Cookie scrutiny, third-party cookie demise, ePrivacy Regulation
Last reviewed:
Cookie consent has drawn heavy regulatory fire: Privacy International (2019), NOYB's 422 complaints (2021), and in January 2022 France's CNIL fined firms €210 million over non-compliant cookie consent. Browsers are restricting third-party cookies (Google's Privacy Sandbox; Safari blocks them by default). A proposed ePrivacy Regulation would replace the Directive, broaden what needs consent, raise fines and harmonise rules across the EU - but it is not yet agreed.
| Development | Detail |
|---|---|
| NOYB complaints (2021) | 422 complaints to ten European DPAs over cookie consent mechanisms |
| CNIL fines (Jan 2022) | Totalling €210 million for cookie consent failures |
| Privacy Sandbox | Google's Chrome plan to replace third-party-cookie tracking |
| Safari | Already blocks all third-party cookies by default |
| ePrivacy Regulation | Would replace the Directive: broader consent scope, higher fines, harmonisation - not yet agreed |
The ePrivacy Regulation would be a regulation, giving greater harmonisation than the patchwork of national implementations of the Directive. Once finalised it won't be directly applicable in the UK, but UK organisations targeting EU individuals would still likely need to comply.
Key terms - quick answers
What is “CNIL”?
What is “Privacy Sandbox”?
What is “ePrivacy Regulation”?
Keep going - free
Every study note on this site is free. So are these: