{"id":1014,"date":"2024-03-19T11:54:07","date_gmt":"2024-03-19T11:54:07","guid":{"rendered":"https:\/\/clt.nliu.ac.in\/?p=1014"},"modified":"2024-03-19T11:54:09","modified_gmt":"2024-03-19T11:54:09","slug":"navigating-the-legal-landscape-of-cookies-privacy-concerns-and-dark-patterns","status":"publish","type":"post","link":"https:\/\/clt.nliu.ac.in\/?p=1014","title":{"rendered":"Navigating the Legal Landscape of Cookies: Privacy Concerns and Dark Patterns"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Soumyabrata Chakraborty\u00a0\u00a0is a student of Gujarat National Law University, Gandhinagar<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cookies are small textual data files launched onto a user&#8217;s device while browsing a website. They are stored in the user\u2019s web browser and contain large chunks of data from their interaction with websites. These data files are then processed by the websites visited or third parties, like advertisers, to provide a personalised and convenient user experience. In terms of their utility, cookies are useful and often considered harmless- however, they pose serious privacy concerns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article seeks to analyse the data privacy concerns posed by internet cookies and how they are sought to be regulated in the European Union. From that moment forward, the article aims to analyse how an Indian cookie law can be read into the provisions of the <a href=\"https:\/\/www.meity.gov.in\/writereaddata\/files\/Digital%20Personal%20Data%20Protection%20Act%202023.pdf\">Digital Personal Data Protection Act, 2023<\/a> (\u201cDPDPA\u201d) and how it compares to the EU approach. Additionally, the article analyses how the <a href=\"https:\/\/consumeraffairs.nic.in\/sites\/default\/files\/The%20Guidelines%20for%20Prevention%20and%20Regulation%20of%20Dark%20Patterns%2C%202023.pdf\">Guidelines for Prevention and Regulation of Dark Patterns, 2023<\/a> (\u201cthe Guidelines\u201d), can be extended to dark patterns in cookie consent notices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I.<\/strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Cookies: Invasive, Yet Useful<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>A. What information do cookies collect?<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cookies can store a wealth of data- enough to identify the user and create an online profile, thus the privacy concerns.<a href=\"https:\/\/www.amazon.in\/gp\/help\/customer\/display.html?nodeId=200534380&amp;ref_=footer_privacy\"> <\/a><a href=\"https:\/\/www.amazon.in\/gp\/help\/customer\/display.html?nodeId=200534380&amp;ref_=footer_privacy\">Privacy Notice of Amazon.in<\/a> lists \u201cAutomatic Information\u201d collected by way of cookies and includes location of device or computer, IP address, login, email address, password, etc. This information can be used to identify user preferences, personalise user experience, and display interest-based ads, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>B. Classification of cookies<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cookies can be<a href=\"https:\/\/gdpr.eu\/cookies\/\"> <\/a><a href=\"https:\/\/gdpr.eu\/cookies\/\">classified<\/a> based on duration, source or provenance, and purpose. Depending on source or provenance, \u201cfirst-party cookies\u201d are launched by websites the user visits, while \u201cthird-party cookies\u201d are placed by entities such as an advertiser or the browser. Based on purpose, \u201cstrictly necessary cookies\u201d are essential for website functionality and are generally first-party cookies, while \u201cmarketing cookies\u201d are used to track user activity to enable advertisers to serve targeted and behavioural advertisements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>II.<\/strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Regulating Cookies In EU And India<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>A.<\/em>&nbsp;&nbsp;&nbsp;&nbsp; <em>European Union: GDPR and ePrivacy Directive<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulatory oversight of cookies depends on whether cookies or information stored by them falls within the definition of personal data prescribed in the specific data protection law. In the European Union, Article 4(1) of the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679\">General Data Protection Regulation<\/a> (\u201cGDPR\u201d) defines \u201cpersonal data\u201d as any information relating to an identified or identifiable person (\u201cdata subject\u201d). Identifiers, as listed in Article 4(1), include an \u201conline identifier\u201d. <a href=\"https:\/\/gdpr.eu\/recital-30-online-identifiers-for-profiling-and-identification\/\">Recital 30<\/a> of the GDPR includes \u201ccookie identifiers\u201d within the ambit of online identifiers. Thus, the GDPR explicitly mentions cookies as personal data, thus extending its regulatory oversight over them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Besides the GDPR, the <a href=\"https:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:PDF\">Directive on Privacy and Electronic Communications<\/a> of 2002, amended in <a href=\"https:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=OJ:L:2009:337:0011:0036:en:PDF\">2009<\/a> (\u201cePrivacy Directive\u201d or \u201cEPD\u201d), has specific provisions concerning the processing of personal data in the electronic communications sector. Recital 25 and Article 5(3) of the EPD provide that the storing of information, including cookies, into the \u201cterminal equipment\u201d or device of a user can only be allowed based on consent. Additionally, Recital 25 requires the method of giving information, requesting consent, and offering a right to refuse to be <em>\u201cas user-friendly as possible.\u201d<\/em> However, Recital 25 also provides that access can be made conditional on well-informed acceptance of a cookie, provided it is for a legitimate purpose. Recital 66 of <a href=\"https:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=OJ:L:2009:337:0011:0036:en:PDF\">Directive 2009\/136\/EC<\/a>, amending the EPD in 2009, further highlights this exception, wherein obligation to provide information and right to refuse can be exempted when cookies are \u201cstrictly necessary\u201d for the legitimate purpose of functionality.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Article 7 of the GDPR outlines the \u201cconditions for consent\u201d and includes the data subject\u2019s right to withdraw consent at any time. Additionally, <a href=\"https:\/\/gdpr.eu\/recital-32-conditions-for-consent\/\">Recital 32<\/a> of the GDPR and Article 4(11) provide that consent should be given by a clear affirmative action and must be free, specific, informed and unambiguous. Recital 32 further states that pre-ticked boxes should not be considered valid consent, which has been reiterated in the <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf;jsessionid=F4E966522DE6EA1901D2B3899333B42E?text=&amp;docid=218462&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=732498\">Planet49 GmbH<\/a> case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>B.<\/em>&nbsp;&nbsp;&nbsp;&nbsp; <em>India<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>a)<\/em> &nbsp;<em><u>DPDPA, 2023<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike the GDPR, India\u2019s long-awaited data protection and privacy legislation, the <a href=\"https:\/\/www.meity.gov.in\/writereaddata\/files\/Digital%20Personal%20Data%20Protection%20Act%202023.pdf\">Digital Personal Data Protection Act of 2023<\/a> (\u201cDPDPA\u201d) has failed to acknowledge cookies as a legislative concern. Cookies find no explicit mention in the DPDPA. Section 2(t) of DPDPA defines \u2018personal data\u2019 as <em>\u201cany data about an individual who is identifiable by or in relation to such data\u201d. <\/em>Reading along the lines of the GDPR, cookies and the information collected in them can be considered personal data to the extent that cookies contain information that can be attributed to specific individuals. While it remains to be seen if the highly anticipated rules and regulations under the DPDPA clarify the issue of cookies and whether they amount to personal data, it is safe to presume they are, based on <a href=\"https:\/\/gdpr.eu\/cookies\/\">learnings<\/a> from the GDPR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Collecting information such as location of the device, IP address, email IDs, passwords, etc., by way of cookies; storing cookies in the user\u2019s device; and sharing them with third parties would amount to \u2018processing\u2019 of digital personal data under Section 2(x) of the DPDPA. Under Section 3 of the DPDPA, processing of cookie data collected from data principals situated within the territory of India by third-party \u2018data processors\u2019 outside India would also be regulated by the Act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like the GDPR, DPDPA envisages \u201cconsent\u201d to be the basis for the processing of personal data. Section 4 provides that processing must be for a lawful purpose, which the Data Principal has consented to. Section 5 requires the data fiduciaries (here, websites) to give notice of personal data collected and the purpose for the same. It remains to be seen whether such notice would need to provide details of each type of cookies that a website stores on a user\u2019s device and the \u2018specific purpose\u2019 for which they are sought to be used. Section 6 of the DPDPA states that a clear affirmative action must give consent, and it must be free, specific, informed, unconditional and unambiguous. Section 6(1) further alludes that consent is given for some specified purpose and is limited to such data as is necessary for such purpose. In the absence of clear rules and regulations as to what cookies are necessary for a specific purpose and what isn\u2019t, users would be left to educate themselves on their own, and this would ultimately lead to <a