SlideShare a Scribd company logo
#3 Cookies are not so appetizing anymore
ePrivacy Directive: to be "as compliant as
possible”?
Brussels December 7th 2022
1
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
A plan, mainly for Ad&MarTech I
1. List digital properties:
a. Websites: who manages DNS, domain name servers, at your company?
b. Are there other digital properties where your company acts as a data
controller? Landing pages in other tools than your content management
solution (CMS)?
c. Start thinking about apps in mobile
2. Scans for cookies, pixels, trackers
a. Be ready for uncertainty as results vary so does classification (purpose)
3. Work with the CMO to decide which processors to keep
4. Find the DPAs for those data processors
5. Clean out the code of those unwanted trackers
2
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
A plan, mainly for Ad&MarTech II
6. Set-up a cookie policy
a. Define what is required: name of cookie, duration, how to exercise rights, ..
b. As with your privacy policy, give this policy a date stamp
7. Define those trackers who need consent
a. Classify those necessary vs. those requiring consent
b. Be prepared for additional uncertainty
8. Set-up some form of a consent mechanism – CMPs?
9. Create a process to keep these lists & DPAs dynamic
10. Audit twice a year through scanning, update cookie policy & archive
3
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
Uncertainty in 7b: depends on configuration
4
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
Tool set-ups matter!
5
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
Why does this classification matter?
6
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
Direct marketing => lead generation
The cookies in ePrivacy are just one
part of the story
The boarder picture is about direct
marketing driving leads
On your website you’d want to know:
1. where they came from and
2. what they did
They might fill in a form and this data
is ingested into a CRM where GDPR
also plays a role
7
Source: https://marketinginsidergroup.com/wp-
content/uploads/2019/04/sales-pipeline.png
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
Some forms drop cookies
Cookies in forms can be used for fraud detection
while others for marketing
Suggestion work outside in:
1. From ePrivacy consent
obligations
2. To forms impacted by
GDPR
3. To sales support using
CRM data and other
lawful basis beyond consent
8
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
2 more caveats
1. ePrivacy is more than “just” cookies, see next slide.
In this context it also applies to server-to-server communications.
Saying this mainly for actors talking about moving away from
cookies like Google, see
https://blog.google/products/chrome/update-testing-privacy-
sandbox-web/
2. Globally, such set-ups could be impacted by other legislations such
as California CCPA/CPRA, which also talks of GPC, Global Privacy
Control (similar to DNT and PIMS)
9
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
From the EDPS replying to the FTC
"The ePrivacy Directive covers processing of personal data and the protection of privacy including provisions on:
the security of networks and services; the confidentiality of communications; access to and storing information
on terminal equipment; processing of traffic and location data; calling line identification; public subscriber
directories. It also lays down general rules applicable to unsolicited commercial communications ("spam").
Initially, it applied only to publicly available electronic communications services (i.e. internet access provision
and telephony services.
Since the entry into application of Directive 2018/1972 establishing the European Electronic Communications
Code on 20 December 2020, it now applies to all ‘interpersonal communications services’, i.e. services
normally provided for remuneration that enable direct interpersonal and interactive exchange of information
via electronic communications networks between a finite number of persons, whereby the persons initiating or
participating in the communication determine its recipient(s) and does not include services which enable
interpersonal and interactive communication merely as a minor ancillary feature that is intrinsically linked to
another service; this includes also ‘number-independent interpersonal communications service’ such as instant
messaging (apps).”
Source: https://www.regulations.gov/comment/FTC-2022-0053-0778
10
aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates –
About Google Analytics
• The conversations today are mainly about international data transfers
following SchremsII
• France, Italy, Denmark, .. Have ruled it inadequate in light of SchremsII +
the fact that Google is subject to FISA/EO12333
• French CNIL set-up a list of alternatives https://www.cnil.fr/fr/cookies-et-
autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure-
daudience (September 2021)
• Google Analytics is being deprecated so a move to another tool is
necessary, see
https://support.google.com/analytics/answer/11583528?hl=en
• Everybody is praying Biden’s EO will solve the issue
• It won’t but what is your time frame for your company’s investments?
11
Thank you for your attention
Aurelie.pols@protonmail.com
12

