SlideShare a Scribd company logo
1 of 14
Cookie Compliance Conference, 6 December 2011, London and Roundtable Medienpolitik, 7 December 2011, Brussels Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive Carl-Christian Buhr European Commission (All expressed views are those of the speaker.) http://slidesha.re/cookieeu http://bit.ly/cc_buhr ,  @ccbuhr
http://bit.ly/NeelieKroesEU , @NeelieKroesEU http://ec.europa.eu/digital-agenda DAE 101 Actions
http://bit.ly/NeelieKroesEU , @NeelieKroesEU http://ec.europa.eu/digital-agenda 101 Actions Advising on... ePrivacy/Data Protection Cloud Computing ICT Standardisation Research Policy etc. http://bit.ly/cc_buhr , @ccbuhr
The ePrivacy Directive “ Directive (2002/58/EC) on privacy and electronic communications as amended by Directive 2009/136/EC ("Citizens' Rights Directive")”   [ Link ]   ⟹  Adopted by EU Parliament, Council 2009 ⟹  Transposition deadline for Member  States 25 May 2011, delays in several  Member States
Article 5(3) From  right to refuse  to consent “ Member States shall ensure that the  storing of information , or the gaining of  access to information already stored , in the  terminal equipment  of a subscriber or user is  only allowed on condition  that the subscriber or user concerned  has given his or her consent ,  having been provided with clear and comprehensive information , in accordance with Directive 95/46/EC, inter alia about the purposes of the processing. This shall not prevent any technical storage or access for the  sole purpose  of  carrying out the transmission  of a communication over an electronic communications network, or as  strictly necessary  in order for the provider of an information society service explicitly requested by the subscriber or user  to provide the service .”
Article 5(3) basics ⟹  Not limited to cookies ⟹  Not limited to specific uses ⟹  Not limited to telcos ⟹  Obliging providers ⟹  Technologically neutral
The Status Quo is not enough Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 “ This revision of the ePrivacy Directive has brought a  material strengthening  of protection for  citizens and Member  States need to make  sure this is reflected  in national law.”
Article 5(3) in Member States Commission guidance paper ⟹  Commission services  working document  of  20/10/2010 ⟹  Presented to  Communications Committee   of  Member State representatives  ⟹  Aim: Help prevent fragmentation
Tracking is the issue  Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 “ [O]nce user profiles exist they can potentially be used  for all kinds of things . “ [D]ifference between a commitment  not to record tracks  and a commitment  not to use  them for a specific purpose once recorded”
EASA/IAB OBA Self-Regulation http://www.easa-alliance.org/page.aspx/386 “ What I like about this solution is that it is  active . Industry is  not just saying  – as some unfortunately still do – that all is fine because users can disable cookies in their web browsers.” [ link ] ⟹  Assuring compliance on its own:  doubts ⟹  Scope:  limited  to certain methods, uses
Need broader discussion  “Do not track” (DNT) Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 DNT can apply to all devices, types and purposes of tracking “ We need a standard!”  Deadline: June 2012 W3C has started work
DNT Scenario after June 2012 Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 1.  Simple Message : If you do DNT you are fine! 2.   Virtuous Circle  of adoption by users and providers 3.  Enabled  by tool  makers' innovation on sufficiently rich  standard
Browser settings etc. 1. ePrivacy obliges provider,  not  browser  2. DNT lets provider  know  user preference! ⟹  Good chance  for future browser settings  to become sufficient ⟹  Issue: How to deal with unset DNT  (trigger user prompt? rely on  earlier browser prompt? etc.)
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

More Related Content

What's hot

Tunisia Internet Governance
Tunisia Internet GovernanceTunisia Internet Governance
Tunisia Internet Governance
rafikd
 
Challenges and solutions for improved durability of materials - Opin summary ...
Challenges and solutions for improved durability of materials - Opin summary ...Challenges and solutions for improved durability of materials - Opin summary ...
Challenges and solutions for improved durability of materials - Opin summary ...
Sirris
 
Openness a principle in need for a code of conduct
Openness a principle in need for a code of conductOpenness a principle in need for a code of conduct
Openness a principle in need for a code of conduct
Leo Plugge
 

What's hot (20)

Peter Strickx: fedict: E-Government & Open Standards, 26.01.2011, Brussels, B...
Peter Strickx: fedict: E-Government & Open Standards, 26.01.2011, Brussels, B...Peter Strickx: fedict: E-Government & Open Standards, 26.01.2011, Brussels, B...
Peter Strickx: fedict: E-Government & Open Standards, 26.01.2011, Brussels, B...
 
