Table of Contents
1.Definitions
1.1. Cookies
A cookie is a small text file that is stored on the user's computer or mobile device while the user accesses a website. With each subsequent visit, cookies are sent back to the website's data controller from which they originated, or to a third party.

Cookies thus function as the memory of a given website, allowing the site to remember data regarding the user's computer or mobile device during subsequent visits, including information about user settings or data that facilitate the use of the site. This also applies to Internet of Things (IoT) devices that connect to the Internet.
1.2. Data Controller
A data controller is a natural or legal person, public authority, agency, or other entity that alone or jointly with others determines the purposes and means of processing personal data.
The website may contain both cookies belonging to the data controller and those belonging to third parties.
It should be noted that cookies may be used not only by the owner of the website but also by other entities if the website owner has permitted the use of third-party cookies. Consequently, the website owner does not have to be the data controller of personal data processed through cookies.
1.3. Subscriber Device and End User Devices
This refers to a device through which users can access all services and obtain information, e.g., personal computer, smartphone, tablet, etc.
1.4. Technologies Similar to Cookies
As a rule, methods of tracking and remembering choices made by users on a website are based on cookies. However, cookies are just one of the ways to track users; there are other similar technologies.
Example:
• A tracking pixel (also known as a 1x1 pixel or pixel tag) is usually a transparent graphic image, measuring 1 x 1 pixel, placed on a website or in an email, which is used to track navigation and "paths" of user traffic on one or several websites. This technology is often used in conjunction with cookies. Tracking pixels are typically utilized by platforms that provide monitoring and tracking services for user traffic, for example, to check whether and when an email has been opened by the recipient. A tracking pixel can help collect information such as: the IP address of the computer, the URL of the page visited by the user, the URL of the page from which the user arrived, the display time, the content of the cookie, or the type of browser used to visit the page.
• A commonly used tracking method is the collection of device and browser fingerprints. Fingerprinting allows for the identification of a unique device by gathering information stored in locally installed applications. Information stored by local applications may include unique identifiers, such as MAC addresses and serial numbers, which enable the identification of users. This technology allows for user identification even if cookies are disabled or deleted.
Browser fingerprints consist of a large amount of diverse information that is unique to each web browser. Furthermore, this technology can collect information about browser plugins and extensions, browsing history, and hardware properties.
This guidance focuses on cookies; however, Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 on the processing of personal data and the protection of privacy in the electronic communications sector (the ePrivacy Directive) and the draft Regulation of the European Parliament and of the Council on privacy and the protection of personal data in the electronic communications sector, repealing Directive 2002/58/EC (the ePrivacy Regulation) apply to anyone who stores information on the end-user's device.
This means that the specified regulations apply to all similar technologies used for tracking end devices (laptops, smartphones, tablets, smart TVs, and others). At the same time, it should be noted that the draft regulation on privacy and electronic communications encompasses both the processing and storage of data on users' end devices, as well as the collection of information from these end devices, thereby including types of tracking technologies that may extend beyond the concept of cookies.
1.5. Website
Websites are based on HTML/XHTML files accessible via the Internet through the http protocol. Virtually every company or non-governmental organization currently has its own website, where information about its activities can be found or services can be ordered. Cookies are traditionally associated with websites, but they are also used on other types of platforms and in applications (e.g., applications for smartphones and tablets). In these guidelines, the term “website” refers to all possible environments in which cookies are used.
1.6. Information Society Services
A service provided at a distance (the parties do not meet physically) is typically provided for a fee, using information and communication technology systems (through digital data processing) and at the individual request of the service recipient. Information society services include e-commerce of goods and services, sending commercial information, offering tools for searching, accessing, and retrieving information, services that ensure the transmission or access to information via telecommunication networks, information storage, and online intermediary services1.
2.Regulations Governing the Use of Cookies
The use of cookies is subject to the following legal acts: the Latvian Law on Information Society Services (in Poland, this will be the Act of July 16, 2004, Telecommunications Law), which was adopted to transpose the Directive on Privacy and Electronic Communications and the General Data Protection Regulation (“GDPR”). The interrelationship between the Directive on Privacy and Electronic Communications and the GDPR has been thoroughly analyzed by the European Data Protection Board in Opinion No. 5/2019 of March 12, 2019, regarding the interdependence between the Directive on Privacy and Electronic Communications and the GDPR - particularly concerning the competencies, tasks, and powers of data protection authorities ("Opinion"). The Opinion clarifies that although the substantive scope of the two legal acts is different, there are areas where the GDPR and the Directive on Privacy and Electronic Communications overlap.
One such area is the use of cookies, as indicated in paragraph 29 of the Opinion. According to the case law of the European Union, there may be situations where data processing falls under both the Directive on Privacy and Electronic Communications and the GDPR. Consequently, the use of cookies on websites requires compliance with both the Latvian Law on Information Society Services (in Poland - the Telecommunications Law) and the GDPR.
It is also important to consider the relationship between the aforementioned legal acts, as mentioned in Article 95 of the GDPR and in Recital 173, which confirms the relationship between general law (GDPR) and specific law (the Latvian Law on Information Society Services or the Polish Telecommunications Law).
A particularly important aspect of applying these legal acts concerns the definition of "consent." Article 2 lit. f) of the Directive on Privacy and Electronic Communications states that the "consent" of the user or subscriber corresponds to the consent of the data subject as described in Directive 95/46/EC. Recital 17 of the Directive on Privacy and Electronic Communications explains that "For the purposes of this Directive, the concept of consent of the user or subscriber should have the same meaning as the consent of the data subject described and more broadly defined in Directive 95/46/EC". Consent can be expressed in any manner that allows the user to freely express a specific and informed will, including by ticking a checkbox on a website.
