Cookie Notice, Banner, and Management Configuration:

Cookie Banner Language

  • Currently, the banner on preserveatcopperleaf.com reads as follows: “We use cookies and similar technologies to analyze website traffic, personalize content, and support our marketing efforts. Some cookies may be placed by trusted third-party service providers. For more information about how we use personal information and your privacy rights under applicable laws, please review our Privacy Policy.”
  • I’m currently not seeing that the website uses targeted advertising cookies. If you choose to do so later, I recommend updating the banner language as follows:
    • “We use cookies and similar technologies to analyze website traffic, personalize content, and support our marketing efforts, and to provide targeted advertising to you. Some cookies may be placed by trusted third-party service providers. For more information about how we use personal information and your privacy rights under applicable laws, please review our Privacy Policy.”
  • The website currently places non-essential cookies by default. This is a note for later that if you ever update the cookie banner language, do not say that if a user clicks “accept all”, they consent to the use of cookies – this wouldn’t be true in your case because cookies are placed by default.  If anything, an update would need to say something along the lines of “by continuing to use our website, you consent to the use of all cookies.”

 

Note on Jurisdiction-Specific Approach to Cookie Banner: Not all states have a privacy law, and of the 23 states that do, not all of them have requirements akin to those under GDPR or CCPA.  All the guidance below is recommended for GDPR, CCPA, and Colorado Privacy Act compliance, as well as when cookies are used to collect information considered “sensitive”, such as precise geolocation, children’s information, or information used for profiling. 

Minimum Recommended Cookie Banner / Consent for All Jurisdictions:

  • You should have a cookie banner that appears immediately when a user visits the site.
  • The cookie banner should state that the website uses cookies to provide website features, for analytics, to enhance the user experience, and for targeted advertising, and that by using the website the user agrees to the use of cookies.
  • Ideally, the site would wait to place non-essential cookies until the user scrolls or clicks anywhere after the cookie banner appears.
    • NOTE: This is critical to preventing future pixel litigation demands. If you choose to place non-essential cookies before a user has affirmatively accepted them, you run the risk of additional pixel litigation.

 

Guidance to Address Pixel Litigation Risks:

In addition to the privacy laws, cookie banner and consent management is central to pixel litigation where plaintiffs assert that website cookies violate one or more of trap and trace statutes, wiretap act / statutes, and/or video privacy protection act (or similar) statutes.  Requirements marked with u are particularly important to reduce risks of pixel litigation.

 

Guidance on Cookie Banner and Consent Management Center:

Rules and Requirements:

  • Configuration Requirements:
    • The cookie banner and consent management tool must be accessible to consumers with disabilities.
    • The cookie banner and consent management tool disclosures must be formatted so that the disclosure is readable even on smaller screens.
    • If the cookie banner or consent management tool presents the user a choice to “accept all” cookies (or similar verbiage or functionality), it must also have a choice to “reject all” cookies (or similar verbiage). 
    • The cookie banner must appear immediately when the user visits the website for new users (or for returning visitors who have cleared their prior choices). u
    • It must be easy for a user to revisit their choices to allow them to change their preferences.
      • This is something that needs to be changed.  Whichever option I select on the cookie banner as currently configured, the only way to revisit my choices is to clear all my browsing data for the site and refresh the website.
    • Pre-checked boxes are not permitted, and a user must not be automatically opted in to accept non-essential cookies; rather, the user must give consent before non-essential cookies are used. u
  • Technical Requirements:
    • A user is able to opt out of sale as easily as they are able to opt in.  An opt-out cannot require more clicks by a user than it takes for a user to opt-in.
    • If a user chooses to opt out, or chooses not to accept cookies, the cookie management tool must prevent cookies from being placed. u
    • Cookies should not be placed unless and until a user accepts them. u
      • This is a functional requirement you will want to test, to make sure it is working correctly, once you have updated the configuration settings (since currently non-essential cookies are placed by default).  I note this only because it’s becoming more common that consent management tools have little bugs or mis-classify certain cookies, and the onus is still on the website owner to ensure the user’s cookie choices are honored. 
    • If the user has expressed their cookie choices through an opt-out preference signal, the website needs to be able to recognize that signal and comply with the user’s choices. u

Cookie Banner:

  • When does the cookie banner appear?
    • It should appear immediately when the user visits the website. u
  • What do the buttons need to say?
    • If you have an “accept all” button, you also need to have a “reject all” button.
    • The “accept all” and “reject all” buttons should be the same size, color, font, and general appearance.
    • If you want to allow users to turn off some but not all cookies, I suggest adding the “cookie settings” button.
  • Should non-essential cookies be placed by default?
    • Having cookies off by default (meaning that non-essential cookies aren’t used unless and until a user accepts) is the least risky option.  This is true generally, and is required in order to protect against pixel litigation claims. u
    • BUT for the U.S., in general it is technically acceptable under state privacy laws (not those upon which pixel litigation claims are based) to have cookies turned on by default, as long as you follow all the configuration and technical function requirements.  However, choosing this option will mean you are still at higher risk of pixel litigation claims.
  • Does the banner have to prevent a user from using the website unless and until they accept or reject cookies?
    • No, and generally a cookie banner should not impede or obstruct the ability to use the website.  That said, the other guidance we’ve given on whether cookies are on or off by default still needs to be followed.