"NTW- working for Transparency and Public Participation in RDW" by Philip kea...
"NTW- working for Transparency and Public Participation in RDW" by Philip kea..."NTW- working for Transparency and Public Participation in RDW" by Philip kea...
"NTW- working for Transparency and Public Participation in RDW" by Philip kea...
 
How much do you know about the European Strategy on Big Data?
How much do you know about the European Strategy on Big Data?How much do you know about the European Strategy on Big Data?
How much do you know about the European Strategy on Big Data?
 
EUDAT 3rd Conference: Bringing Data e-Infrastructures to Horizon2020 - Carl-C...
EUDAT 3rd Conference: Bringing Data e-Infrastructures to Horizon2020 - Carl-C...EUDAT 3rd Conference: Bringing Data e-Infrastructures to Horizon2020 - Carl-C...
EUDAT 3rd Conference: Bringing Data e-Infrastructures to Horizon2020 - Carl-C...
 
Transmission Unbundling
Transmission Unbundling Transmission Unbundling
Transmission Unbundling
 
Tunisia Internet Governance
Tunisia Internet GovernanceTunisia Internet Governance
Tunisia Internet Governance
 
Challenges and solutions for improved durability of materials - Opin summary ...
Challenges and solutions for improved durability of materials - Opin summary ...Challenges and solutions for improved durability of materials - Opin summary ...
Challenges and solutions for improved durability of materials - Opin summary ...
 
OPERANDO @ NetFutures 2016
OPERANDO @ NetFutures 2016OPERANDO @ NetFutures 2016
OPERANDO @ NetFutures 2016
 
Stephen Evoice
Stephen EvoiceStephen Evoice
Stephen Evoice
 
Session 2.1 Martin Mühleck
Session 2.1 Martin MühleckSession 2.1 Martin Mühleck
Session 2.1 Martin Mühleck
 
Wsdan Graham Worsley
Wsdan Graham WorsleyWsdan Graham Worsley
Wsdan Graham Worsley
 
Openness a principle in need for a code of conduct
Openness a principle in need for a code of conductOpenness a principle in need for a code of conduct
Openness a principle in need for a code of conduct
 
What Future for Nanoelectronics in the EU?
What Future for Nanoelectronics in the EU?What Future for Nanoelectronics in the EU?
What Future for Nanoelectronics in the EU?
 
Tdm dechamp colin_open_minted
Tdm dechamp colin_open_mintedTdm dechamp colin_open_minted
Tdm dechamp colin_open_minted
 
Public Funds in the UK - Alfresco Presentation
Public Funds in the UK - Alfresco PresentationPublic Funds in the UK - Alfresco Presentation
Public Funds in the UK - Alfresco Presentation
 
Accessibility and Open Data
Accessibility and Open DataAccessibility and Open Data
Accessibility and Open Data
 
The European Cloud Computing Strategy
The European Cloud Computing StrategyThe European Cloud Computing Strategy
The European Cloud Computing Strategy
 
Europetition project April 2010
Europetition project April 2010Europetition project April 2010
Europetition project April 2010
 
Aarhus in scotland
Aarhus in scotlandAarhus in scotland
Aarhus in scotland
 
COVID-19 and Copyright: Challenges for Higher Education, CITE Forum November ...
COVID-19 and Copyright: Challenges for Higher Education, CITE Forum November ...COVID-19 and Copyright: Challenges for Higher Education, CITE Forum November ...
COVID-19 and Copyright: Challenges for Higher Education, CITE Forum November ...
 