Considering that Article 94 of the GDPR states that references to the repealed Directive 95/46/EC should be understood as references to this Regulation, it is considered that the concept of "consent" in the context of the provisions transposing the Directive on Privacy and Electronic Communications is analogous to the concept of "consent" defined in Article 4(11) of the GDPR. According to Article 4(11) of the GDPR, the "consent" of the data subject means a voluntary, specific, informed, and unambiguous indication of the data subject's wishes, by which the data subject, by means of a statement or a clear affirmative action, consents to the processing of personal data concerning them. Consent must therefore be expressed by means of a clear affirmative action, which means a voluntary, specific, informed, and unambiguous indication by the data subject of their consent to the processing of personal data concerning them, for example, in written, electronic, or oral form.
3. Cookies - Application
3.1. Functions of Cookies
Cookies serve many important functions, including storing information about the user and their previous actions on the website. The information stored in cookies may include personal data such as IP address, username, unique identifier, or email address. Cookies also contain information about language settings, data about the type of device that the user is using to view the site, as well as user identifiers, advertising identifiers, and others, depending on the tracking technology used.
Cookies can be used, for example, to track online activity, to track information entered into an online application form, to identify the user when registering for banking or using other online services, as well as to assist in loading web pages or speeding up information transmission over the network.
There are no stupid GDPR questions.
There are free answers
3.2. Categories of cookies by management structure
Depending on the organization that manages the server or domain from which cookies are sent and subsequently processes the collected data, the following categories of cookies can be distinguished:
- first-party cookies: these are cookies created by the service provider; sent by the service provider through its domain;
- third-party cookies: these are cookies created by other service providers (third parties); sent from domains that are not managed by the service provider itself; any data collected via cookies is processed by the third party.
If cookies are sent from a domain managed by the service provider, but the information from the cookies is processed by a third party, they should be treated as third-party cookies. For example, if a user watches a video from the Youtube service on the website of a Polish company, the cookies used by the Youtube service to access the video will be considered third-party cookies, and the Youtube service will be the data controller.
3.3. Categories of cookies based on their purpose
Categories of cookies based on the purpose for which they are collected:
- technical cookies, also known as essential or functional cookies, which enable the user to browse the website, platform, or application and use the features contained in these services. These are cookies used to operate and manage the website, enabling the execution of functions such as controlling traffic and communication, identifying sessions, saving items added to the cart, processing payments, managing payments, detecting and preventing fraud, logging events, completing registration forms, counting visits for the purpose of charging software licensing fees.
These cookies enable the use of the service (website, platform, or application), ensure security during usage, add content to video or audio streams, as well as allow the transmission of dynamic content (such as animated text or images) or sharing content on social media.
Due to the technical nature of these cookies, this category also includes cookies that allow for the most effective management of advertising space, which are implemented as an integral part of the website, platform, or application, provided that user information is not collected for other purposes, such as personalization and content customization.
Technical cookies do not require consent for their use on the website, even in the case of storing information on the end device or accessing information stored on the end device. They are essential for the flow of information through the telecommunications network or for the service provider to deliver a service at the request of the subscriber or user.
Technical cookies do not require consent for their use on the website, as they are responsible for services directly required by users (e.g., the selection of language made by clicking in the appropriate section of the site), provided that these cookies are used solely for this purpose.
- Analytical cookies allow the data controller to track and analyze user behavior on websites. This category includes cookies used by advertisers to track user habits related to browsing the website, enabling advertisers to tailor advertisements to the user's interests. Cookies that allow for the collection of statistical information regarding individuals visiting the website are also considered analytical cookies.
In general, any information obtained through this type of cookies is used to assess the performance of any website, application, or platform in order to implement improvements based on the analysis of data regarding the use of services provided to users.
In order to process analytical cookies, user consent must be obtained in accordance with Article 7 paragraph 1 of the Latvian Law on Information Society Services (Article 173 paragraph 2 of the Telecommunications Law). Before obtaining consent, the user must receive clear and comprehensive information regarding the purposes for which analytical cookies are used (Article 173 paragraph 1 of the Telecommunications Law).
In the performance of their tasks, public authorities are prohibited from processing analytical cookies for marketing purposes, as the legislator determines the legal basis for the processing of personal data by public authorities (as stated in Recital 47 of the GDPR).
It should be noted that the categories of cookies mentioned above do not constitute a closed set. Service providers and third parties may adopt different classifications that better reflect the purposes of using cookies, provided that the principle of transparency for users is respected.
3.4. Types of cookies based on their storage method
Depending on the duration for which a cookie is stored on end devices, the following categories can be distinguished:
- Session cookies or temporary cookies: these are used to collect and store data while the user is accessing the website. Each session cookie will exist only for the duration of the browser session, after which it will be deleted. Each browser session begins when a browser window is opened and ends when it is closed. Session cookies are used to store information that is relevant only for providing services required by users in a specific situation (e.g., a list of products in the cart or information about the user's journey), and which should disappear after the session is closed.
- Persistent cookies: these allow for the retention of user settings or actions on one page or across different pages. They have a longer lifespan than session cookies and operate for the period specified in the cookie (ranging from a few minutes to several years, depending on the purpose of using the cookie). This type of cookie will not be deleted after the browser window is closed and will be stored on the user's device. The cookie will be activated each time the user visits the page where the persistent cookie was created.
