Web Tracking vs. Consent: No Child's Play

Uncertainty is spreading in the digital marketing world regarding whether the use of a tracking tool or the associated data processing requires the user's consent.

Image: PrivacyStock photo.

This article is intended to help you understand in a simple manner that there is no universally valid standard answer to the consent question and that, as is so often the case, it "depends" on how the facts of the case present themselves. Questions such as the following are currently unsettling: Has Switzerland adopted the obligation to provide consent from European law with the new DPA? Can a Swiss website operator be subject to EU data protection law? Do cookie and data protection rules even apply to server-side tracking? Is the USA safe or not and can a data transfer there require consent?

In Switzerland, the following still applies: No consent is required for the setting of cookies and other client-side tracking technologies or for the processing of personal data. However, it is mandatory to inform the user transparently and to offer an opt-out option at any time. The legal basis for this is the Telecommunications Act and the Data Protection Act. The information can be provided in the data protection statement, which is always required, but also via an info banner.

Despite the Swiss "no consent" concept, there may be constellations that require consent. Specific individual cases should be clarified with a specialist.

The following exemplary tracking scenarios can serve as inspiration:

A Swiss website operator without EU traffic uses cookie tracking. The tracking data is transferred directly to a server in the EU: No consent is required. Neither for cookie setting nor for the processing of any personal data, nor for the transfer to the secure EU countries.

Identical, but with transfer of personal data to a cloud in the U.S. that does not offer standard data protection clauses or other safeguards: From a Swiss perspective, the USA is currently considered an insecure third country. A transfer to the USA to a provider who does not provide standard data protection clauses or other guarantees is in principle a violation of data protection law. Obtaining explicit consent would be required. The new Data Privacy Framework (DPF) is expected to make things easier with regard to the USA in the near future.

A Swiss hotel chain offers special offers for customers from the European Economic Area (EEA) on its website with cookie tracking: Consent is required (only for EEA traffic), since the qualified reference to the EEA is the national implementations of the European ePrivacy Directive. This includes the German Telecommunications Telemedia Data Protection Act (TTDSG).

A Swiss bank with branches in the EU installs server-side "cookieless" tracking on its website: With this tracking, there is no access to the end device. It does not require consent, neither under CH nor under EU law.

To keep data protection risks under control, it is worth considering the services of local, established tracking providers who rely on European hosting solutions. These providers are also able to filter traffic according to content requirements. Because: Unnecessary content banners mean loss of valuable analytics data!

Author: Thomas Michel - Information Security Officer at Capture Media.

More information is available here.

More articles on the topic