Currently there are two trends on cookie consent banner design – either (1) the “Accept All” and “Reject All” options are shown in the first layer of a cookie consent management solution, or (2) only the “Accept All” option is shown in the first layer together with a link to the second layer of the cookie consent management solution where the user can reject to the use of non-essential cookies. There is more clarity on the views of the UK data protection authority on whether a “Reject All” option in the first layer of a cookie consent management solution is required.

Continue Reading “Reject All” button in cookie consent banners – An update from the UK and the EU

On 3 October 2023, the UK Information Commissioner’s Office organised its annual Data Protection Practioner’s Conference 2023 (DPPC 2023). This year its focus was on Cybersecurity – a topic that concerns organisations across the board. Here are the takeaways from the DPPC 2023 (the event sessions available here).

Continue Reading The UK Information Commissioner’s Data Protection Practioner’s Conference 2023 on Cybersecurity

On 3 October 2023, the Information Commissioner’s Office (ICO) published guidance (the Guidance) on lawful monitoring in the workplace. The Guidance provides advice to companies to help them comply with their obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) when monitoring anyone who performs work on their behalf. This is not limited to employees and could include monitoring of workers or those who are self-employed.

Continue Reading UK Workplace monitoring – are you compliant?

On 19 September, the Department for Science, Innovation and Technology (DSIT) announced in a press release that it is to launch a pilot advisory service next year, called the DRCF AI and Digital Hub.

This service will be operated by members of the Digital Regulation Cooperation Forum (DRCF), made up of the Information Commissioner’s Office (ICO), the Office of Communications (Ofcom), the Competition and Markets Authority (CMA) and the Financial Conduct Authority (FCA).

The DRCF AI and Digital Hub will provide businesses with tailored advice and support regarding how to meet requirements across multiple regulatory regimes. The DSIT anticipates that this service will expedite the process of getting new products and innovations to market, in a safe and responsible manner.

As such, the launch of the DRCF AI and Digital Hub will likely be welcome news for businesses across the UK, providing companies and innovators with the tools to navigate a challenging and multi-layered regulatory environment.

Continue Reading DRCF to launch AI and Digital Hub regulatory advice pilot in 2024

Further to the joint announcement in June by UK Secretary of State for Science, Innovation, and Technology and the US Commerce Secretary of their intention to create a UK-US data bridge (please see our blog for further details), the UK government has passed a Regulation establishing a UK-US data bridge. The data bridge comes in the form of an extension to the EU-US Data Bridge Privacy Framework (the DPF) and will come into force on 12 October.

Continue Reading UK government announces a UK data bridge with the US

On 11 September 2023, the UK’s Department for Science, Innovation, and Technology (DSIT), published the draft Data Protection (Fundamental Rights and Freedoms) (Amendment) Regulations 2023 (DP Regulations), which seek to amend the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 (DPA 2018).

Continue Reading DSIT publishes draft amendments to the UK GDPR and DPA 2018

On 12 September 2023, the UK Information Commissioner and the Chief Executive of the National Cyber Security Centre (NCSC), signed a joint Memorandum of Understanding (MoU), which establishes how the NCSC and the Information Commissioner’s Office (ICO) will cooperate. The NCSC is the technical authority in the UK that provides standards and guidance to organisations on cyber security. The ICO is responsible for providing guidance and enforcement of the data protection rules in the UK, including the obligation of organisations to apply security measures around personal data.

Continue Reading Boosting digital resilience – The UK Information Commissioner and NCSC CEO sign Memorandum of Understanding

On August 18, 2023, the Fourth Circuit decertified approximately 20 million putative class action claims arising out of a 2018 data breach involving Marriott Hotels. See here. The Fourth Circuit reversed the district court’s certification and required it to consider in the first instance whether all of the putative plaintiffs waived their claims by signing class action waivers when they registered to be part of the Starwood Preferred Guest Program (“SPG”). The SPG waiver specifically stated that “Any disputes arising out of or related to the SPG Program or the[] SPG Program Terms will be handled individually without any class action ….”

Continue Reading Fourth Circuit Decision Highlights Class Action Waivers for Data Breaches are Alive and Well

The House of Commons Committee on Science, Innovation and Technology (the Committee), embarked on an inquiry in October 2022 to assess the impact of artificial intelligence (AI) on various sectors, AI regulation, and the UK Government’s AI governance proposals. The resulting interim report, published on 31 August 2023, offers valuable insights, particularly from a legal standpoint, on the challenges and approaches related to AI governance in the UK.

Continue Reading AI, a Double-Edged Sword: Recommendations from the Committee’s Interim Report on AI

On 9 August 2023, the Information Commissioner’s Office (ICO) and the Competition and Markets Authority (CMA) published a joint position paper on Harmful Design in Digital Markets (Harmful Designs Paper) that urges businesses to stop using harmful website designs that exploit customers by encouraging them to provide more personal data than necessary. The regulators are calling for businesses to embrace fair and transparent practices, providing users with increased control over their data, and warning that failure to comply could lead to formal enforcement actions.

The Concerning Landscape: Tricky Design Practices

The position paper centres on the way information regarding choice and consent is presented to customers, known as “Online Choice Architecture” (OCA). The ICO and CMA have raised red flags website design practices that compromise user privacy and manipulate their choices. Some examples of harmful designs include:

  1. Harmful Nudges and Sludge: Subtle manipulations that steer users away from privacy-friendly choices. For example, prioritizing one option to be significantly quicker than a time-consuming alternative. The ICO emphasizes that this may infringe upon the “fairness” and “transparency” principles of the GDPR, potentially rendering the collected consent legally non-compliant.
  2. Confirmshaming: Design elements that pressure users into specific choices, such as requesting customer details and consent for marketing in exchange for a discount. The ICO notes that consent obtained through this method might not be considered truly “freely given”. A specific example of this, as recently highlighted by an IOC representative, is failing to include a “reject all” button on cookie consent banners (see here for our blog on this).
  3. Biased Framing: Presenting choices in a manner that steers users toward certain outcomes, heavily favoring one option while downplaying risks. This approach prevents users from making informed decisions.
  4. Bundled Consent: Forcing users to accept multiple services simultaneously, such as cookies, marketing, and account settings, with the provision that individual consents can be adjusted later in account settings.
  5. Default Settings: Designing interfaces that prioritize certain choices as default, influencing user decisions and making it unclear how to choose different options.

Meeting Regulators Expectations

In the Harmful Designs Paper, the ICO and CMA suggest that the primary focus for website design is a user-centred approach that empowers individuals to make well-informed choices and feel in control. Before launching any website, companies are advised to rigorously test and refine their designs and to adhere to the fundamental principles of data protection, consumer rights, and fair competition.

Looking Ahead: Education and Enforcement

As part of their mission, the CMA will expand its Rip Off Tip Off campaign that encourages consumers to report deceitful online sales tactics. This educational initiative aims to raise awareness among users and encourage them to report misleading practices. Simultaneously, the ICO will continue to enforce data protection rights, particularly for vulnerable individuals at risk of harm. With the CMA and ICO focussed on website design and fairness to consumers, it is likely that there will be increased enforcement. The ICO and CMA expect that the position paper will drive businesses to revaluate their website practices to make sure they are compliant with the current laws.

Takeaway
If companies are unsure about whether their website contains harmful designs that don’t respect the fundamental principles of data protection, consumer rights or fair competition, it’s time to think about carrying out an assessment of website design and its operation.