Subject to the limitations regarding data minimization and retention, cookies may not be stored longer than is necessary to achieve their purpose.
4. Conditions for the use of cookies on the website
Article 7 paragraph 1 of the Latvian Law on Information Society Services states that cookies may only be used after obtaining the consent of the subscriber or user (Article 173 paragraph 1 of the Telecommunications Law). Paragraph 2 (Article 173 paragraph 3 of the Telecommunications Law) of the same article provides an exception to the general requirement for consent, excluding from this requirement the use of cookies that are necessary for the flow of information in telecommunication networks or for providing a service at the request of the subscriber or user. This classification is consistent with the aforementioned division of cookies into technical and analytical categories. Technical cookies do not require consent. The use of analytical cookies requires prior consent before their processing. In the case of personalized cookies, to the extent that these cookies record choices made by the user regarding the functions of the website (for example, the choice of the website's language), it can be considered that the user has expressed consent for the use of these cookies through their active behavior.
The Latvian Law on Information Society Services requires that before using any cookies (including technical cookies), the user receives comprehensive and clear information about the intended actions. It should be noted that according to the GDPR, one of the key issues to consider when obtaining consent is to provide the website user with the necessary information about the planned processing of personal data. These two aspects (obtaining appropriate consent and providing necessary information) will be explained in this section of the guidelines.
4.1. Clear and comprehensive information
Article 7 paragraph 1 of the Latvian Law on Information Society Services (Article 173 paragraph 1 of the Telecommunications Law) states that clear and comprehensive information must be provided regarding the purpose of processing personal data (the use of cookies), in accordance with the provisions concerning the protection of personal data, according to which personal data should be processed in a manner that is transparent to the subscriber or user.
4.1.1. Clear information
The requirement for clear information includes the following conditions: a) the information is concise and easy to understand; b) the language used is simple and easy to understand, avoiding misleading statements or expressions that would hinder the understanding of the information; c) the information is presented in a transparent manner.
4.1.1.1. Concise and easy to understand information
Information should be concise and easy to understand. Unnecessary content that could distract users or cause "information overload" should be avoided. By easy-to-understand information, we mean information that is comprehensible to the average user of the website. The knowledge of the average user regarding the use and management of cookies should always be taken into account. The lower the technical level of the average user of a given website, the simpler the language used should be (technical terms that may be difficult to understand and assimilate should be avoided).
The service provider (data controller) should know the target group, including the approximate age of the group to which the service is offered. Information about the target group should be used to select the language that is most appropriate for that group. For example, a marketer offering IT security training on a website may assume that their target group understands the issues related to cookies better than a group of recipients to whom they offer the purchase of toys for children.
4.1.1.2. The language used is simple and easy to understand
The requirement to use simple and easy-to-understand language means that information should be presented in the simplest possible way, avoiding complicated sentences and linguistic constructions2. Information should be specific and definitive; it should not be abstract or ambiguous, and it should not leave room for interpretation. In particular, the purposes and legal basis for the processing of personal data should be clear. Individual paragraphs and sentences should be correctly constructed. Key information may be emphasized with varying degrees of emphasis. Information provided to the user should not contain an excessive amount of technical language, including legal or technical terminology.
Example of bad practice
"We may use users' personal data to offer personalized services."
(The information provided does not clearly indicate what "personalization" means).
Example of good practice
"We will store your purchase history and use information about the products you have previously purchased to recommend other products that we believe may interest you".
(It is clear what types of data will be processed, as well as the purpose of their use, which is to display targeted advertising to the data subject.)
It is advisable to avoid using terms such as "may," "could," "some," "often," and "probably." In cases where data controllers (service providers) use imprecise terms, the principle of accountability requires them to demonstrate why such language is unavoidable.
4.1.1.3. Transparent presentation of information
Considering the amount of information that needs to be provided to the user, data controllers may adopt a layered approach to transparency. A layered information obligation regarding cookies can help address the issue of "information overload," while also allowing users to directly access the part of the information they wish to review.
The layered content of the information obligation regarding cookies allows for the linking of different categories of information that must be communicated under the principle of transparency. This way, instead of displaying all cookie information in one place on the device screen, it is possible to divide the content into separate sections, thereby avoiding the problem of "information overload."
Regardless of the above, all information should be easily accessible in one section of the website or in one document, in case users wish to review the complete information about cookies. It should be noted that using a layered system is not necessary for the information to be presented transparently. Data controllers may choose any other method of presenting information that complies with the principle of transparency.
The first layer should allow the user to familiarize themselves with the available information regarding the processing of their personal data and indicate where more detailed information about cookies can be found.
The first layer of the information obligation should include the following information:
- Data identifying the data controller. If this information is provided in other sections of the site (e.g., in the "About Us," "Contact," etc. sections), identifying the data controller in the first layer is not necessary. Similarly, if the identity of the data controller can be clearly inferred from the domain address (the domain name is the same as the name or trademark under which the data controller is known to the public, or this information is clearly indicated on the website), then providing the data controller's information in the first layer of the information obligation is not necessary.
- The purposes for which cookies are used on the site.
Migrations, clouds, systems.
GDPR in IT.
- Information on whether the cookies belong to the first party (data controller) or are third-party cookies.
- General information about the types of data that are collected and used during user profiling (e.g., when using analytical cookies).
- The manner in which users can accept and reject cookies, as well as manage their choices.
- A clearly visible link to the second layer of the information obligation, which contains more detailed information, e.g., "Cookie Policy" or "Click here for more information." The same link may serve to redirect users to the cookie management panel (users should not have to browse the second layer of information to find such a panel).
