Asia Australia Brazil Canada China Cyprus Germany Hong Kong Indonesia Ireland Malaysia Mexico Morocco Saudi Arabia South Africa Switzerland United Arab Emirates United Kingdom United States Webinar

The Compliance Digest
Subscribe Us!
  • Home
  • About Us
  • Categories
    • Compliance
    • Compliance Training & Education
    • Corporate Governance
    • Data Security & Privacy
    • Ethical & Social Responsibility
    • Events & Conferences
    • Expert Interviews
    • Financial Crimes & Fraud Prevention
    • Personal & Professional Development
    • Regulatory Updates
    • Risk Management
    • Technology & Fintech
  • Media Sources
  • Contact
Data Security & Privacy

ICO update – be a “smart cookie” and comply before its AI tool catches you

Brodies LLP | Alison Bryce | Rebecca Ronney | Amelia Wilson

As discussed in our previous blog ‘Cookie Compliance – ICO takes a bite’, the ICO issued a statement in November 2023 revealing that it had written to 53 of the companies operating the UK’s top 100 most visited websites warning them that they risked facing enforcement action if they failed to offer website visitors fair choices regarding personalised advertising tracking within 30-day from the notification.

The ICO highlighted concerns that many websites lacked mechanisms for users to make informed decisions about being tracked for personalised advertising. Previously, the ICO had issued clear guidance, emphasising the necessity for organisations to make it as easy for users to “Reject All” advertising cookies as it is to “Accept All”.

In its statement, the ICO drew attention to the emotional toll of cookie tracking and targeted advertising. Examples included scenarios where gambling addicts might receive betting offers based on their browsing history, women could be subjected to distressing baby adverts shortly after experiencing a miscarriage, and individuals exploring their sexuality might encounter ads disclosing their sexual orientation.

Subsequently, the ICO has reported that most contacted companies responded positively to the warning. Of the 53 companies contacted, 38 of the companies have since adjusted their cookie banners and taken measures to ensure compliance with data protection regulations and a further four committed to be compliant before the end of February 2024.

Nevertheless, the ICO has announced plans to pursue action against the next top 100 websites regarding their use of advertising cookies stating that the ICO “will not stop with the top 100 websites. We are already preparing to write to the next 100 – and the 100 after that.” The ICO has also stated that they intend to develop an AI solution to identify websites using non-compliant cookie banners.

Cookie Requirements

As a reminder, the use of cookies is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 and the Data Protection Act 2018. Website providers using cookies must:

  • inform users cookies are being used and specify the individual cookies being used;
  • clearly and comprehensively explain the purposes relating to the cookies storage and access to the information;
  • the duration of the operation of the cookies and if any third parties have access to the cookies;
  • request in plain language the user’s active and specific consent to the use of the cookies;
  • distinguish cookie consent from consent to any other terms of use or terms and conditions;
  • be able to demonstrate the valid and informed consent provided by users; and
  • include mechanisms that allows users to withdraw consent.

This article first appeared on Lexology. You can find the original version here.

About Author / ayianni

Previous post
Regulating AI – UK & EU take divergent approaches
Next post
ESAs risk update: risks remain high in the EU financial system

Leave a Comment Cancel reply

Your email address will not be published.

You Might Also Like

Data Security & Privacy

The EU Digital Operational Resilience Act (DORA): Top 7 Challenges for IT Vendors

13 August 2025
Data Security & Privacy

Debt Capital Markets: Global Overview

2 July 2025
Data Security & Privacy

Zero Trust Architecture: Trend or Transformation?

1 July 2025
compliance

Compliance

compliance-training-education

Compliance Training & Education

corporate-governance

Corporate Governance

data-security-privacy

Data Security & Privacy

ethical-social-responsibility

Ethical & Social Responsibility

events-conferences

Events & Conferences

expert-interviews

Expert Interviews

financial-crimes-fraud-prevention

Financial Crimes & Fraud Prevention

personal-and-professional-development

Personal & Professional Development

regulatory-updates

Regulatory Updates

risk-management

Risk Management

technology-fintech

Technology & Fintech

true

Subscribe to get the latest GRC news!

The Compliance Digest
Copyright © 2023 - The Compliance Digest
Privacy Policy Terms of Service
Subscribe Us!
  • Home
  • About Us
  • Categories
    • Compliance
    • Compliance Training & Education
    • Corporate Governance
    • Data Security & Privacy
    • Ethical & Social Responsibility
    • Events & Conferences
    • Expert Interviews
    • Financial Crimes & Fraud Prevention
    • Personal & Professional Development
    • Regulatory Updates
    • Risk Management
    • Technology & Fintech
  • Media Sources
  • Contact

Start typing and press Enter to search