More Related Content

PPTX
The EU ePrivacy Directive - Navigating the UK Cookie Law
PDF
GLG webcast impact of GDPR on ad tech
PDF
4Ps Cookies Legislation
PDF
EU Privacy for US Businesses - Presentation to Union Square Ventures
PDF
EU Privacy for US Businesses - Presentation to Union Square Ventures
ODP
120119 ukgc12-cookies
PPT
4 ps cookies
PPT
Cookies Update
The EU ePrivacy Directive - Navigating the UK Cookie Law
GLG webcast impact of GDPR on ad tech
4Ps Cookies Legislation
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square Ventures
120119 ukgc12-cookies
4 ps cookies
Cookies Update

Similar to ePrivacy Directive, a 10 steps framework to be as compliant as possible for marketing (20)

PDF
Here comes the Cookie Monster
PDF
Everything B2B Tech Marketers Need to Know About Privacy + Consent
PPT
Eprivacy issues and standards -- where do we stand?
PDF
Greenlight digital marketing - when the digital cookie crumbles
PDF
Your Big Data Opportunity
PDF
Privacy and Electronic Communications Regulation - Elaine McKinney
PDF
The DMA conference 2012
PPTX
GDPR - Australian perspective - the challenge, the opportunity and your duty
PPTX
Nick Stringer, IAB UK - Preparing for the revised ePrivacy directive
PPT
DMA North: Legal Update
PPT
DMA North: The DMA legal update
PPT
Solved the european e privacy directive and performance marketing - Kevin E...
PPT
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
PPTX
2012-Oct: Effect of EU cookie law on US organisations
PPT
Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive
PPTX
The somewhat awkward marriage between digital marketing and data protection (...
PDF
Deck for Chardan conference call on ePrivacy and GDPR
PDF
Acquia Webinar Deck - 9_13 .pdf
PDF
Google Solutions for Brands to Build a Privacy-First Strategy
PPTX
Travelodge GDPR Case Study
Here comes the Cookie Monster
Everything B2B Tech Marketers Need to Know About Privacy + Consent
Eprivacy issues and standards -- where do we stand?
Greenlight digital marketing - when the digital cookie crumbles
Your Big Data Opportunity
Privacy and Electronic Communications Regulation - Elaine McKinney
The DMA conference 2012
GDPR - Australian perspective - the challenge, the opportunity and your duty
Nick Stringer, IAB UK - Preparing for the revised ePrivacy directive
DMA North: Legal Update
DMA North: The DMA legal update
Solved the european e privacy directive and performance marketing - Kevin E...
Agenda 21 eu cookie seminar - david naylor - field fisher waterhouse
2012-Oct: Effect of EU cookie law on US organisations
Cookie Conundrum? Article 5(3) of the EU ePrivacy Directive
The somewhat awkward marriage between digital marketing and data protection (...
Deck for Chardan conference call on ePrivacy and GDPR
Acquia Webinar Deck - 9_13 .pdf
Google Solutions for Brands to Build a Privacy-First Strategy
Travelodge GDPR Case Study
Ad

More from Aurélie Pols (20)

PDF
AI Roles and Risk for election year 2024
PDF
Preparing for the AI Act - 5 years into GDPR enforcement
PDF
Creative destruction & Privacy Whitewashing: where does risk lie?
PDF
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
PDF
Women in STEM for IE Girl Up Club
PDF
For Superweek 2022: discussing risk using IAB's TCF
PDF
Interoperability in Digital will take a Global Village
PDF
The GDPR is here. So do you know what the courts are saying?
PDF
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
PDF
GDPR and the aftermath: what are we building towards?
PDF
Who Goes There? Demystifying Digital Identity for All (1/2)
PDF
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
PDF
How digitization challenges our values as citizens
PDF
Technical Consequences of the Data Subject's Rights
PDF
From GDPR to ePrivacy: what does it mean to the advertising sector?
PDF
State of EU legislation: GDPR & ePrivacy for Superweek
PDF
The Great GDPR MyData Debate - Aurelie Pols - Keynote
PDF
The Data Subject First? Decoding the GDPR at StrataData
PDF
Brussels data science - Privacy Engineering for Big Data & Data Science
PDF
Sibos INNOTRIBE Digital Ethics
AI Roles and Risk for election year 2024
Preparing for the AI Act - 5 years into GDPR enforcement
Creative destruction & Privacy Whitewashing: where does risk lie?
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
Women in STEM for IE Girl Up Club
For Superweek 2022: discussing risk using IAB's TCF
Interoperability in Digital will take a Global Village
The GDPR is here. So do you know what the courts are saying?
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
GDPR and the aftermath: what are we building towards?
Who Goes There? Demystifying Digital Identity for All (1/2)
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
How digitization challenges our values as citizens
Technical Consequences of the Data Subject's Rights
From GDPR to ePrivacy: what does it mean to the advertising sector?
State of EU legislation: GDPR & ePrivacy for Superweek
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Data Subject First? Decoding the GDPR at StrataData
Brussels data science - Privacy Engineering for Big Data & Data Science
Sibos INNOTRIBE Digital Ethics
Ad

Recently uploaded (20)

PDF
Optimise Shopper Experiences with a Strong Data Estate.pdf
PPTX
Pilar Kemerdekaan dan Identi Bangsa.pptx
PPTX
Steganography Project Steganography Project .pptx
PPTX
sac 451hinhgsgshssjsjsjheegdggeegegdggddgeg.pptx
PPT
lectureusjsjdhdsjjshdshshddhdhddhhd1.ppt
PPTX
STERILIZATION AND DISINFECTION-1.ppthhhbx
PDF
Navigating the Thai Supplements Landscape.pdf
PDF
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
PPTX
Business_Capability_Map_Collection__pptx
PPTX
DS-40-Pre-Engagement and Kickoff deck - v8.0.pptx
PPTX
Introduction to Inferential Statistics.pptx
PDF
Introduction to Data Science and Data Analysis
PDF
Microsoft 365 products and services descrption
PPTX
CYBER SECURITY the Next Warefare Tactics
PPTX
chrmotography.pptx food anaylysis techni
PPTX
A Complete Guide to Streamlining Business Processes
PDF
Tetra Pak Index 2023 - The future of health and nutrition - Full report.pdf
PPTX
SAP 2 completion done . PRESENTATION.pptx
PPTX
Topic 5 Presentation 5 Lesson 5 Corporate Fin
PPTX
Copy of 16 Timeline & Flowchart Templates – HubSpot.pptx
Optimise Shopper Experiences with a Strong Data Estate.pdf
Pilar Kemerdekaan dan Identi Bangsa.pptx
Steganography Project Steganography Project .pptx
sac 451hinhgsgshssjsjsjheegdggeegegdggddgeg.pptx
lectureusjsjdhdsjjshdshshddhdhddhhd1.ppt
STERILIZATION AND DISINFECTION-1.ppthhhbx
Navigating the Thai Supplements Landscape.pdf
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
Business_Capability_Map_Collection__pptx
DS-40-Pre-Engagement and Kickoff deck - v8.0.pptx
Introduction to Inferential Statistics.pptx
Introduction to Data Science and Data Analysis
Microsoft 365 products and services descrption
CYBER SECURITY the Next Warefare Tactics
chrmotography.pptx food anaylysis techni
A Complete Guide to Streamlining Business Processes
Tetra Pak Index 2023 - The future of health and nutrition - Full report.pdf
SAP 2 completion done . PRESENTATION.pptx
Topic 5 Presentation 5 Lesson 5 Corporate Fin
Copy of 16 Timeline & Flowchart Templates – HubSpot.pptx

ePrivacy Directive, a 10 steps framework to be as compliant as possible for marketing