The above information must be provided before the use of the cookie, in a manner visible to users, until the user gives consent or decides to refuse.
Example:
„We use our own and third-party cookies to store the user's purchase history and to utilize information about previously purchased products to recommend other products that we believe may interest the user. To learn more about our cookie policy, click the "More Information" button. The user can accept all cookies by pressing the "Accept" button, or reject cookies by pressing the "I Do Not Agree" button. If the user presses the "I Do Not Agree" button, only technical cookies, which are necessary for the functioning of the website, will be saved; the use of such cookies does not require the user's consent.”
If the user does not press the "I Agree" button, the use of cookies (other than technical) will not be permitted. This means that if the user continues browsing the site without clicking the "I Agree" button, the use of cookies requiring consent is not allowed.
The information contained in the second layer of the information obligation should be continuously available on the website or in the application. The second layer should include the information specified in subsection 4.1.2 of these guidelines.
4.1.2. Comprehensive Information
Comprehensive information about cookies should be understood as that which enables users to understand the intended purposes and manner of application of cookies. For this reason, the cookie policy should include at least the following information:
- Definition and explanation of the general function of cookies
Example:
What is a cookie: This site uses cookies and/or other similar technologies that serve to collect and store information. Each specific cookie is used for a specific purpose or purposes, such as identifying the user, obtaining information on how websites are used, or personalizing the content displayed. Below are the specific applications of these technologies.
- Information about the types of cookies used and their purposes.
Example:
• Technical cookies: allow the user to browse the website, platform, or application and use the features contained in these services. These are cookies used to operate and manage the website and enable the use of services offered by the features of this site.
• Personalized cookies: allow for the retention of information, enabling users to use the service under specific conditions tailored to their needs, such as language preferences, the number of search results displayed, the appearance or content of the service depending on the browser used and the availability of information in a given region, etc.
• Analytical cookies: allow the cookie administrator to track and analyze user behavior on websites. Any information obtained through such cookies is used to assess the performance of the website, application, or platform in order to implement improvements to the services provided to users.
- Cookie recipients must be identified
Users must be able to identify the data controller(s) processing their data, including joint controllers, before giving consent or refusal. For this purpose, information about the controllers can be collected in the form of a list, allowing users to familiarize themselves with the list as part of the information provided in the first layer of the information obligation.
We recommend using descriptive titles and clear terms, such as "list of companies that use cookies on our website/application." The list should be easily accessible to users at any time, regardless of whether the processing concerns a website or a mobile application. The list of new controllers should be placed in a prominent location on the screen that attracts users' attention or in a place where users can easily find it.
The user must be informed who will process the information obtained through individual cookies - the first party (service provider) or third parties.
Example:
Third-party cookies:
Analytical cookies allow the cookie administrator to track and analyze user behavior on websites. Any information obtained through this type of cookie is used to assess the performance of the website, application, or platform in order to implement improvements to the services provided to users.
If the service provider is unable to sufficiently explain the purpose of using cookies by third parties, information can be indicated via a link to the third party's website. A solution to this issue may also be Consent Management Platforms (CMP) that comply with the GDPR.
- Information on how to give consent, refuse, or withdraw consent for the use of cookies
Information explaining how to provide consent for cookies should be indicated.
Example:
We use various types of cookies placed by default (e.g., "necessary" cookies), but for some cookies, such as those used for analytical purposes, we ask for the user's consent for their use. By making a selection by pressing the appropriate button on the cookie bar that appears when visiting the site, the user decides whether to allow the use of specific categories of cookies. If you click the "I agree" option, it will mean that you accept all cookies placed on the website.
How to withdraw consent.
Example:
The user can withdraw their consent regarding cookies at any time and refuse their use. The user can reject all cookies except for "necessary" cookies. If you wish to withdraw your consent for analytical and marketing cookies, press the button: Withdraw consent.
Information on the consequences of the user's refusal to accept cookies.
Example:
By clicking the "I do not agree" button, the user opts out of analytical and marketing cookies on the website; however, technical cookies that are necessary for the functioning of the site will still be stored and do not require the user's consent.
Closing the cookie consent pop-up means that the user has not made a choice regarding the use of cookies on the website. In this case, the site cannot use cookies that require consent until the user's consent for their use is obtained. This does not apply to cookies for which consent is not required.
- Information on the retention period of cookies
This applies to cookies belonging to the data controller and third parties. If it is not possible to specify the retention period of cookies accurately, criteria should be provided to determine this period.
Example:
• First-party cookie will be deleted after closing the browser window.
• Third-party cookies will be deleted after 3 months.
- Where applicable, information that the data controller intends to transfer personal data to a third country or an international organization.
According to the GDPR, individuals must be informed whether there is a decision by the European Commission determining an adequate level of protection or another basis for the transfer of personal data to a third country under Article 46 of the GDPR or Article 47. In the case of transfers referred to in Article 49(1), and in the case of transfers referred to in Article 49(1) second paragraph, the information obligation must include a reference to the relevant safeguards and information on how to obtain a copy of the data or information on where the data is available.
Example:
It should be noted that the cookie "bcd" sends information to third countries for processing by a third party for marketing purposes (see the "Third-Party Cookies" section in the Cookie Policy).
- Information on profiling, if profiling involves automated decision-making that may have a significant impact on users.
Depending on the circumstances, significant effects for the user should be taken into account, including:
- the degree of invasiveness of the profiling process, including tracking individuals across different websites, devices, and services;
- the expectations and preferences of individuals using the services;
- the manner of presenting information;
- the use of information about the individuals whose data is being processed.