Similar to Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive

The E-Privacy Directive and Performance Marketing
The E-Privacy Directive and Performance MarketingThe E-Privacy Directive and Performance Marketing
The E-Privacy Directive and Performance Marketing
Andrew Tibber
 
E-privacy Directive and Performance Marketing - Andrew Tibber
E-privacy Directive and Performance Marketing - Andrew TibberE-privacy Directive and Performance Marketing - Andrew Tibber
E-privacy Directive and Performance Marketing - Andrew Tibber
auexpo Conference
 
Cookies guidance v3
Cookies guidance v3Cookies guidance v3
Cookies guidance v3
Andy Ryu
 
Open innovation towards_smarter_cities_o
Open innovation towards_smarter_cities_oOpen innovation towards_smarter_cities_o
Open innovation towards_smarter_cities_o
ssusereb85c4
 

Similar to Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive (20)

The E-Privacy Directive and Performance Marketing
The E-Privacy Directive and Performance MarketingThe E-Privacy Directive and Performance Marketing
The E-Privacy Directive and Performance Marketing
 
E-privacy Directive and Performance Marketing - Andrew Tibber
E-privacy Directive and Performance Marketing - Andrew TibberE-privacy Directive and Performance Marketing - Andrew Tibber
E-privacy Directive and Performance Marketing - Andrew Tibber
 
Cookies guidance v3
Cookies guidance v3Cookies guidance v3
Cookies guidance v3
 
Ev 20130514 mi_en
Ev 20130514 mi_enEv 20130514 mi_en
Ev 20130514 mi_en
 
20190626 eu blockchain_how europe supports blockcahcin (cv conference) (1)
20190626 eu blockchain_how europe supports blockcahcin (cv conference) (1)20190626 eu blockchain_how europe supports blockcahcin (cv conference) (1)
20190626 eu blockchain_how europe supports blockcahcin (cv conference) (1)
 
The European Cloud Computing Strategy: Key Actions
The European Cloud Computing Strategy: Key ActionsThe European Cloud Computing Strategy: Key Actions
The European Cloud Computing Strategy: Key Actions
 
My Privacy at Risk, is it Safe?
My Privacy at Risk, is it Safe?My Privacy at Risk, is it Safe?
My Privacy at Risk, is it Safe?
 
Congress 2012: The European Cloud Computing Strategy: Key Actions – Carl‐Chri...
Congress 2012: The European Cloud Computing Strategy: Key Actions – Carl‐Chri...Congress 2012: The European Cloud Computing Strategy: Key Actions – Carl‐Chri...
Congress 2012: The European Cloud Computing Strategy: Key Actions – Carl‐Chri...
 
The European Electronics Strategy
The European Electronics StrategyThe European Electronics Strategy
The European Electronics Strategy
 
Data Privacy of the Internet of Things
Data Privacy of the Internet of ThingsData Privacy of the Internet of Things
Data Privacy of the Internet of Things
 
Presentation Morten Helveg Fdim
Presentation Morten Helveg FdimPresentation Morten Helveg Fdim
Presentation Morten Helveg Fdim
 
Open Access to Research Publications and Data
Open Access to Research Publications and DataOpen Access to Research Publications and Data
Open Access to Research Publications and Data
 
Open innovation towards_smarter_cities_o
Open innovation towards_smarter_cities_oOpen innovation towards_smarter_cities_o
Open innovation towards_smarter_cities_o
 
European Commission: Open Data Policies & Activities
European Commission: Open Data Policies & ActivitiesEuropean Commission: Open Data Policies & Activities
European Commission: Open Data Policies & Activities
 
EU data protection issues in IoT
EU data protection issues in IoTEU data protection issues in IoT
EU data protection issues in IoT
 
The European Commission and Open Access
The European Commission and Open AccessThe European Commission and Open Access
The European Commission and Open Access
 
Eprivacy issues and standards -- where do we stand?
Eprivacy issues and standards -- where do we stand?Eprivacy issues and standards -- where do we stand?
Eprivacy issues and standards -- where do we stand?
 
Presentation for CPDP 2015
Presentation for CPDP 2015Presentation for CPDP 2015
Presentation for CPDP 2015
 
EU Digital Agenda and Open Data
EU Digital Agenda and Open DataEU Digital Agenda and Open Data
EU Digital Agenda and Open Data
 
Open Science in the Digital Agenda
Open Science in the Digital AgendaOpen Science in the Digital Agenda
Open Science in the Digital Agenda
 

More from Carl-Christian Buhr

More from Carl-Christian Buhr (20)

Open Digital Science & e-infrastructures
Open Digital Science & e-infrastructuresOpen Digital Science & e-infrastructures
Open Digital Science & e-infrastructures
 
Infrastructures for Open, Digital Science
Infrastructures for Open, Digital ScienceInfrastructures for Open, Digital Science
Infrastructures for Open, Digital Science
 
Digitale EU-Politik nach 2014
Digitale EU-Politik nach 2014Digitale EU-Politik nach 2014
Digitale EU-Politik nach 2014
 
