Would anyone be willing to share best practices about how their organization deals with ensuring Cookie Compliance, specifically to GDPR rules? Where should this sort of compliance review sit in an organization? The particular issue we have is who should review new web deployments that use cookies and to make the decisions on whether Cookies are Strictly Necessary or Functionality Cookies. For example is a Cookie required for a Live Chat to work Functionality or Strictly Necessary? Our Security team does not consider taking on these compliance reviews as their domain, as Cookie Compliance is not an internal security matter and the Data Protection team has a limited interest as the GDPR rules around Cookies apply in case of any Cookie being used by a website, whether or not it contains personal data. 

3.1k views3 Comments
Sort By:
Oldest
Head of Cyber Security in Manufacturinga year ago
I would say, DPO and Security team both shall be involved and work hand in hand.

Most of the time the legals and or DPO don't have the technical acumen to understand when data is floating to third party services. 

Lets take the example you brought up with the LiveChat being on a different provider.  In that case with a high probability you would need to receive explicit consent due to the fact that its not relevant for the website/service to work, it would ease engagement but that's it.
Chief Technology Officer in Mediaa year ago
The responsibility for cookie compliance often falls under legal or compliance teams, ensuring alignment with GDPR rules. A cross-functional committee involving legal, IT, marketing, and web development teams can collaboratively assess new web deployments. Defining clear guidelines and holding regular meetings can help categorize cookies effectively, addressing challenges such as determining if a cookie is Strictly Necessary or Functionality.
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
IT Manager in IT Servicesa year ago
Cookie Compliance is a multi-faceted task that requires inputs from DPO as well as Security teams continuously. Establishing a dedicated privacy or compliance team and following best practices for documentation, assessment, and collaboration can help to ensure GDPR cookie compliance.

Content you might like

Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments

TCO19%

Pricing26%

Integrations21%

Alignment with Cloud Provider7%

Security10%

Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment

No Increase16%

1-5% increase47%

6-25% increase24%

26-50% increase6%

51-75% increase1%

76%+1%

Other2%

View Results
1.7k views1 Upvote