According to the GDPR, essential information regarding the principles of profiling, as well as the significance of such operations and the anticipated consequences for users, must be provided.
In the absence of the above factors, delivering targeted advertising based on profiling will not lead to a significant impact on the users of the site, e.g., an online clothing store using advertising based on a simple demographic profile: "women aged 25-35 living in Riga may be interested in fashion or a specific type of clothing."
4.2. Consent
Consent is a voluntary, specific, informed, and unambiguous expression of the will of the data subject (user), through which the individual, by means of a statement or a clear affirmative action, consents to the processing of their personal data.
4.2.1. Voluntary expression of consent
The element of "voluntarily expressed" consent means a real choice regarding cookies, without the risk of negative consequences. The website must provide the user with the option to choose "Accept" or "Do not accept" cookies in the first information banner, as well as indicate where in the "More information" section additional information about the cookies used on the website can be found.
Example of bad practice
This site uses cookies. By continuing to use this site, you consent to our use of cookies.
Example of good practice
We use our own and third-party cookies to store the user's purchase history and to utilize information about previously purchased products to recommend other products that we believe may interest the user. Click the "HERE" button to review our privacy policy regarding cookies. The user can consent to all cookies by pressing the "I Agree" button or reject them by pressing the "Leave technical cookies" button, or set a preferred configuration by pressing the "HERE" button.
If the user selects the "I Agree" option, it means that they consent to all cookies placed on the website. If the user selects the "Leave technical cookies" option, they reject all cookies that require the user's consent, which also means the continued use of technical cookies that enable the website to function.
Instead of the term “technical cookies,” other names such as "essential cookies" or "functional cookies" are permissible.
Example of good practice
We use our own and third-party cookies to store the user's purchase history and to utilize information about previously purchased products to recommend other products that we believe may interest the user. To learn more about our cookie policy, click the "More Information" button. The user can accept all cookies by pressing the "Accept" button or reject them by pressing the "I Do Not Agree" button. If a user clicks the "I Do Not Agree" button, only technical cookies that are necessary for the functioning of the site and do not require the user's consent will be used on the website.
If the user selects the "I Agree" option, it means that they consent to all cookies placed on the website.
If the user selects the "I Do Not Agree" option, it means that they do not consent to all cookies that require the user's consent.
If the user selects the "More Information" option, it means that they will be redirected to a section where they can familiarize themselves with the data controller's cookie policy and make an informed choice regarding all cookies for which consent is required.
The fact that a user decides to close the cookie consent pop-up (e.g., by clicking the "X" option) cannot be considered as consent. Clicking the "X" closes the information window and does not provide the user with the option to choose "I agree" or "I do not agree" to cookies, and consequently does not allow the use of cookies on the website that require consent.
Consent will only be valid if the user has a free choice regarding the individual cookies used on the website. This means that the website must allow the user to freely choose between: 1) the option to accept all or some cookies; 2) the option to reject all or some cookies; 3) and the possibility to change cookie settings in the future.
Regardless of whether the user decides to reject all or only some cookies, the choice made must not have negative consequences for the user - for example, in the form of a prohibition on further browsing the site or a specific part of it (e.g., in the case of a website used for e-commerce, whose main purpose is to sell products, the ability to purchase products cannot be conditioned on the acceptance of analytical cookies).
4.2.2. Specific Consent
The specific nature of consent requires the specification of particular purposes for which personal data is processed. Furthermore, the processed data must be adequate, relevant, and not excessive in relation to the purposes for which it was collected and/or is further processed.
This means that in cases where achieving the purpose of providing an online service does not require the use of a specific type of cookie, there is no need to use those cookies on that site.
This also means that consent does not need to be sought for each cookie, but rather for each of the purposes for which these cookies are used. If a cookie is used for more than one purpose, consent must be obtained for each of those purposes separately.
4.2.3. Informed Consent
The "informed" nature of consent means that providing information on the website is essential - prior to obtaining consent, in order to enable the user to make an informed decision, including understanding what they are consenting to.
This means that the website must provide the user with the ability to give consent, and before informing the user about the use of cookies and obtaining the user's consent, no cookies (other than those that do not require consent) may be placed on the user's device.
On the initial part of the website, where the user begins their browsing session, a clear and explicit statement regarding the use of cookies must be included, along with a request for consent. Upon entering the website, users should have access to all necessary information about the types of cookies used on the site and information about the purposes for which the data collected through cookies will be used. It is good practice to provide a link to a section where information about all cookies used on the site can be read.
In subsection 4.1.1.3 "Transparent Presentation of Information" of these guidelines, the information that should be provided to the website user to meet the requirement of "informed consent" is indicated.
If the data controller does not provide the required information and/or uses cookies before providing the required information, the consent will be an invalid basis for data processing, as the user's control will become illusory.
4.2.4. Explicit Consent
The "explicit" nature of consent means that consent must be clearly given through an active action by the user, which confirms that the user agrees to the use of cookies. It should be clearly defined what actions signify consent to cookies. It must be ensured that the choice expressed through an active action is indeed based on clear information that this action will result in the use of cookies.
E-learning GDPR is now standard!
Moreover, clicking on the "more information about cookies" link cannot be considered as giving consent, as in such a case the user is merely requesting additional information. The absence of any action also cannot be regarded as valid consent.
Consent is necessary for cookies to be processed on the website (see subsection 4.1.1.3 of the Guidelines).
