precedents are available from either the monetary penalty notices served by the Commissioner or the decisions of the First-tier Tribunal (Information Rights), further guidance will be produced so that those affected can better assess their position.”

Examples of Privacy Breach

Data ProtectionThough this does not apply to honest marketers and businesses, there’s always the possibility of a scenario where user data is abused or falls into the wrong hands. Either of the following two outcomes is an example of “systematic failings” where responsibility falls to the data operator. That’s you.

  1. A burglary resulting in the theft of laptops or media storage devices. Inadequate password protection could lead the perpetrators going on to commit identity theft. Names, addresses and phone numbers might be used for criminal activity and this would be a serious breach of data protection. The burden of responsibility is upon the organisation or individual who failed to prevent the breach.
  2. A customer sends an email enquiry through a website contact form, providing name, email address and phone number. If that data is added to an email marketing list without consent, or if unsolicited phone calls were placed or text messages sent to the individual, that would constitute a breach of privacy.

It is prudent to familiarise yourself with the ICO’s guidelines, as well as putting “end of May 2014” in your calendar, because by then we should have clear legislation regarding data protection. If you’re in the UK, keep an eye on BBC Parliament on the iPlayer, and maybe Newsnight too. Watch the following video taken from my local web design YouTube channel. I’ll show you what you need to look at as a website owner. Please bear in mind, Google have now released their own javascript cookie notification bar for websites called cookie choices.

Update 2015: I have it on good authority that the notification bar might not be necessary any more, as long as you have a visible link at the bottom of every page on your site linking to information about the cookies you use.  You can still watch the video, but please be aware I am no longer using the SiteBeam Cookie Consent scripts because I found it seriously slowed down my websites I was using it on.

Watch video on YouTube

Useful links

ICO: Privacy and Electronic Communications Regulations ICO: Data Protection Guidelines Overview ICO: Cookies Guidance (PDF) ICO: Privacy Notices Code of Practice (PDF) ICO: Collecting Information About Your Customers – Small Biz Checklist (PDF) ICO: Monetary Penalties Statutory Guidance (PDF)

You Might Also Be Interested In...

  • Google Plus Brand Page Backlink Tips
  • Nuisance Calls, Emails and Empty Promises: The Bungling Incompetence of Yell.com 🙉
  • Badly Behaved Images? Leverage the Power of Vector Graphics to Eliminate Unruly Design ⚡

Filed Under: Internet, Legal, Video, Web Development Tagged With: Cookies, Data, EU, Marketing, Privacy, Websites

About Small Biz Geek

I'm Darren, helping small businesses with design, marketing & tech.

Small Business Website Design

Do you need help with something web related?

Hire Me

Reader Interactions

Subscribe to Blog Feed by Email

Your email address won't be shared. You'll never be spammed. Check your inbox to confirm opt-in.

Add Your Thoughts Cancel reply

Your email address is safe and will NOT be shared with anyone else.

Hateful, spammy or abusive comments will not be tolerated.

For more information please see the comment policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Search Website

Latest Blogs

  • Is Generative Engine Optimisation (GEO) the Answer to the Future of Search? 🎨
  • How Hiding Your Phone Number and Using a Booking System Repels Time Wasters and Helps “Positioning” 🗓️
  • “Fucking Good Content” – Dan Kelsall (Book Review) 📘
  • Scam Poetry: The Time I Was Recruited to the Cult of Amway ⚠️
  • A Story of Seductive Social Media Success and Neglected Email Strategy 🏚️
  • The Classic Social Media Trend Destined to Ruin Your Business 😭
  • Looking for Online Work? Don’t Fall for this Fake Hays Recruitment WhatsApp Scam ⚠️
  • Cream of the Crap: How Fake Reviews, Bad Businesses and Dangerous Products Rise to the Top 💣
  • Exposed: The Hong Kong Investment “Fraud Recovery” Scammer Deceiving Victims 🤑
  • Computer Says No: Does Your Website Work for People with Disabilities? ♿
  • Chinese Tinder Profiles Are Using Photos of Pretty Girls to Scam “Investors” 💋
  • Small Biz Owners “Trapped” Using Email Addresses Belonging to Internet Service Providers 🪤
  • In the Pandemic, QR Codes are Finally Proving Worthy in the West 😷
  • Small Businesses Finally Start Marketing… and All It Took Was a Global Pandemic 🏁

Footer

Primary Navigation

Home
About Darren
Good Books
My Tools
Blog Posts
Hire Me
Contact Me

Derby & Nottingham Area

The Internet
Marketing
Graphic Design
Website Development
Website Design
Social Media
Technology
Miscellaneous
Privacy & Security

Let’s Connect

Twitter
YouTube
LinkedIn
RSS

Small Business Blog · Privacy Policy · Commenting Policy · Website Disclaimer · ICO number: ZA305900


Written and designed by Ilkeston Web Design

  • Home
  • Good Books
  • Tools
  • Blog
  • Darren
  • Contact
  • Hire Me