Cookie Consent Management Tool:

  • Note that this section is particularly relevant to the cookie banner I found for LSCRE, as the current configuration violates some of these rules.
  • How many clicks to reject or accept?
    • In the consent management center, the user must be able to reject all cookies with the same number of clicks it takes to accept all cookies.
    • If advertising cookies are on by default, you have to be able to opt out in the same number of steps to take to opt in.  See example.
  • Consent Management Choices:
    • If you have an allow all on the configuration page, you must have a reject all or deny all.  This is for BOTH the cookie banner and the cookie/consent management center.
  • Cookie consent management configuration
    • If you have to toggle to opt out of advertising cookies then select “confirm my choices”, but at the same time you would only have to click on “allow all” to opt back in, this isn’t permitted.
  • Location of links to consent management center:
    • The link to manage cookie preferences needs to be in the privacy policy, cookie policy, and in the footer of the privacy policy web pages. 
    • If you aren’t selling any personal data other than targeted advertising cookies, you should include the following image and text that will link to the consent management center:   (Here is the link where you can download the icon: https://oag.ca.gov/privacy/ccpa/icons-download)
      • Otherwise, you’ll need to include a link at the bottom of the webpage that says “Do Not Sell / Share My Personal Information” which will allow the user to opt out of sale and sharing.  I can provide more detail on this if it is relevant.
    • Make sure users have a way to revisit their cookie choices.  There should be an icon or a link so I can easily find my choices and update them.
  • Cookie Categories:
    • The consent management tool should have 4 categories of cookies:
      • Strictly Necessary / Essential (always on, can’t turn off in the consent management tool)
      • Functional
      • Analytics / Performance
      • Marketing / Advertising
    • You need to list all the cookies on your website.  This can be listed in the cookie policy, or you can include them in drop down menus (but there will need to be a link to the drop down menus if possible)
    • Make sure that the cookie category names you use in the consent management center are the same as they are described in the cookie policy.
  • Be careful of default configurations of cookie tools: I make this note and the examples in particular because of a recent enforcement action in California (the Honda decision), where the configuration used by the website noted above (2 clicks to opt out, 1 click to opt back in) was a default configurations for certain cookie vendors, including OneTrust.  I’m happy to check on the appearance and functionality before you finalize.
  • Review for Functionality – here are a few common issues I’ve run into.
    • Make sure that no matter which webpage of the site a user is on when they make cookie choices, those cookie choices are applied consistently throughout the website. 
    • If there is a search bar / feature on any page of your website, make sure that the info a user types in is not shared with Google Analytics (unless that’s intentional).  This is to help protect against pixel litigation.
    • If possible, do not configure videos to auto-play without a user action.  If a webpage does have a video that auto-plays, ideally it would only do so if the user affirmatively accepted cookies.
  • Website Search Tools u
    • When a website visitor runs a search using the website search function and the user has rejected non-essential cookies, either or both of the following should be implemented:
      • The request URL does not include the search term
      • The request URL is not sent to a third party (e.g., Google Analytics)
    • Potential configuration options include:
      • Client-side masking (Browser JS before gtag/dataLayer push)
      • Server-side redaction (Backend before responses or server-side tagging)
      • Cookie-based tokenization (browser cookie set by server or JS)
      • GA4 Data Redaction / Query param removal (GA Admin settings)

EXAMPLE OF CORRECT CONSENT MANAGEMENT CENTER CONFIGURATION / APPEARANCE:

EXAMPLE OF CONFIGURATIONS THAT ARE NOT PERMITTED:

Website Chat Guidance:

Regarding the Live Chat feature, below please find some proposed language that LSCRE can use to ensure it has consent to record those conversations.

By continuing with this chat, you agree that this conversation may be monitored and recorded by LSCRE and _____________.  See Terms of Use and Privacy Policy for more information.

A few things to note about the above language:

  • Regarding the Portion Highlighted in Yellow: LSCRE should include both the name of the company, as well as the names of any third party companies who will be monitoring the conversations in real time for a purpose other than as a vendor to LSCRE to support LSCRE’s business.  For example, if the meta pixel will be monitoring chatbot conversations and using that data to engage in targeted marketing, LSCRE should disclose that the meta pixel, in addition to LSCRE, may be monitoring or recording the conversation. 
    • In other words, if the third party company is monitoring the conversation in real time for a purpose other than as a vendor to LSCRE to support LSCRE’s business, we recommend including the language highlighted in yellow above.
  • LSCRE does not need to use the “Continue Yes/No” “button” options to obtain consent if this is not feasible or is unreasonably expensive to build out.  That said, if it is doable, we recommend allowing the website visitor to check yes/no, because it provides extra evidence of consent if LSCRE is ever sued. 
  • If LSCRE does build in the Yes/No buttons, if the visitor clicks “no”, LSCRE should discontinue the chat immediately.  You could display a message like “We are unable to continue with the Live Chat.  Goodbye.” 
  • If feasible, LSCRE should refrain from recording the conversation until after the visitor either checks “Yes” or continues with the chat.  (We have seen some litigation regarding the timing of when a recording starts).  We’re happy to help troubleshoot with how this will work operationally if the team has questions. 
  • LSCRE should hyperlink to both Terms of Use and Privacy Policy, as noted in our proposed language above. 
  • This consent will only cover consent to record in the live chat function.  If LSCRE is recording communications or website visits through some other function (e.g., software that tracks a user’s visit to the website, website clicks, cookies, etc.), LSCRE will need to obtain separate consent for that recording. 
    • Alternatively, LSCRE could obtain broad consent to recording communications through a general pop-up or other disclosure that appears as soon as the visitor visits the website.  Because disclosures to obtain consent need to be fairly specific, this option often isn’t workable, but we’re happy to discuss with you.
  • This disclosure does not cover recording phone calls between the consumer and LSCRE.  If LSCRE is also recording any phone calls with consumers, LSCRE will need to disclose at the very beginning of the call that the call is being monitored and recorded. 
    • Please let us know if you would like for us to evaluate your call recording compliance. 
  • These disclosures in no way touch upon TCPA or marketing related consent to send text messages or communicate with customers about those types of things.