There are various tools and methods for obtaining consent. The choice of the most appropriate one requires consideration of the type of cookies used, their purpose, and whether they are first-party or third-party cookies.
4.3. Consent Management Tools (CMP)
The following methods are available for expressing consent (the list is not exhaustive):
- During the website or application setup process
Many websites and smartphone applications allow users to choose settings, such as language, font, background color, etc. Depending on the specific features of the application, users may be asked to allow access to information on their smartphone (e.g., access to contacts to recommend the application to friends, or access to the photo album). During this process, users may also give consent for cookies to be used for a specific purpose. In this case, consent is integrated with other user settings.
- Through a Consent Management Platform (CMP)
The Consent Management Platform is a tool that provides comprehensive management of cookies on a website. There are various platforms that allow for the management of how consent is obtained. Some of them are integrated with a Tag Management System (TMS). A Tag Management System (TMS) is software used to manage marketing tags attached to URLs in certain online processes and e-commerce sites. The Tag Management System simplifies the handling of digital marketing tags related to various advertising outcomes.
Before selecting one of the platforms, it is essential to ensure that the chosen solution complies with the requirements of the GDPR regarding the principles of transparency and consent.
- Obtaining consent before offering a service or application that requires downloading files (e.g., videos, images, or games)
In such cases, users should be allowed to express their consent to the use of cookies before downloading the service or application. Users should be adequately informed that downloading the service or application requires them to consent to the use of cookies for a specified purpose.
If cookies are processed by third parties, to enable users to make an informed decision, they should be informed about this, along with the purposes of processing by these entities.
- Layered information obligation
In a layered information model, the first layer of information is presented in a window that appears when the user enters the website. The first layer contains a request for consent to use cookies, as well as often a link to the second layer, which contains additional information about cookies.
When using a pop-up window containing the first layer of information, it should not present content that "encourages" the user to accept cookies instead of rejecting them. Therefore, if a "Accept" button is placed in the pop-up window, a "Reject" button should also be included in the same pop-up window, allowing the user to refuse consent to the use of cookies. The individual buttons should have the same color and should not differ in terms of underline, font, or colored fill.
Example of bad practice
We use our own and third-party cookies to store the user's purchase history and to utilize information about previously purchased products to recommend other products that we believe may interest the user. To learn more about our cookie policy, please click the "More information" button. The user can accept all cookies by clicking the "Accept" button or reject them by clicking the "I do not agree" button. If the user clicks the "I do not agree" button, technical cookies that are necessary for the functioning of the website will still be saved and do not require the user's consent.
More information I do not agree I agree
Example of good practice
We use our own and third-party cookies to store the user's purchase history and to utilize information about previously purchased products to recommend other products that we believe may interest the user. To learn more about our cookie policy, please click the “More information” button. The user can accept all cookies by clicking the “Accept” button or reject them by clicking the “I do not agree” button. If the user clicks the “I do not agree” button, technical cookies that are necessary for the functioning of the website will still be saved and do not require the user's consent.
More information I do not agree I agree
4.4. User Browser Settings as a Method of Obtaining Consent
User browser settings are not considered a GDPR-compliant method of obtaining user consent. More information on this topic can be found in Opinion 2/2010 on online behavioral advertising issued by the Article 29 Working Party.
The average website user is not aware that their online actions may be tracked. Users do not always know how to use browser settings to reject cookies, even if such information is included in the privacy notice. It is a mistake to assume that a lack of action by the website user is equivalent to a clear and unambiguous expression of their preferences. The responsibility for the lawful processing of cookies cannot be transferred to the user who has not taken certain precautions through their browser settings.
For browser settings to provide informed consent, there must be no possibility of "overriding" the choice made by the user when setting up the browser. In practice, however, deleted cookies can easily be "restored" using so-called "flash cookies," which allow the advertising network provider to continue monitoring the user. Flash cookies are text files that the web server sends to the user when the browser requests content served by the Adobe Flash plugin. Flash cookies differ from regular browser cookies in terms of how much data they can store and how they can be declined. Unlike regular browser cookies, flash cookies must be deleted using the settings of the Adobe Flash Player.
The availability and growing popularity of this type of technology call into question the ability to ensure informed and valid consent through browser settings.
For the above reasons, expressing consent to receive cookies through browser settings will, in most cases, mean that website users will consent to data processing, often without knowledge of the purposes or uses of those cookies. Any consent to data processing without knowledge of the circumstances surrounding the processing may be deemed invalid.
4.5. Obtaining Consent from Minors
If the direct provision of information society services requires the consent of the data subject, and the data subject is a child, their consent may constitute a lawful basis for processing, provided that the child is at least 13 years old.
If the child is under 13 years old, the processing of personal data will be lawful, provided that consent has been given by a parent or legal guardian.
In order to obtain "informed consent" from a child who is at least 13 years old, the data controller should appropriately provide the child with information and convey this information in clear and simple language that is easily understandable for the child. In the case of younger children, taking into account available technologies, the data controller should make reasonable efforts to verify whether consent has been given or confirmed by a person who is the parent or legal guardian.
Furthermore, the level of risk associated with the use of cookies should be taken into account (e.g., considering the nature of the personal data being collected), in line with the principle of data minimization: the lower the risk, the simpler the consent verification system that should be implemented.
- If a website aimed at children can be visited by unregistered users, and cookies will be used for analytical purposes, parental consent can be obtained through a pop-up window that appears when the child visits the specified website. This method avoids the need to request additional data from the child or from a person who is their parent or legal guardian.
