Are you ready for good cookie, bad cookie?

Are you ready for good cookie, bad cookie?
The new cookie law comes in to force on 26th May

Tomorrow marks the cookie implementation deadline and from the end of today all UK websites that store cookies should have implemented some sort of policy, or they could be facing fines.

Over the last week major sites like the BBC, the Mirror, BT have started to obtain consent from visitors to store or retrieve any information on any device from computers through to smartphones and tablets.

The reason they're doing this is because of the Privacy and Electronic Communications Regulations law. The law was designed to protect online privacy by making consumers aware of how information about them is collected by websites, and enables them to choose whether or not they want it to happen.

The BBC cookies policy

The BBC cookies policy

It started as an EU directive adopted by all EU nations on 26 May 2011, and this directive was brought into UK law through the Privacy and Electronic Communications Regulations. Although the directive came into force in May 2011, the UK Information Commissioner Christopher Graham gave British organisations a year to conform.

A code of conduct introduced by the London office of the International Chamber of Commerce at the beginning of April implied website owners will need to differentiate between cookies that they need simply to make a website work, those that provide enhanced functionality, and those that exist simply to gather information for the site's own purposes.

The Mirror cookie policy

The Mirror cookie policy

Most UK companies are reportedly expected to miss today's deadline, and both Graham and Communications Minister Ed Vaizey have said that they are unlikely to punish firms severely while the new policies are phased in – fines could be as much as £10,000.

You will however have to comply with the law at some time in the future, so here's our quick guide to "bad" cookies and your website choices.

Third-party cookies are the cookies that pose the most compliance issues. For example, a cookie that is used in behavioural advertising, where they identify what you click on and tell advertising websites to display that type of product or service wherever you go afterwards. From 26 May, website owners must disclose or seek permission to use this type of cookie.

BT functional cookies

BT functional cookies

Next up is the "persistent cookie" that remains on a computer after the customer has moved on to another website. They're also one of the most useful cookies, as they're the cookies that flag that a person is a returning customer and enables your website to be personalised. They're also used extensively in web analytics, so you could potentially lose all that valuable tracking data.

Strictly necessary cookies from BT - What the ???

Strictly necessary cookies from BT - What the ???

Previously, cookies were used on most websites on an opt-out basis, meaning many site visitors undertook their web sessions with no idea that cookies were being used. The new regulations mean that users now need to opt-in to a cookie session – making it far less likely that they will be accepted

An explicit opt-in/opt-out - If your site has third-party advertising, social media connectors, uses web analytics then your safest bet is to seek explicit opt-in from visitors via some kind of very visible opt in like those used by BT.

Targettin Cookies from BT

Targettin Cookies from BT

Implied consent via notice If your site doesn't feature advertising and uses cookies for functional purposes (accessibility, Facebook Like buttons and Google Analytics), then you may be fully compliant if you have a cookie notice displayed clearly on your website referencing details on your privacy page.

Performance cookies on BT - Viagra ??

Performance cookies on BT - Viagra ??

We'd like to hear what you think about the new cookie legislation. Are you waiting to see what others do? What approach are you taking? Leave a comment below and share your feelings.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring