{"id":9071,"date":"2021-12-16T15:33:38","date_gmt":"2021-12-16T14:33:38","guid":{"rendered":"https:\/\/www.myagileprivacy.com\/the-new-cookie-law-aka-the-storm-you-dont-expect\/"},"modified":"2026-01-02T15:09:07","modified_gmt":"2026-01-02T14:09:07","slug":"the-new-cookie-law-aka-the-storm-you-dont-expect","status":"publish","type":"post","link":"https:\/\/www.myagileprivacy.com\/en\/the-new-cookie-law-aka-the-storm-you-dont-expect\/","title":{"rendered":"The new Cookie Law aka the storm you don't expect"},"content":{"rendered":"<p>All website owners\u2014whether individuals, companies, public organizations, or corporations\u2014must comply with the new guidelines from the Privacy Guarantor. This requirement applies even to inactive sites or those that haven\u2019t been updated in months or years.<\/p>\n<p><strong>What are the main changes?<\/strong><br \/>\nTo comply with GDPR principles and privacy by design, websites can no longer pre-install cookies other than strictly technical ones. <strong>All profiling cookies must be blocked by default<\/strong> and can be activated only after the user\u2019s explicit consent.<\/p>\n<p>Consent collection has also changed:<\/p>\n<ul>\n<li>Passive actions such as <strong>scrolling<\/strong> are no longer valid for consent.<\/li>\n<li>Consent must be given explicitly, either with \u201cAccept All\u201d or through <strong>granular choices<\/strong> that allow users to accept or reject each individual cookie\u2014not just whole categories like \u201cstatistics\u201d or \u201cmarketing.\u201d<\/li>\n<li>\u201cAccept All\u201d and \u201cReject All\u201d options can be used for quick choices, but there must always be a customization option.<\/li>\n<li>Users must be able to change their preferences at any time.<\/li>\n<\/ul>\n<p><strong>What are profiling and third-party cookies?<\/strong><br \/>\nProfiling cookies are used to track individuals, actions, or behavior\u2014often for marketing and measuring KPIs in campaigns, as done by Facebook, LinkedIn, or Google. Even tools such as chat, messaging, or maps may collect user data. <strong>Explicit user consent is always required.<\/strong><br \/>\n<strong>Activating cookies without user permission is a violation.<\/strong><\/p>\n<p><strong>How should the banner look?<\/strong><br \/>\nThe banner must be properly sized for the user\u2019s device, avoid hindering navigation (no \u201ccookie walls\u201d), and include:<\/p>\n<ul>\n<li>A link to extended privacy disclosures<\/li>\n<li>Buttons to accept, customize, or reject cookies<\/li>\n<li>An \u201cX\u201d button in the top right, to close the banner and explicitly refuse profiling or third-party cookies<\/li>\n<\/ul>\n<p><strong>Is a cookie consent log required?<\/strong><br \/>\nA cookie consent log is <strong>not required<\/strong>.<br \/>\nA registry typically means saving choices sequentially over time.<br \/>\nAccording to the Guarantor, you must record the user\u2019s current choice, but do not need to keep an ongoing log\u2014just ensure the user\u2019s choices are remembered for up to six months. Requests for consent should not repeat more frequently than this.<\/p>\n<p><strong>What risks do I face?<\/strong><br \/>\nRisks are significant: fines can reach \u20ac20 million or 4% of annual turnover (whichever is higher), especially for illegal data transfers or noncompliance with regulatory orders.<br \/>\nCompliance is complex. Even seemingly \u201clegitimate\u201d solutions may fall short, leading inadvertently to costly mistakes or violations.<\/p>\n<p><strong>How can you help me be compliant?<\/strong><br \/>\nWe offer a WordPress plugin, <a href=\"https:\/\/www.myagileprivacy.com\/en\/\" target=\"_blank\" rel=\"noopener\">My Agile Privacy<sup>\u00ae<\/sup><\/a>, designed to ensure compliance with these new privacy regulations.<br \/>\nKey features include:<\/p>\n<ul>\n<li>Designed specifically for <strong>European regulations<\/strong><\/li>\n<li><strong>Hosted on your own website\u2014no page view costs<\/strong><\/li>\n<li>Fully customizable to your needs<\/li>\n<li>Comes with a default <strong>cookie list<\/strong> (expandable as needed)<\/li>\n<li>You can modify the default disclosures to fit your requirements<\/li>\n<li>Fast, dedicated <strong>support<\/strong> (response within 24\/48 hours)<\/li>\n<li>Extensively tested on thousands of websites, including E-Commerce<\/li>\n<\/ul>\n<p>Try a live demo on our website or the very site you\u2019re visiting.<\/p>\n<p><strong>\"How does your plugin handle the preference log?\"<\/strong><br \/>\nOur plugin tracks user choices using a technical cookie. These are stored for six months from the user\u2019s first access or last update, then deleted\u2014no historical record is kept. The log is a current snapshot only, not a record of past choices.<\/p>\n<p>We understand <strong>there\u2019s a lot of confusion<\/strong> about this topic, and we hope this explanation provides <strong>clarity<\/strong>.<br \/>\nIf you have further questions, <a href=\"https:\/\/www.myagileprivacy.com\/en\/contact-us\/\" target=\"_blank\" rel=\"noopener\">contact us here<\/a>.<\/p>\n<p><strong>Where can I buy your software?<\/strong><br \/>\nIf you own a website, you can <a href=\"https:\/\/www.myagileprivacy.com\/en\/#section-tariffe\" target=\"_blank\" rel=\"noopener\">purchase My Agile Privacy<sup>\u00ae<\/sup> here<\/a>.<br \/>\nIf you\u2019re a web agency or privacy consultant, <a href=\"https:\/\/www.myagileprivacy.com\/en\/professional-cmp-installation\/\" target=\"_blank\" rel=\"noopener\">visit the dedicated reseller page<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>All website owners\u2014whether individuals, companies, public organizations, or corporations\u2014must comply with the new guidelines from the Privacy Guarantor. This requirement applies even to inactive sites or those that haven\u2019t been updated in months or years. What are the main changes? To comply with GDPR principles and privacy by design, websites can no longer pre-install cookies [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8719,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[75],"tags":[],"class_list":["post-9071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-updates"],"acf":{"visibilita_box_autore":false,"autore_associato":null,"elenco_faq_articolo":[{"domanda":"When did the new Privacy Authority Guidelines on cookies come into effect?","risposta":"The new Privacy Authority Guidelines have been in effect since January 9, 2022, and apply to all website owners, including private individuals, companies, and public or private entities, even if the website is no longer active or updated."},{"domanda":"How must user consent be obtained according to the new rules?","risposta":"Consent must be explicit, either through an 'Accept all' option or in a granular manner, cookie by cookie (not just by category). Consent through scrolling or passive actions is no longer valid. Users must be able to customize, accept, or reject cookies at any time."},{"domanda":"What characteristics must a cookie banner have to be compliant?","risposta":"The banner must be of adequate size without blocking navigation, contain a link to the extended privacy policy, include clear controls for acceptance, customization, and rejection, and must have an X in the top right corner to close the banner and reject profiling cookies. Without the X, the banner is not compliant."},{"domanda":"Is it mandatory to keep a record of users' cookie preferences?","risposta":"No, no cookie log is required. The Privacy Authority states that only the user's current choice needs to be stored, with no history. Consent cannot be requested within 6 months of the user's first choice."},{"domanda":"What penalties are provided for those who do not comply with cookie regulations?","risposta":"Penalties can reach up to 20 million euros or 4% of turnover, especially in cases of unlawful data transfer or non-compliance with the Privacy Authority's orders."},{"domanda":"What are profiling cookies and why do they require explicit consent?","risposta":"Profiling cookies are used to track a specific individual, action, or behavior and are used by platforms such as Facebook, LinkedIn, and Google for marketing purposes. Even free tools such as chats, messaging systems, or maps may track users. In all these cases, explicit consent is required; otherwise, it constitutes a violation."},{"domanda":"How does the My Agile Privacy\u00ae plugin work for managing cookie preferences?","risposta":"My Agile Privacy\u00ae tracks the user's choices through a technical cookie. The preference is stored for 6 months from the first access or the last update, after which it is deleted. No history of choices is retained: it is a snapshot in time, not a historical tracking record."}],"url_esterno":""},"_links":{"self":[{"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/posts\/9071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/comments?post=9071"}],"version-history":[{"count":5,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/posts\/9071\/revisions"}],"predecessor-version":[{"id":15163,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/posts\/9071\/revisions\/15163"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/media\/8719"}],"wp:attachment":[{"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/media?parent=9071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/categories?post=9071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.myagileprivacy.com\/en\/wp-json\/wp\/v2\/tags?post=9071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}