Skip to content
E-commerce

Cookie Policy and Cookie Bar, how to adapt your site

Team Host.it 8 min read

Content

January 10, 2022 is the deadline to adapt your website for correct management of cookie consent to the new Guidelines of the Privacy Guarantor. Millions of websites will no longer be compliant and will be at risk of sanctions. The management of visitor data has always been an important source of income for websites, whether blogs or e-commerce. Tracking and analyzing visit data allows you to profile visitors to prepare better marketing campaigns and activate specific re-marketing strategies. The collection and management of this data occurs through so-called cookies, small text files stored on users' devices and allows the user's experience on different websites to be personalized, saving browsing preferences, language, behavior on the site and other information useful for profiling.

This activity of installing cookies is not free, but is regulated by precise regulations such as the Cookie Law and the most recent Guidelines issued by the Privacy Guarantor, which require the publication of an information on the use of Cookies and the display of a tool that allows the user to express their acceptance or refusal of the installation of cookies on their device. The Cookie Policy is not just information that is published on the website but must accurately reflect which cookies are installed on users' devices, which data is collected and used and above all how users are given the opportunity to choose whether or not to provide this information, putting them in a safe position and leaving full rights over the management of the profiling of their browsing experience completely in their hands.

It is therefore necessary to provide each website with a specific cookie policy formulated in accordance with the law and a cookie bar (consent management system) created as per the directives and always updated, both for regulatory adjustments and for changes made to the website.

What changes from January 10, 2022.

What is a cookie policy for a website?

How to create a cookie policy

How to adapt your site in just 3 steps

Cookie Law: what is it? The term "Cookie Law" refers to the "ePrivacy Directive", which is Directive 2009/136/EC of the European Parliament and of the Council regarding the management of cookies and user tracking technologies.

The Cookie Law is a regulation that applies to all websites that can be visited by European users, regardless of the headquarters of the company that operates the website.

The Cookie Law requires each website to inform EU citizens about data collection activities and give them the opportunity to choose whether or not to consent to such data collection activities. This implies that, if a site or any third-party service integrated on the site uses cookies, it is necessary to obtain consent from the user before a cookie can be installed on the user's device.

The collection of consent to cookies is generally carried out through the use of a cookie banner or a cookie bar, essentially a pop-up or a bar positioned on the site which informs the user about the presence of cookies and provides the user with the possibility of accepting or not the installation of cookies.

The Cookie Law therefore requires website owners to:

Perform preventive blocking of cookies. In fact, cookies can only be installed after obtaining the user's consent.

Publish a Cookie Policy, an information that describes in detail the purposes of installing cookies, indicate the third parties that install cookies, indicate to the user how to provide and revoke their consent.

Publish a Cookie Bar, i.e. a tool that allows the user to indicate their preferences regarding the installation or not of cookies.

There are some cookies that are exempt from the request for consent, these cookies are:

technical cookies strictly necessary for the use of the service (e.g. language preference, session cookies, security, etc.)

statistical cookies managed by the same subject (not third parties) if not used to profile the user.

third-party but anonymized statistical cookies.

What changes from January 10, 2022? January 10, 2022 is the deadline to adapt your "cookie management" to the latest Guidelines of the Italian Privacy Guarantor regarding cookies and tracking tools.

Compared to the original Cookie Law, some aspects have been clarified and some indications have been provided on how to manage the collection of consent.

You must provide "Accept" and "Reject" buttons in the Cookie Bar

Users must be able to provide consent in a granular way, accepting/rejecting specific categories and third-party cookies to be installed.

Users must be able to update their cookie preferences whenever they want.

The user's preferences regarding cookies must be maintained for at least 6 months, it is no longer possible to ask for consent at each visit.

Cookie walls are not valid for collecting consent.

Collecting consent by scrolling the page is not acceptable. The user must provide a clear choice through the appropriate buttons and features of the cookie bar.

For each consent collected it is necessary to be able to provide proof of consent as required by the GDPR standards which certifies the user's preferences and the time at which it was collected.

First-party statistical cookies (analytics) do not require consent and do not require prior blocking. For third-party statistical cookies, exemption from consent and preventive blocking is only possible under certain conditions.

Legitimate interest no longer constitutes a valid legal basis for the use of cookies.

What is a Cookie Policy for a website? The Cookie Policy, in Italian Information on the use of Cookies and other tracking technologies, is a legal document that includes the most complete information on how the site owners collect, store, process and share the user's browsing data through the use of cookies.

The cookie information must include a list of all the cookies installed by the website and for each of them specify the purposes of installation of the cookie, its category (e.g. statistical, profiling, marketing, technical, etc.) and the duration of the cookie itself.

In the case of cookies installed by a third party (e.g. a chat service, a statistical data collection service, etc.) it is necessary, in addition to providing information on the third parties involved, on the duration and purpose of the processing, to indicate the links to the respective privacy policies, cookies and consent forms.

The Cookie Policy must always be easily accessible by the user, either through a link from the cookie bar or through specific menu items within the site. Furthermore, it is necessary to indicate the date of last update of this document.

The information on Cookies is also necessary when the site installs exclusively first-party technical cookies that do not perform tracking, to inform the user about the presence of such cookies.

Website Cookie Policy: how to create it? Drafting a cookie information text that complies with the law can be a difficult task, if you do not have the right skills or the support of a legal professional expert in the matter. It is not enough to create a text that develops the key points and, even more importantly, we cannot copy one already made from another website. Each site is different and therefore each site needs its own Cookie Policy. The information required by law is detailed and meticulous and is required to be disclosed in a comprehensive manner and with appropriate legal terms.

So how to proceed? There are several ways, let's see the most common one:

Do it yourself You can "venture" into creating your own cookie policy, this takes time and the risk of making mistakes or forgetting something is very high.

To do this, it is still necessary to perform a complete analysis of the website to identify all the cookies installed by your site,

For each cookie we must identify the purposes, duration, any third party involved and map them to the appropriate category and indicate everything in our cookie policy document.

We must then install a plugin / script on the website that blocks all cookies and offers the user the possibility to accept cookies or not and, subsequently, unblocks the accepted cookies.

We will then have to have what we have done approved by a legal professional, in order to avoid making mistakes that can cost us thousands of euros in fines. Are we really convinced that we should do this? No, the sanction is around the corner.

If, however, we want to sleep soundly and have a complete cookie management solution, with cookie information, a cookie bar installed and compliant with regulations, we can rely on services such as those provided by Host.it

Website Cookie Management: the Compliance service by Host.it Host.it has activated a service that allows all website owners to activate a simple and convenient subscription, with which you are guaranteed to have:

Cookie Preferences Register

and installed on the website, with zero effort on the part of the site owner.

All in three simple steps: you sign up for a subscription

the site access data is sent in a secure form to the Host legal team

within a few days the site is compliant, but above all it will remain there forever, because the service provides continuous updates even when the law changes

E-commerce

Hosting for online stores

PrestaShop, WooCommerce and Magento: performance, security and datacenters in Italy.

From the blog

E-commerce

Un’acquisizione strategica

Bhoost e Magentiamo in Host.it

From the archive

E-commerce

0-day vulnerability in PrestaShop

E-commerce

Prestashop: how to improve performance and indexing of an e-commerce