Example
If you are under 13 years old, ask your parents to read this notice! We use our own and third-party cookies to understand how users interact with our website and to prepare statistical reports. To learn more about our cookie policy, click the "More information" button. Users can accept all cookies by clicking the "Accept" button or reject them by clicking the "I do not agree" button.
- In the case of automatic adjustment and personalization of certain aspects of the displayed content (such as the language of the website or the layout of the content), additional precautions must be taken to ensure that the parent or legal guardian has given consent in the specific circumstances of the case—regardless of the appropriate risk analysis. Consequently, users may be asked whether they are over 13 years old, and if they respond negatively, the following message will be displayed.
Example
Ask the parent or legal guardian to provide the date of birth! (The information about the year of birth of the parent or legal guardian is used to verify consent. The information about the year of birth will not be stored). We use our own and third-party cookies to understand how the user interacts with our site, to generate statistical reports, and to personalize the use of the site, for example, by adjusting the layout of the page or selecting the language.
To learn more about our cookie policy, click the "More information" button. The user can accept all cookies by pressing the "Accept" button or reject them by pressing the "I do not agree" button. If the website user clicks the "I do not agree" button, technical cookies that are necessary for the functioning of the website and do not require the user's consent will be saved.
- If cookies may pose a greater risk than described in examples a) and b) (e.g., information collected through cookies regarding websites visited by the child—subsequently, the collected information is shared with third parties for the purpose of analyzing the child's interests and displaying personalized advertisements), parents or legal guardians should be required to provide additional information to verify the consent given (e.g., an email address to which the data controller can send a verification message to further confirm the consent provided by the parent or legal guardian).
Given that children constitute a vulnerable group, data controllers should refrain from profiling children for marketing purposes. Opinion 02/2013 on smartphone applications (WP202), adopted on February 27, 2013, states particularly in section 3.10 regarding children on page 26, that "data controllers should not process children's data for the purposes of behavioral advertising, either directly or indirectly, as this exceeds the understanding of the child, and thus goes beyond lawful data processing." Children may be particularly susceptible to online abuse and are also more easily influenced by behavioral advertising. For example, in online games, profiling may be used to identify players who, according to algorithmic indications, are more likely to spend money on the game. The age and immaturity of the child may affect their inability to understand the motives and consequences of such marketing actions.
4.6. Explicit Consent
If processing is based on the consent of the data subject, the data controller must be able to demonstrate that the individual has given consent to the processing operation. This means that the website must implement "I agree"/"I do not agree" cookies that will store the choices made by the user’s IP address regarding the cookies used by the site.
There is no specific time limit for which the given consent remains valid. How long the consent remains valid depends on the context, the scope of the original consent, and the expectations of the data subject. If the circumstances surrounding the data processing change significantly, the original consent will lose its validity. In such a case, new consent must be obtained.
4.7. Withdrawal of Consent
The website user may withdraw their consent at any time, in a manner as easy as it was to give consent. To this end, the website should provide information on how to withdraw consent and delete cookies. The GDPR does not require that consent always be given and withdrawn in the same manner. However, when consent is obtained electronically, with a single mouse click, swipe, or key press, data subjects should have a practical ability to withdraw their consent just as easily. The requirement for simple withdrawal of consent is included in the GDPR as an essential aspect of the validity of consent. If the mechanism for withdrawing consent does not meet the requirements of the GDPR, then the mechanism for granting consent is also not compliant with the GDPR.
Example of bad practice
The user can change their cookie preferences at any time through the settings in their web browser. For example, the user can withdraw consent for the use of cookies by selecting the appropriate option in the browser, which will result in rejecting all proposals to save cookies. These settings can be found in the "options" or "preferences" menu. Below are useful links: Chrome: Google Chrome Help Center; Firefox: Cookies - information that websites store on the user's computer; Safari: Safari for macOS Sierra: Managing cookies and website data using Safari; Edge: Microsoft Edge, browsing data and privacy; Opera: Security and privacy in Opera.
Example of good practice
The user can withdraw their consent regarding cookies at any time and refuse their use. The user can reject all cookies except for "essential" cookies. If you wish to withdraw your consent for analytical and marketing cookies, press the appropriate button: Withdraw consent.
4.8. Extending consent and changes in the use of cookies
Good practice requires that granted consents be regularly verified and updated to ensure compliance with the latest requirements. As a rule, consent for cookies remains valid until the purpose of processing personal data is achieved.
If the purpose of processing personal data has been achieved or has changed, consent must be requested again.
The same applies to changes in the purpose of using cookies - if the purpose has changed, renewed consent is required for further use of cookies.
4.9. Exceptions to the requirement to obtain consent
Employer, recruiter, candidate.
GDPR in HR.
- the transmission of a communication over a public telecommunications network;
- the provision of a telecommunications service or an electronic service requested by the subscriber or end user.
4.9.1. Exceptions to the Requirement for Consent
This exception applies to cookies whose sole purpose is the transmission of information over a network. At least three elements can be considered strictly necessary for communication to occur between two parties via the network:
- the ability to direct information over the network, in particular by identifying the endpoints of communication;
- the ability to exchange data in the intended order, in particular by numbering data packets;
- the ability to detect transmission errors or data loss.
More information on this topic can be found in the Opinion of the Article 29 Working Party regarding the exemption concerning consent for the use of cookies (WP 194).
For example, if a cookie is used for load balancing to distribute network traffic among different servers, it can be considered a type of cookie that is relevant for the flow of information through the electronic communication network. The sole purpose of such a cookie is to identify one of the servers (i.e., the endpoint of communication), and therefore it is necessary for network communication.
