In News / Updates

How to adapt to the new Cookies guidelines of the Protection Authority

30 September 2021
cookie policy protection

The final version of the guidelines on the use of cookies and other online tracking systems has been published. Many new features have been introduced and six months it has been given to adapt sites to the new rules.

In the Gazzetta Ufficiale n.163 of July 9, 2021 the new Guidelines for cookies adopted by the Italian Data Protection Authority have been published. The update of the 2014 Guidelines on the usage of cookies and other tracking tools, which apply to read and write operations in users' devices, was necessary due to the entry into force of the GDPR (General Data Protection Regulation) and other reasons, such as:

  • the experience gained over the years - also on the basis of the numerous complaints, reports and requests for opinions received by the Authority
  • the increasing use of particularly invasive trackers
  • the multiplication of users' digital identities that encourages the cross-referencing of their data and the creation of more detailed profiles

But first things first.

What is the function of cookies?

Cookies are strings of text placed and stored on the users’ devices, e.g. smartphones, computers, tablets, etc., by websites they have visited.Software used to navigate in sites store these identifying strings. When the user visits those web sites again, the memory of the interactions, which the user previously had with those sites, is maintained. The characteristics of the user, such as IP address, user name, email address, language setting and information on the type of device used to browse the site, are maintained as well. The practical function of such cookies is both to load web pages faster and keep track of items placed in a shopping cart in a previous navigation. Another function includes sending targeted advertising to the user: on the basis of the user's behavior on the web in previous access sessions, the advertising is chosen.

What changes with the new guidelines?

Current legislation provides that specific configurations of computer programs or devices – easy and clear for the user – may be used to acquire user consent. According to the Authority, this is a generic provision that needs to be supplemented with clear procedures to acquire user consent to the use of cookies.

In short, if you or your users are based in Italy, these are the updates that affect you:

Cookie banner
- the "Accept" and "Reject" buttons are compulsory       
- users should be able to make granular choices about the functionality, third parties and categories of cookies to be installed. While leaving implementation details to the service provider, the guidelines suggest that grouping options is a suitable way to meet this requirement
- users must be able to update their tracking preferences at any time.

Consent collection
- consent via simple scroll is no longer valid
- cookies walls are not permitted
- v
alidity of user preferences regarding consent : after asking for consent the first time, at least 6 months must elapse before it can be asked again

Statistics Cookies (analytics)
First-party statistical cookies may be installed without the user's consent (and without prior blocking)
- Third-party statistical cookies may be installed without the user's consent (and without prior blocking) only under certain conditions

Proof of Consent: you must be able to demonstrate that you have obtained valid consent in line with GDPR standards
Legal grounds: they are applicable to the use of cookies in addition to the consent. Legitimate interest is not a valid legal ground

Among other things, the new Guidelines contain provisions on scrolling and cookies walls, all the details athttps://www.garanteprivacy.it
Website owners will have six months from the present publication – until 01.10.2021 – to comply with the new Guidelines.


How do you adapt?

YAK Agency cannot replace the customer, who remains the owner of data processing and therefore responsible both to the interested parties and the Supervisory Authority for data processing. However, we guarantee that data customers entrust us with is processed in accordance with Italian and European legislation and more generally in a lawful, fair and transparent way. We also ensure that our staff receive appropriate privacy training.

For Customers who have an active Iubenda contract a quick intervention to adapt the Cookie Policy and the consent collection banner is needed.
For Customers who do not have an active Iubenda contract and who have not upgraded their website we will be happy to inform you of the existing rules and risks.

Contact us for more information!