how bradford made friends with the cookie monster v0.1

37
The most eagerly awaited IWMW session EVER Workshop session C1: Responding to the Cookie Monster

Upload: claire-gibbons

Post on 06-May-2015

2.302 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: How Bradford made friends with the Cookie Monster v0.1

The most eagerly awaited IWMW session EVER

Workshop session C1: Responding to the Cookie Monster

Page 2: How Bradford made friends with the Cookie Monster v0.1

We are . . .

• John Kelly, Principal Legal Information Specialist with JISC Legal

• Claire Gibbons, Senior Web and Marketing Manager, University of Bradford

Page 3: How Bradford made friends with the Cookie Monster v0.1

We’ll cover . . .

• The Legal Stuff– Legal requirements– Clarifying the ICO guidance on how to comply with the new

cookie law requirements– Appropriate Wording for Policies– Tips for Compliance

• What Bradford and the sector did• Good, bad and best practice and views on the Cookie

Law – discussion, sharing, venting!• What next for institutions and the sector – ideas and

suggestions

Page 4: How Bradford made friends with the Cookie Monster v0.1

John with the Legal Stuff

Page 5: How Bradford made friends with the Cookie Monster v0.1

Claire with ‘what we did’

Page 6: How Bradford made friends with the Cookie Monster v0.1

How Bradford Made Friends with the Cookie Monster

Page 7: How Bradford made friends with the Cookie Monster v0.1

What we did

• Timeline• Issues• Remaining queries• Articles and news since May 2012• Next steps

Page 8: How Bradford made friends with the Cookie Monster v0.1

• Announcement of the change in the law• 24 May 2011 - email sent to JISCMAIL list

from me

A year in the life . . .

Page 9: How Bradford made friends with the Cookie Monster v0.1

• 26 May 2011: Law changed and we had a year to comply

• May/June 2011: Draft policy online at Bradford , clearly marked draft

Page 12: How Bradford made friends with the Cookie Monster v0.1

• 26 July 2011: Session with Jason Miles-Campbell last year at IWMW. Cookies was a hot topic

Page 13: How Bradford made friends with the Cookie Monster v0.1

• August 2011 (after IWMW11): Google doc set up for the sector

Page 14: How Bradford made friends with the Cookie Monster v0.1

• November 2011: Privacy Policy on agenda of University of Bradford committee

• 13 December 2011: Half term report from ICO – must try harder

Page 15: How Bradford made friends with the Cookie Monster v0.1

• December 14 2011: Blog post for sector invite and Google doc

Page 16: How Bradford made friends with the Cookie Monster v0.1

• December 15 2011: Brian’s blog post on the Half Term Report

Page 17: How Bradford made friends with the Cookie Monster v0.1

• February 2012: Created Draft Privacy Policy for comment

Page 18: How Bradford made friends with the Cookie Monster v0.1

• Spring 2012: JISC Inform article

Page 19: How Bradford made friends with the Cookie Monster v0.1

• 25 May 2012 (later!): Updated info from ICO re: implied consent

Page 20: How Bradford made friends with the Cookie Monster v0.1

• 25 May 2012: blog post from me(updated later that day!)

Page 21: How Bradford made friends with the Cookie Monster v0.1

• 25 May 2012: Privacy Policy Amended and launched

Page 22: How Bradford made friends with the Cookie Monster v0.1

• But it’s probably a bit hidden!

Page 23: How Bradford made friends with the Cookie Monster v0.1

A novel approach!

Page 24: How Bradford made friends with the Cookie Monster v0.1

• Post-26 May Guidance– JISC podcast

Page 25: How Bradford made friends with the Cookie Monster v0.1

• Post-26 May Guidance– updated guidance from JISC Legal

Page 26: How Bradford made friends with the Cookie Monster v0.1

• Article 29 Working Party– CRITERION A: the cookie is used

“for the sole purpose of carrying out the transmission of a communication over an electronic communications network”.CRITERION B: the cookie is “strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service”

Page 27: How Bradford made friends with the Cookie Monster v0.1

Exemptions?• User-input cookies (e.g. shopping carts): probably exempt under Criterion

B (but note comments on cookie lifetime);• Authentication cookies: probably exempt under Criterion B if used within

a single browser session; need to warn the user beforehand (i.e. get implied consent) if the cookie will persist across browser sessions;

• User-centric security cookies (e.g. to detect repeated login failures): may be exempt under Criterion B, but need to check specific details;

• Multi-media Player Session Cookies: probably exempt under Criterion B, but make sure they aren’t used for other purposes;

• Load-balancing Session Cookies: probably exempt under Criterion A;• UI Customisation Cookies: short-lifetime cookies probably exempt under

Criterion B, for longer lifetimes obtain implied consent as for authentication cookies;

• Social Plug-in Sharing Cookies: may be exempt under Criterion B, but only if they are restricted to logged-in users and limited to a session;

Page 31: How Bradford made friends with the Cookie Monster v0.1

But what does the averageuser think?

Page 32: How Bradford made friends with the Cookie Monster v0.1

The results are in

Page 33: How Bradford made friends with the Cookie Monster v0.1

Next steps

• Systems and cookies audit?• Are we doing enough?• Continuous review through Committee

structure• Update the Privacy Policy Template?• Sector article on our actions to national

magazines/blogs etc? Big up the sector!

Page 35: How Bradford made friends with the Cookie Monster v0.1

Thanks – over to you for discussion, questions, sharing, venting!

Page 36: How Bradford made friends with the Cookie Monster v0.1

What should the sector do next?

Apart from go and watch the football . . .

Page 37: How Bradford made friends with the Cookie Monster v0.1

Thanks!