Web tracking and risk management

The systematic assessment of risks that a company can take in a controlled manner is called risk management. Data protection risks associated with tracking should not be overlooked in this context.

A functioning risk management is a control instrument for achieving the company's goals. For larger companies it is mandatory, for others it makes sense: to identify, analyze, treat and monitor risks. These risks are not limited to financial, strategic or information security risks. Data protection, i.e., the protection of the individual from infringing data processing, also harbors risks.

Privacy risks in tracking

If "cookies" are placed on an end device during web tracking, the user is generally considered to be an identifiable person via IP address and, as a result, Swiss data protection law is applicable. A Swiss website operator is quickly also subject to EU data protection law if he tracks his EU traffic or selectively plays out offers in this area. The data protection law requirements are manifold: information obligations, data subject rights, data inventory, data security or the cookie consent question (EU yes, CH no) and much more. Data protection law requires regular risk analyses here, whereby assessing data protection risks is not easy even for specialists.

One bugbear is big-tech data transfers abroad and potential access by authorities. Although the probability is considered low, there would be a cluster risk associated with this: Requests for information, FDPIC notification, lawsuits, loss of reputation, very high threat of fines (EU) and newly personal fines in Switzerland. Even standard data protection clauses do not offer sacrosanct protection, as the record fine from Ireland shows. Another risk is the assurance of anonymization of IP addresses in data protection declarations, because this is relative, as it only takes place after transmission to the data center.

How are data protection risks handled?

The seemingly cheapest and simplest treatment is to accept a risk, which must be formally documented with reasons (lack of resources). Risks are transferred classically via insurance. Cyber and D&O insurances, however, refuse to cover personal fine risks.

The right way is to reduce. This respects the risk-based approach of data protection law, according to which protective measures are taken in function of the probability of infringement and possible effects. The focus here is on the use of a European tracking solution. In addition to sharpened privacy awareness and on-site data centers, such solutions are equipped with first-class features. Data proximity and data sovereignty are particularly valued by companies from sensitive and regulated industries. Next, avoidance is an option by relying on tracking technology that does not require cookies and still provides useful marketing data. Companies that systematically address tracking risks often choose a mix: cookie tracking where consent is available or not necessary, and cookieless tracking where it is not.


Author: Thomas Michel, Information Security Officer at Capture Media.

More information is available here.

More articles on the topic