Cookie audits inspired by UK ICO
Cookie audits resurfaced as a major topic shortly after the United Kingdom’s Information Commissioner’s Office (ICO) recommended that such audits become a regular part of a company’s privacy compliance efforts.
On July 3rd, the ICO announced that it had published new, detailed guidance covering the use of cookies and similar tracking technologies on websites and other terminal equipment.
As part of this guidance, the ICO emphasized the importance of performing comprehensive cookie audits to detail what cookies are being used on a website and to discern which of them comprise “strictly necessary” first and third-party cookies versus those which do not.
A cookie audit should inform website operators
The audit should inform operators about the:
- presence of cookies on a website
- purpose and use of each cookie including the cookie’s involvement with processing of personal data
- values, data, lifespan and other attributes linked to each cookie
- proper categorization of each cookie such as required, functional or advertising
- classification of each cookie as first or third party
Every website is unique, but cookie audits do not need to be a difficult exercise for companies wanting to address consent requirements from the GDPR, CCPA, and other regulations.