If a cookie, whose purpose is to transmit messages over the network, serves this function only seemingly, without any real intention to utilize its properties, it is not exempt from the requirement to obtain consent.
4.9.2. For the Provision of Services Requested by the Subscriber or User
For a cookie to be exempt from the requirement to obtain consent based on this criterion, it must meet two conditions simultaneously:
- the user has explicitly requested an information society service: the user (or subscriber) has taken action to request a service with a clearly defined scope;
- the cookie is strictly necessary for the provision of the information society service: the service will not function with cookies disabled.
Example:
• Consent is not required if: session cookies are used on the website to track the items placed by the user in the shopping cart. These cookies expire at the end of the session or shortly thereafter. Such cookies meet the "strict necessity" condition and do not require consent. Similarly, cookies that record the user's language or country when visiting the website do not require consent, as they are strictly necessary for providing the services requested by the user.
• Consent is necessary if: the travel-related page uses a cookie that has a 2-year validity period and is used on each visit to the page: to identify the user's browser and device, as well as to display the travel plan and to remember the user's travel-related choices. Although such functionality may be useful for some users, such cookies require consent. The user must know how long the website will store the choices made.
If the user purchases a ticket from the starting point to the destination of the journey, this goal can be achieved using a session cookie. However, if the intention is to provide the user with a service that allows the website to remember the user's choices for a longer period, consent is required for the cookie that stores information about such choices.
4.9.3. Cookies for which consent is not required
Examples of cookies that do not require user consent include:
- cookies used for user input (session identifier), for example, cookies used by the first party (data controller) that are used to collect data entered by the user while filling out online forms, shopping carts, etc.;
- cookies used for authentication (user identification) - during the session;
- Cookies related to user security, used to detect authentication breaches - for a limited, fixed period;
- cookies related to the operation of multimedia players, used to store technical data that serve to play video or audio content – during the session;
- cookies used for load balancing - during the session;
- cookies used to customize user settings, such as language or background preferences - during the session (or slightly longer);
- cookies used for sharing content via third-party social media plugins.
Aside from exceptional cases, the only legal basis for placing cookies is consent.
If the website uses only cookies for which consent is not required, the data controller may inform the user about the existence of cookies in the privacy notice, which should be accessible on the website. In such a case, there is no obligation to place a pop-up informing that the site uses technical cookies.
In the above case, if the data controller decides to provide information via a pop-up window, they do not need to ask for additional consent. It is sufficient to include in the pop-up a clear and understandable message that there is no obligation to provide consent.
Example of bad practice
Please note that the site uses technical cookies.
I agree
Example of good practice
We inform you that the site uses technical cookies to identify users during their session. For more information about the technical cookies used on the site, please click the link: "Privacy Policy". Pressing the "I understand" button will close this window.
I understand
5. Data Protection Impact Assessment
Before commencing processing, the data controller must in every case take into account the nature, scope, context, and purpose of the processing, as well as whether the processing may result in a high risk to the rights and freedoms of natural persons, in accordance with Article 35(1) of the GDPR, and also conduct a Data Protection Impact Assessment (DPIA) if they believe that the processing may result in a high risk to the rights and freedoms of natural persons.
The Latvian supervisory authority has published a list of processing activities for which conducting a DPIA is mandatory. This list includes processing activities involving systematic monitoring, tracking the location or behavior of individuals whose data is being processed, as well as profiling these individuals on a large scale.
Conducting a DPIA is also necessary when the processing involves aggregating, combining, or comparing separate datasets, if such operations significantly contribute to the profiling or behavioral analysis of individuals whose data is being processed. This particularly applies to situations where the datasets originate from different sources and where the processing has been/is being carried out by different data controllers for different purposes.
It should be noted that the list from the Latvian supervisory authority is not exhaustive, and the primary criterion for assessing the necessity of conducting a DPIA is the risk to the rights and freedoms of individuals whose data is being processed.
It can be observed that the risk to the rights and freedoms of these individuals is significantly lower when using technical cookies and somewhat lower in the case of personalized cookies.
The identified risk can also be largely mitigated by implementing appropriate technical and organizational measures that secure the collected data.
It is widely believed that the use of analytical cookies provided by third parties increases the risk to the individual, as it limits the ability to control who has access to the data and to what extent, as well as how it is used.
Other factors to consider when assessing the potential risk to the rights and freedoms of individuals include: the content offered by the website, the reasonably expected level of anonymity, the content of the information collected in cookies, and the extent to which information about the individual whose data is being processed may already be in the possession of a third party providing the cookies used to collect information.
In light of the above, the Latvian supervisory authority encourages careful consideration of conducting a DPIA when a website offers content that can be linked to personal data of a special category (e.g., a dating site or a site related to medical services), or to data that may be considered sensitive by the client (e.g., financial services), as well as in other cases where the analysis conducted by the data controller leads to the conclusion that the processing may pose a high risk to the rights and freedoms of the individual whose data is being processed.
For more information on the processing of cookies in accordance with the GDPR, please contact Cezary Lutyński. He is our experienced Data Protection Officer (DPO) – he will provide you with support and advice on matters related to planning projects in compliance with the GDPR.
Check what you remember - a reward for the correct answer!
Should the user have the ability to withdraw consent for cookies?
1 Latvian Law on Information Society Services. Latvijas Vēstnesis, 17.11.2004, No. 183, Article 1, paragraph 2 of the first section.
2 See: European Commission publication "Let's be clear" (2011).





