Given the particular invasiveness that cookies (especially third-party cookies) can have on users' private sphere, European and Italian laws provide that the user must be adequately informed about their use and express his or her valid consent to the insertion of cookies on his or her terminal.
In particular, with the provision "Guidelines on Cookies and Other Tracking Tools", the Italian Data Protection Authority (Garante per la protezione dei dati personali) has deemed it necessary to clarify that the framework for identifying the technical method for obtaining online consent for tracking via cookies (or other tools) outlined in the aforementioned provision of May 2014 is still valid, despite the changed regulatory framework that favors and requires data controllers to act in compliance with the new accountability regime (Article 5, paragraph 2, of the Regulation), allowing them, where appropriate, to also adopt different methods to ensure compliance with the rules and the protection of data subjects.
Generally speaking we can say that when accessing the home page or another page of a website that uses cookies, a clearly visible banner must immediately appear, clearly indicating:
- that the site uses cookies;
- what types of cookies are used;
- that the site also allows the sending of “third-party” cookies;
- a link to more extensive information, with indications on the use of cookies sent by the site and where it is possible to deny consent to their installation (directly or by linking to the various sites in the case of third-party cookies);
- the possibility of choosing which types of cookies to accept and, in the event of refusal, that the possibility of browsing the site is not denied;
- the possibility of changing choices at any time through an easy-to-use interface.