  • 1. #3 Cookies are not so appetizing anymore ePrivacy Directive: to be "as compliant as possible”? Brussels December 7th 2022 1
  • 2. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – A plan, mainly for Ad&MarTech I 1. List digital properties: a. Websites: who manages DNS, domain name servers, at your company? b. Are there other digital properties where your company acts as a data controller? Landing pages in other tools than your content management solution (CMS)? c. Start thinking about apps in mobile 2. Scans for cookies, pixels, trackers a. Be ready for uncertainty as results vary so does classification (purpose) 3. Work with the CMO to decide which processors to keep 4. Find the DPAs for those data processors 5. Clean out the code of those unwanted trackers 2
  • 3. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – A plan, mainly for Ad&MarTech II 6. Set-up a cookie policy a. Define what is required: name of cookie, duration, how to exercise rights, .. b. As with your privacy policy, give this policy a date stamp 7. Define those trackers who need consent a. Classify those necessary vs. those requiring consent b. Be prepared for additional uncertainty 8. Set-up some form of a consent mechanism – CMPs? 9. Create a process to keep these lists & DPAs dynamic 10. Audit twice a year through scanning, update cookie policy & archive 3
  • 4. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – Uncertainty in 7b: depends on configuration 4
  • 5. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – Tool set-ups matter! 5
  • 6. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – Why does this classification matter? 6
  • 7. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – Direct marketing => lead generation The cookies in ePrivacy are just one part of the story The boarder picture is about direct marketing driving leads On your website you’d want to know: 1. where they came from and 2. what they did They might fill in a form and this data is ingested into a CRM where GDPR also plays a role 7 Source: https://marketinginsidergroup.com/wp- content/uploads/2019/04/sales-pipeline.png
  • 8. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – Some forms drop cookies Cookies in forms can be used for fraud detection while others for marketing Suggestion work outside in: 1. From ePrivacy consent obligations 2. To forms impacted by GDPR 3. To sales support using CRM data and other lawful basis beyond consent 8
  • 9. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – 2 more caveats 1. ePrivacy is more than “just” cookies, see next slide. In this context it also applies to server-to-server communications. Saying this mainly for actors talking about moving away from cookies like Google, see https://blog.google/products/chrome/update-testing-privacy- sandbox-web/ 2. Globally, such set-ups could be impacted by other legislations such as California CCPA/CPRA, which also talks of GPC, Global Privacy Control (similar to DNT and PIMS) 9
  • 10. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – From the EDPS replying to the FTC "The ePrivacy Directive covers processing of personal data and the protection of privacy including provisions on: the security of networks and services; the confidentiality of communications; access to and storing information on terminal equipment; processing of traffic and location data; calling line identification; public subscriber directories. It also lays down general rules applicable to unsolicited commercial communications ("spam"). Initially, it applied only to publicly available electronic communications services (i.e. internet access provision and telephony services. Since the entry into application of Directive 2018/1972 establishing the European Electronic Communications Code on 20 December 2020, it now applies to all ‘interpersonal communications services’, i.e. services normally provided for remuneration that enable direct interpersonal and interactive exchange of information via electronic communications networks between a finite number of persons, whereby the persons initiating or participating in the communication determine its recipient(s) and does not include services which enable interpersonal and interactive communication merely as a minor ancillary feature that is intrinsically linked to another service; this includes also ‘number-independent interpersonal communications service’ such as instant messaging (apps).” Source: https://www.regulations.gov/comment/FTC-2022-0053-0778 10
  • 11. aurelie.pols@protonmail.com © prepared by Aurélie Pols for Aurelie Pols & Associates – About Google Analytics • The conversations today are mainly about international data transfers following SchremsII • France, Italy, Denmark, .. Have ruled it inadequate in light of SchremsII + the fact that Google is subject to FISA/EO12333 • French CNIL set-up a list of alternatives https://www.cnil.fr/fr/cookies-et- autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure- daudience (September 2021) • Google Analytics is being deprecated so a move to another tool is necessary, see https://support.google.com/analytics/answer/11583528?hl=en • Everybody is praying Biden’s EO will solve the issue • It won’t but what is your time frame for your company’s investments? 11
  • 12. Thank you for your attention Aurelie.pols@protonmail.com 12