Open, Digital Science in Europe
Open, Digital Science in EuropeOpen, Digital Science in Europe
Open, Digital Science in Europe
 
Horizon 2020 and Research Data Infrastructures
Horizon 2020 and Research Data InfrastructuresHorizon 2020 and Research Data Infrastructures
Horizon 2020 and Research Data Infrastructures
 
Making EU Open Access Policies Work
Making EU Open Access Policies WorkMaking EU Open Access Policies Work
Making EU Open Access Policies Work
 
On Opening Up Government Data
On Opening Up Government DataOn Opening Up Government Data
On Opening Up Government Data
 
Cross-cutting Informatics in Horizon 2020
Cross-cutting Informatics in Horizon 2020Cross-cutting Informatics in Horizon 2020
Cross-cutting Informatics in Horizon 2020
 
Die Europäische Cloud-Computing-Strategie
Die Europäische Cloud-Computing-StrategieDie Europäische Cloud-Computing-Strategie
Die Europäische Cloud-Computing-Strategie
 
Die Open-Access-Politik der EU
Die Open-Access-Politik der EUDie Open-Access-Politik der EU
Die Open-Access-Politik der EU
 
Open-Data-Politik der EU-Kommission
Open-Data-Politik der EU-KommissionOpen-Data-Politik der EU-Kommission
Open-Data-Politik der EU-Kommission
 
Why Open Data?
Why Open Data?Why Open Data?
Why Open Data?
 
Open Access in Europe. On the Road to 2020
Open Access in Europe. On the Road to 2020Open Access in Europe. On the Road to 2020
Open Access in Europe. On the Road to 2020
 
Update on the Digital Agenda for Europe
Update on the Digital Agenda for EuropeUpdate on the Digital Agenda for Europe
Update on the Digital Agenda for Europe
 
The Digitial Agenda for Europe: Where do we stand?
The Digitial Agenda for Europe: Where do we stand?The Digitial Agenda for Europe: Where do we stand?
The Digitial Agenda for Europe: Where do we stand?
 
Europa und die digitale Welt - E-Privacy, Datenschutz & Co.
Europa und die digitale Welt - E-Privacy, Datenschutz & Co.Europa und die digitale Welt - E-Privacy, Datenschutz & Co.
Europa und die digitale Welt - E-Privacy, Datenschutz & Co.
 
Open Science at the European Commission
Open Science at the European CommissionOpen Science at the European Commission
Open Science at the European Commission
 
Öffentliche Information als Wirtschaftsgut
Öffentliche Information als WirtschaftsgutÖffentliche Information als Wirtschaftsgut
Öffentliche Information als Wirtschaftsgut
 
European Policies for High Performance Computing
European Policies for High Performance ComputingEuropean Policies for High Performance Computing
European Policies for High Performance Computing
 
Offene Daten in Europa. Die Vorschläge der EU-Kommission
Offene Daten in Europa. Die Vorschläge der EU-KommissionOffene Daten in Europa. Die Vorschläge der EU-Kommission
Offene Daten in Europa. Die Vorschläge der EU-Kommission
 

Recently uploaded

Recently uploaded (8)

12052024_First India Newspaper Jaipur.pdf
12052024_First India Newspaper Jaipur.pdf12052024_First India Newspaper Jaipur.pdf
12052024_First India Newspaper Jaipur.pdf
 
10052024_First India Newspaper Jaipur.pdf
10052024_First India Newspaper Jaipur.pdf10052024_First India Newspaper Jaipur.pdf
10052024_First India Newspaper Jaipur.pdf
 
Income Tax Regime Dilemma – New VS. Old pdf
Income Tax Regime Dilemma – New VS. Old pdfIncome Tax Regime Dilemma – New VS. Old pdf
Income Tax Regime Dilemma – New VS. Old pdf
 
Textile Waste In India/managing-textile-waste-in-India
Textile Waste In India/managing-textile-waste-in-IndiaTextile Waste In India/managing-textile-waste-in-India
Textile Waste In India/managing-textile-waste-in-India
 
declarationleaders_sd_re_greens_theleft_5.pdf
declarationleaders_sd_re_greens_theleft_5.pdfdeclarationleaders_sd_re_greens_theleft_5.pdf
declarationleaders_sd_re_greens_theleft_5.pdf
 