href=\"https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=2412418\">consent fatigue<\/a>. What stands out in Section 6(1) is the use of the word \u201cunconditional\u201d. While EPD has carved out an exception for \u201cstrictly necessary\u201d cookies from a functional standpoint and allowed websites to take an exception to the right to refuse obligation, Section 6(1) of the DPDPA restricts the use of \u2018cookie walls\u2019 or denial of service for want of consent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Section 9(3) states- <em>\u201ca data fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children\u201d<\/em>. This is significant, considering tracking user activity, behavioural monitoring, and serving targeted advertisements are some of the most prominent use cases of internet cookies. A complete crackdown on targeted advertisements directed at children (individuals below 18 years of age) may look good on paper; however, its operational viability is a big concern. Section 9(1) puts the onus on the Data Fiduciary to obtain \u201cverifiable consent\u201d of the parent or lawful guardian. What constitutes \u2018verifiable consent\u2019 is not specified, leaving room for interpretation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>b)<\/em> <em><u>Guidelines for Prevention and Regulation of Dark Patterns, 2023<\/u><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Central Consumer Protection Authority issued the <a href=\"https:\/\/consumeraffairs.nic.in\/sites\/default\/files\/The%20Guidelines%20for%20Prevention%20and%20Regulation%20of%20Dark%20Patterns%2C%202023.pdf\">Guidelines for Prevention and Regulation of Dark Patterns, 2023<\/a> (\u201cthe Guidelines\u201d). Though these guidelines cater to consumer protection, not consumer data protection <em>per se<\/em>, it is a noteworthy development for cookie consent banners. Studies have <a href=\"https:\/\/www.jdsr.io\/articles\/2021\/2\/8\/dark-and-bright-patterns-in-cookie-consent-requests\">found<\/a> that using dark patterns in cookie disclaimers or consent banners is rampant. Annexure 1 of the Guidelines lists several \u2018specified dark patterns\u2019. \u2018Forced action\u2019 has been defined to include forcing a user into taking an action requiring the user to share personal information to buy or subscribe to a product or service. Depending on whether cookies can be read into the definition of \u201cpersonal information\u201d as used in the Consumer Protection Act, 2019, and the Guidelines made thereunder, these guidelines can be extended to dark patterns in cookie notices. Constant requests to turn on or accept cookies with no right to refuse have been illustrated as an example of \u201cnagging\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>III.<\/strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>Conclusion<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The article briefly analysed the privacy risks of cookies and how the GDPR and the EPD have attempted to regulate them. Even though the DPDPA has left much to be desired, and the rules and regulations under the Act are anticipated to shed some light on several concerns, the article has tried to read a cookie law into the provisions of DPDPA, considering cookies to be personal data in line with GDPR. Regulating the use of cookies will go a long way in ensuring the anonymity of netizens. GDPR has already brought about a <a href=\"https:\/\/reutersinstitute.politics.ox.ac.uk\/news\/third-party-cookies-down-22-europes-news-sites-gdpr?mod=djemCMOToday\">22% drop<\/a> in the use of third-party cookies on Europe\u2019s news sites. Along similar lines, Google Chrome has started testing <a href=\"https:\/\/blog.google\/products\/chrome\/privacy-sandbox-tracking-protection\/\">\u201cTracking Protection\u201d<\/a> feature as part of its <a href=\"https:\/\/developers.google.com\/privacy-sandbox\/blog\/cookie-countdown-2023oct#:~:text=If%20your%20site%20uses%20third,users%20from%20January%204th%2C%202024.\">Privacy Sandbox initiative<\/a> to phase out third-party cookies in second half of 2024. With legislative interest and growing awareness, the use of cookies needs to be reigned in, and all stakeholders have a role to play.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Soumyabrata Chakraborty\u00a0\u00a0is a student of Gujarat National Law University, Gandhinagar Cookies are small textual data files launched onto a user&#8217;s device while [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1014","post","type-post","status-publish","format-standard","hentry","category-blog-series","col-md-6 col-sm-6"],"_links":{"self":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1014"}],"version-history":[{"count":1,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1014\/revisions"}],"predecessor-version":[{"id":1015,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=\/wp\/v2\/posts\/1014\/revisions\/1015"}],"wp:attachment":[{"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clt.nliu.ac.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}