| So far, we have mostly read about the gigantic fines imposed by foreign data protection authorities on tech giants (Google, Amazon, Meta) in connection with cookies. Simple website operators have waited until the last possible moment – for economic reasons – to continue their illegal practices without risk. The moment has arrived, at least for Hungarian data controllers, as the National Authority for Data Protection and Freedom of Information (NAIH) has published its first and so far only official decision on cookie management. Although the NAIH has imposed a fine of only a modest HUF 10,000,000 (around EUR 25,000), the text of the decision states that the low fine is justified by the fact that this is the first time the authority has opened an investigation into cookie management. It is not worth defending the fact that everyone does it: the NAIH has stressed that the widespread nature of the infringement does not make it legal. In this context, the NAIH also pointed out that operating under the IAB Europe framework does not necessarily guarantee compliance. First of all, the authority stated that the information stored in cookies constitutes personal data, since it assigns unique identifiers to a specific person in order to identify a specific user. Some points from the practice challenged by the NAIH: It is unlawful practice when it is technically more difficult to “reject everything” than to “accept everything”. The “accept all” option was available at the first level (one click), whereas the “reject all” option was only available at the second level (two clicks). The “rejection” option, i.e. the option to refuse to place cookies in case of legitimate interest, was only available at the third level (at least three clicks). We note that a consistent decision was made by the French Data Protection Authority in December 2022, when it fined Microsoft €60 million for its cookie management practices on the bing.com website, among other reasons, because while acceptance was possible with one click, rejection required two clicks. The information was too complicated and difficult to read. The website displayed a very long text regarding cookies, all within an unjustifiably small area of the screen, making it readable only a few lines at a time. Overall, the information did not comply with the General Data Protection Regulation. Referring to the data controller as “we and our partners,” even with 754 partners, was not sufficiently clear. Incorrect use of legitimate interest. The website used the concept of “legitimate interest” in a misleading way. It is unfair to state the same processing purposes for cookies based on consent and cookies based on legitimate interest. In contrast, the use of consent as a legal basis for cookies necessary for the technical functioning of websites is excluded, but the controller did not provide an appropriate interest test. Unlawful transfers to third countries. In several cases, the data collected by the cookies were transferred to third countries through the 754 designated partners, but the risks of transfer to third countries were not managed and the data subjects were not informed about this. It is worth noting that civil organisations can also actively contribute to the mass proceedings against websites and apps. For example, the NOYB, led by Austrian activist Maximilian Schrems, filed nearly 300 complaints with national data protection authorities in the summer of 2022 against websites using OneTrust cookie banners. It is therefore clear that it is now the last moment to review websites’ cookie management practices and cookie banner settings before the NAIH does the same. |
