As some of you may or may not know on the 26th of May 2011 new legislation comes into force for any site doing business inside the European Union about the way cookies can be used by websites.

Have already prepared changes or are you waiting to see what the bigger sites do first?

Dani AI

Generated

A short, practical note for site owners and devs who hit this thread: if your site reaches EU users, start with a cookie audit and a consent mechanism rather than waiting to see what big sites do. As asked whether to prepare, the sensible first step is discovery; as noted, truly internal intranets/extranets are typically outside the scope—check the regulator guidance for your country for specifics.

The legal core to keep in mind is simple: cookies that are strictly necessary for a service may be set without consent, but anything else (analytics, advertising, social widgets, personalization) requires prior, informed and unambiguous consent. The EU Article 29 Working Party stressed consent must be an affirmative action, not buried or assumed. Article 29 Working Party opinion on cookies

Practical checklist:

  • Audit every cookie (name, domain, purpose, lifetime, first/third party).
  • Classify as strictly necessary or non-essential.
  • Add a clear cookie policy listing names/purposes/durations.
  • Block non-essential scripts/cookies until consent is given; allow easy withdrawal and record consent events.
  • Keep a vendor list and proof of your audits.

On 's "cookiejacking" point: the danger is usually cookie theft via XSS or interception, not a mysterious remote-control attack. Mitigate by serving over HTTPS and using cookie attributes like HttpOnly, Secure and SameSite, plus XSS prevention and CSP. See browser docs and secure-session guidance for implementation details. MDN Set-Cookie header | OWASP Session Management Cheat Sheet

Recommended Answers

All 2 Replies

Most if not all companies silently ignore this as it's utterly ridiculous. Adding a disclaimer is probably all that most companies will do, as the alternative would be to not use cookies at all which would cripple their sites.
A typical law created by bureaucrats who don't have any idea what they're dealing with, yet have far reaching powers that far outstretch their competence.

Personally, I don't have to do anything as I work almost exclusively on intranet and extranet applications which aren't public websites.

New hack! Cookiejacking. Using cookies to control someone else computer.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.