Posted on May 25, 2012 by
Spread the word...

Cookie Law ThumbnailLearn more about ICO and the Cookie Law

Well it’s the eve before the Information Commissioner’s Office (ICO) starts enforcing the new EU cookie law (e-Privacy Directive); the law which applies to how you use cookies and similar technologies for storing information on a user’s equipment such as a PC or mobile device.

But what sort of shape is the government in? How are they treating cookies and privacy concerns?

The ICO has had nearly one year to warn them to get in line with the new law.

So we decided to investigate…

We ran through Direct.gov.uk’s list of central government websites which include government departments, executive agencies and non-departmental public bodies… 122 sites in all.. Then we ran through all 122 to see how they conform according to the 3 main principals of setting cookies for being within the law:

  1. tell people that the cookies are there,
  2. explain what the cookies are doing, and
  3. obtain their consent to store a cookie on their device

Not all bodies are included as they may share the same domain or not distinct enough to warrant being its own site. You can view the full table of websites below.

Statistics we found…

11 Sites where it was impossible to find information regarding cookies or having a privacy policy at all.

2 Sites chose to use exactly the same method as ICO for not allowing any cookies to form (only allowing consent first).

4 Sites chose to use the ICO method but with session cookies being stored first.

6 Sites in total chose to obtain consent; visibly warning users about cookies. 4 of which were Scottish sites.

11 Sites mentioned cookies were being used when entering their homepage.

14 Sites that used cookies failed to mention their policy on cookies.

8 Sites do not set cookies when entering their site by their main/root domain.

47 Sites chose to display their policy via a link mentioning the word ‘cookies’. Of those only 1 site offered to turn off cookies via its own settings such as a cookie control panel (The Forestry Commission).

4 Sites were found to have misleading or incorrect information regarding their cookies.

  1. The Serious Fraud Office uses Google Analytics and states on their page “We do not use cookies for collecting information from the site.”
  2. The British Waterways states “Once the user closes their browser, the cookie terminates.” Which is true to a point, but their analytics uses persistent cookies.
  3. The Care Quality Commission (CQC) fails to signal any use of cookies from using their site but states “Please be aware that some systems on our website require the use of cookies, but we will always state if this is the case.”
  4. It might be picky but The Crown Estate site intends to use Analytics which uses persistent cookies but states, “Where we intend to use a cookie, explanatory text will be provided to tell you what the cookie does, and you will be given a specific opportunity to accept the cookie or refuse it.”

Below is the list we have compiled of central government websites taken from Direct.gov.uk such as government departments, executive agencies and non-departmental public bodies.

What the columns represent:

