cookie conundrum? article 5(3) of the eu eprivacy directive

Post on 09-May-2015

1.678 Views

Category:

News & Politics

1 Downloads

Preview:

Click to see full reader

DESCRIPTION

Slideshow for presentations at the Cookie Compliance Conference, 6 December 2011, London and the Roundtable Medienpolitik, 7 December 2011, Brussels

TRANSCRIPT

Cookie Compliance Conference, 6 December 2011, London

and

Roundtable Medienpolitik, 7 December 2011, Brussels

Cookie Conundrum?

Article 5(3) of the EU ePrivacy Directive

Carl-Christian Buhr

European Commission

(All expressed views are those of the speaker.)http://slidesha.re/cookieeu

http://bit.ly/cc_buhr, @ccbuhr

http://bit.ly/NeelieKroesEU,@NeelieKroesEU

http://ec.europa.eu/digital-agenda

DAE

101 Actions

http://bit.ly/NeelieKroesEU,@NeelieKroesEU

http://ec.europa.eu/digital-agenda

101 Actions

Advising on...

ePrivacy/Data ProtectionCloud ComputingICT StandardisationResearch Policyetc.

http://bit.ly/cc_buhr,@ccbuhr

The ePrivacy Directive

“Directive (2002/58/EC) on privacy and electronic communications as amended by Directive 2009/136/EC ("Citizens' Rights Directive")” [Link]

⟹ Adopted by EU Parliament, Council 2009

⟹ Transposition deadline for Member States 25 May 2011, delays in several Member States

Article 5(3)From right to refuse to consent

“Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.”

Article 5(3) basics

⟹ Not limited to cookies

⟹ Not limited to specific uses

⟹ Not limited to telcos

⟹ Obliging providers

⟹ Technologically neutral

The Status Quo is not enough

Online privacy – reinforcing trust and confidence, Brussels, 22/06/2011,http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461

“This revision of the ePrivacy Directive has brought a material strengthening of protection for citizens and Member States need to make sure this is reflected in national law.”

Article 5(3) in Member States Commission guidance paper

⟹ Commission services working document of

20/10/2010

⟹ Presented to Communications Committee of

Member State representatives

⟹ Aim: Help prevent fragmentation

Tracking is the issue

Online privacy – reinforcing trust and confidence, Brussels, 22/06/2011,http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461

“[O]nce user profiles exist they can potentially be used for all kinds of things.

“[D]ifference between a commitment not to record tracks and a commitment not to use them for a specific purpose once recorded”

EASA/IAB OBA Self-Regulationhttp://www.easa-alliance.org/page.aspx/386

“What I like about this solution is that it is active. Industry is not just saying – as some unfortunately still do – that all is fine because users can disable cookies in their web browsers.” [link]

⟹ Assuring compliance on its own: doubts

⟹ Scope: limited to certain methods, uses

Need broader discussion “Do not track” (DNT)

Online privacy – reinforcing trust and confidence, Brussels, 22/06/2011,http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461

DNT can apply to all devices, types and purposes of tracking

“We need a standard!”

Deadline: June 2012

W3C has started work

DNT Scenario after June 2012

Online privacy – reinforcing trust and confidence, Brussels, 22/06/2011,http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461

1. Simple Message: If you do DNT you are fine!2. Virtuous Circle of adoption by users and providers3. Enabled by tool makers' innovation on sufficiently rich standard

Browser settings etc.

1. ePrivacy obliges provider, not browser

2. DNT lets provider know user preference!

⟹ Good chance for future browser settings

to become sufficient

⟹ Issue: How to deal with unset DNT (trigger user prompt? rely on earlier browser prompt? etc.)

Pointers

ePrivacy Directive 2009http://ec.europa.eu/information_society/policy/ecomm/doc/24eprivacy.pdf

http://ec.europa.eu/information_society/policy/ecomm/eu-rules/index_en.htm

COCOM Guidance Paperhttp://bit.ly/cocom_guidance

OR http://circa.europa.eu/Public/irc/infso/cocom1/library?l=/public_documents_2010/

cocom10-34_guidance/_EN_1.0_&a=d

W3C DNT Standardisationhttp://www.w3.org/2011/tracking-protection

Neelie Kroes speeches04/10/2011 http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/62922/06/2011 http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/46117/09/2010: http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/10/452

Contacts<web>http://bit.ly/{NeelieKroesEU, cc_buhr}</web>

<twitter>@NeelieKroesEU, @ccbuhr</twitter><facebook>http://on.fb.me/Neelie_Kroes</facebook>

top related