11052024_First India Newspaper Jaipur.pdf
11052024_First India Newspaper Jaipur.pdf11052024_First India Newspaper Jaipur.pdf
11052024_First India Newspaper Jaipur.pdf
 
Politician uddhav thackeray biography- Full Details
Politician uddhav thackeray biography- Full DetailsPolitician uddhav thackeray biography- Full Details
Politician uddhav thackeray biography- Full Details
 
KING VISHNU BHAGWANON KA BHAGWAN PARAMATMONKA PARATOMIC PARAMANU KASARVAMANVA...
KING VISHNU BHAGWANON KA BHAGWAN PARAMATMONKA PARATOMIC PARAMANU KASARVAMANVA...KING VISHNU BHAGWANON KA BHAGWAN PARAMATMONKA PARATOMIC PARAMANU KASARVAMANVA...
KING VISHNU BHAGWANON KA BHAGWAN PARAMATMONKA PARATOMIC PARAMANU KASARVAMANVA...
 

Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive

  • 1. Cookie Compliance Conference, 6 December 2011, London and Roundtable Medienpolitik, 7 December 2011, Brussels Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive Carl-Christian Buhr European Commission (All expressed views are those of the speaker.) http://slidesha.re/cookieeu http://bit.ly/cc_buhr , @ccbuhr
  • 2. http://bit.ly/NeelieKroesEU , @NeelieKroesEU http://ec.europa.eu/digital-agenda DAE 101 Actions
  • 3. http://bit.ly/NeelieKroesEU , @NeelieKroesEU http://ec.europa.eu/digital-agenda 101 Actions Advising on... ePrivacy/Data Protection Cloud Computing ICT Standardisation Research Policy etc. http://bit.ly/cc_buhr , @ccbuhr
  • 4. The ePrivacy Directive “ Directive (2002/58/EC) on privacy and electronic communications as amended by Directive 2009/136/EC ("Citizens' Rights Directive")” [ Link ] ⟹ Adopted by EU Parliament, Council 2009 ⟹ Transposition deadline for Member States 25 May 2011, delays in several Member States
  • 5. Article 5(3) From right to refuse to consent “ Member States shall ensure that the storing of information , or the gaining of access to information already stored , in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent , having been provided with clear and comprehensive information , in accordance with Directive 95/46/EC, inter alia about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service .”
  • 6. Article 5(3) basics ⟹ Not limited to cookies ⟹ Not limited to specific uses ⟹ Not limited to telcos ⟹ Obliging providers ⟹ Technologically neutral
  • 7. The Status Quo is not enough Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 “ This revision of the ePrivacy Directive has brought a material strengthening of protection for citizens and Member States need to make sure this is reflected in national law.”
  • 8. Article 5(3) in Member States Commission guidance paper ⟹ Commission services working document of 20/10/2010 ⟹ Presented to Communications Committee of Member State representatives ⟹ Aim: Help prevent fragmentation
  • 9. Tracking is the issue Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 “ [O]nce user profiles exist they can potentially be used for all kinds of things . “ [D]ifference between a commitment not to record tracks and a commitment not to use them for a specific purpose once recorded”
  • 10. EASA/IAB OBA Self-Regulation http://www.easa-alliance.org/page.aspx/386 “ What I like about this solution is that it is active . Industry is not just saying – as some unfortunately still do – that all is fine because users can disable cookies in their web browsers.” [ link ] ⟹ Assuring compliance on its own: doubts ⟹ Scope: limited to certain methods, uses
  • 11. Need broader discussion “Do not track” (DNT) Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 DNT can apply to all devices, types and purposes of tracking “ We need a standard!” Deadline: June 2012 W3C has started work
  • 12. DNT Scenario after June 2012 Online privacy – reinforcing trust and confidence , Brussels, 22/06/2011, http://europa.eu/rapid/pressReleasesAction.do?reference=SPEECH/11/461 1. Simple Message : If you do DNT you are fine! 2. Virtuous Circle of adoption by users and providers 3. Enabled by tool makers' innovation on sufficiently rich standard
  • 13. Browser settings etc. 1. ePrivacy obliges provider, not browser 2. DNT lets provider know user preference! ⟹ Good chance for future browser settings to become sufficient ⟹ Issue: How to deal with unset DNT (trigger user prompt? rely on earlier browser prompt? etc.)
  • 14.