Irish DPC gives 6 months to get cookies sorted
Irish website owners and operators have been warned by the Irish Data Protection Commission (DPC) that they could face enforcement…
Read MoreIn-depth blogs, how-tos and compliance strategies on privacy laws and guidelines
When accessing online the cookie policy of the URL page: https://www.vueling.com/es, users are informed about what cookies are and what cookies they use. It also communicates that Vueling can use the information by itself or through third parties such as, beacons, Pixel tags and Local storage, evaluations and statistical calculations on anonymous data, indicating “such information will not be used for any other purpose”. They also report that they may use third-party analytics cookies.
However, on the management of cookies, the company merely indicates that: “you can configure the browser to accept or reject by default all cookies or to receive an on-screen notice of the reception of each cookie and decide at that time its implementation or not on your hard drive.
You can also use ‘do not track’ tracking cookie blocking tools”. It is also noted that, “you can revoke at any time the consent given for the use of cookies by Vueling, configuring the browser for this purpose and that you can adjust the browser settings to prevent the installation of cookies websites or third parties in general.”
What the company does not provide is a management system or cookie configuration panel that allows the user to delete them in a granular way. To facilitate this selection the panel would have to enable a mechanism or button to reject all cookies, another to enable all cookies or to be able to do it in a granular way in order to manage the preferences of each user.
On this subject, it is considered that the information offered on the tools provided in the browsers of the computers to configure cookies would be complementary to the previous one, but insufficient for the intended purpose of allowing you to configure preferences in granular or selective form.
These facts constitute an infringement of Section 22.2 of the LSSI (Spanish Law on Information Society Services and Electronic Commerce), according to which:
“Service providers may use of data storage and retrieval devices on recipients’ terminal equipment, provided that they have given their consent after they have been provided with clear and complete information on their use, in particular, on the purposes of data processing”.
Read the decision in Spanish here
Begin your journey to cookie compliance with our easy-to-follow guides.
Irish website owners and operators have been warned by the Irish Data Protection Commission (DPC) that they could face enforcement…
Read MoreIt is the largest fine ever issued by the French data privacy watchdog CNIL. US retail giant Amazon was also…
Read MoreThe General data protection regulation (GDPR) is an EU law that helps protect data subjects personal data by ensuring user…
Read More