|
|
|
|
|
by cdrx
1930 days ago
|
|
To be legal you need to get the user's consent, upfront, for that tracking. Technical challenges are not a defence. GDPR is not the only regulation at play here. The PECR also applies. You need consent for the session cookie in the public areas of your site. It doesn't become essential until the user logs in, registers, adds an item to the cart, etc. |
|
And considering the ICO, the UK org that enforces these laws and where you have to go to find out the UK laws on it, literally just tell you that they use cookies to make their website work and don't ask for consent makes me think this is so much more complicate than any of us truly understand.
If they're setting cookies without consent with a user tracking id, I am going to guess that my session cookie falls under the same thing theirs does.
https://ico.org.uk/for-organisations/guide-to-pecr/what-are-...'. - Check developer tools and cookies.