Cookies On Arrival All visits were based on visiting the root page of the website and whether cookies had been downloaded.
Tell Visitors Cookies Are There This is based on ICO’s principal of being clear about cookies. A popup or sentence would be deemed acceptable. A link saying Cookies is not acceptable.
Explain What Cookies Are Doing These are direct links from the home page to information on cookies. Some are recorded as 2 hops, say, from Privacy page to Cookies page.
Obtained Consent Did they obtain consent first before allowing cookies.
Cookie Types Types of cookies stored from first visiting the website.
Appropriate Info Page: The appropriate page for finding information about their privacy policy and cookies.
Note: Not all bodies listed by DirectGov are included as they may share the same domain or are not distinct enough to warrant being their own site.
NameCookies On ArrivalTell Visitors Cookies Are ThereExplain What Cookies Are DoingObtained ConsentCookie TypesAppropriate Info Page
Information Commissioner’s Office (ICO)NoYesYesYesNoneLink
DirectGovYesNo (Direct link)YesNoSession/PersistentLink
Advisory, Conciliation and Arbitration Service (ACAS)YesNoYes (via Privacy page)NoSession/Persistent/Third PartyLink
The Adjudicator’s OfficeYesNoNoNoPersistentLink
Association of Police Authorities (APA)YesNoPartial (Privacy Page)NoPersistentLink
Attorney General’s Office (AGO)YesNo (Direct link)YesNoSession/PersistentLink
Audit CommissionYesNo (Direct link)YesNoSessionLink
Audit ScotlandNoYesYesNoPersistentLink
Department for Business Innovation & Skills (BIS)YesYesYesNoSession/PersistentLink
Bona VacantiaYesNo (Direct link)YesNoSession/PersistentLink
Boundary Commission for EnglandYesNo (Direct link)YesNoSession/PersistentLink
Boundary Commission for Northern IrelandYesNoNoNoPersistentx
Boundary Commission for ScotlandYesNoNoNoSessionx
Boundary Commission for WalesYesNoNoNoSession/Persistentx
BRB (Residuary)Non/aNon/aNonex
British MonarchyYesNoPartial (via About this Site)NoSession/Persistent/Third PartyLink
British WaterwaysYesNoPartial (via Privacy page)NoSession/PersistentLink
Office for Budget ResponsibilityYesNoNoNoThird Partyx
Business LinkYesYesYesNoSessionLink
business.wales.gov.ukYesNo (Direct link)YesNoSessionLink
Business GatewayYesNo (Direct link)YesNoSessionLink
Cabinet OfficeYesNoYesNoSession/PersistentLink
Care Quality Commission (CQC)YesNoPartial (Privacy page)NoSession/PersistentLink
Charity CommissionYesNoYes (Privacy page)NoSession/PersistentLink
Civil ServiceYesNo (Direct link)YesNoSession/PersistentLink
Department for Communities and Local GovernmentYesNo (Direct link)YesNoSession/PersistentLink
Companies HouseYesNo (Direct link)YesNoPersistentLink
Competition Appeal TribunalYesNo (Direct link)YesNoSession/PersistentLink
Competition CommissionYesNoYes (via Privacy page)NoSession/PersistentLink
The Crown EstateYesNoYes (via Privacy page)NoSession/PersistentLink
Crown Prosecution Service (CPS)YesNo (Direct link)YesNoSession/PersistentLink
Department for Culture, Media and Sport (DCMS)YesNo (Direct link)YesNoSession/PersistentLink
Department of Energy & Climate Change (DECC)YesNo (Direct link)YesNoSession/PersistentLink
Department for Environment, Food and Rural Affairs (DEFRA)YesNo (Direct link)YesNoSession/PersistentLink
Ministry of Defense (MoD)YesNo (Direct link)YesNoSession/PersistentLink
Department for Internation Development (DFID)YesNo (Direct link)YesNoSession/PersistentLink
Department of Finance and Personnel of NI (DFP)YesNo (Direct link)YesNoSession/PersistentLink
Department for EducationYesNoYes (via Legal information)NoSession/PersistentLink
Department for Transport (DfT)YesNo (Direct link)YesNoSession/PersistentLink
Department of Health (DH)YesNo (Direct link)YesNoSession/PersistentLink
UK Debt Management Office (DMO)YesNoNoNoSessionx
Driver and Vehicle Licensing Agency (DVLA)YesNo (Direct link)YesNoSession/PersistentLink
Department for Work & Pensions (DWP)YesNoYes (via Privacy page)NoSession/PersistentLink
The Electoral CommissionYesYesYesNoSession/PersistentLink
The Environment AgencyYesNo (Direct link)YesNoSession/PersistentLink
European Consumer Centre for Services (UK ECC)NoYesYesYesNoneLink
UK Export Finance (ECGD)YesNoYes (via Privacy page)NoSession/PersistentLink
Equality and Human Rights Commission (EHRC)YesNoNoNoSession/PersistentLink
Office of Fair Trading (OFT)YesNo (Direct link)YesNoSession/PersistentLink
Financial Ombudsman ServiceYesNoYes (via Privacy page)NoSession/PersistentLink
Financial Services Authority (FSA)YesNoYes (via Privacy page)NoSession/PersistentLink
Food Standards AgencyYesNo (Direct link)YesNoSession/PersistentLink
Foreign and Commonwealth Office (FCO)YesNo (Direct link)YesNoSession/PersistentLink
http://www.forestry.gov.ukYesNo (Direct link)YesNoSession/PersistentLink
Gambling CommissionYesNo (Direct link)YesNoSession/PersistentLink
Office of Gas and Electricity Markets (OFGEM)YesNo (Direct link)YesNoSession/PersistentLink
Government Actuaries Department (GAD)YesNoNoNoSession/PersistentLink
Government Communications Headquarters (GCHQ)Non/aYesn/aNoneLink
GCNYesNoYes (via Privacy page)NoSession/PersistentLink
General Register Office for ScotlandNoYesYesYesNoneLink
Health and Safety Executive (HSE)YesNo (Direct link)YesNoSession/PersistentLink
HM Inspectorate of Constabulary (HMIC)YesNo (Direct link)YesNoSession/PersistentLink
HM Revenue & Customs (HMRC)YesNoYes (via Privacy page)NoPersistentLink
HM TreasuryYesNoYes (via Privacy page)NoSession/PersistentLink
Higher Education Funding Council for England (HEFCE)YesNoNoNoSession/Persistentx
Highways AgencyYesNoYes (via Terms & Conditions)NoSession/PersistentLink
Homes and Communities AgencyYesNoYes (via Legal)NoSession/PersistentLink
Home OfficeYesNo (Direct link)YesNoSession/PersistentLink
The Independent Case Examiner (ICE)Non/an/an/aNonex
Independent Police Complaints Commission (IPPC)YesNo (Direct link)YesNoSession/PersistentLink
Intellectual Property Office (IPO)YesNo (Direct link)YesNoSession/PersistentLink
Department for JusticeYesNoYes (Privacy page)NoSession/Persistent/Third PartyLink
Land RegistryYesNoYes (Privacy page)NoSession/PersistentLink
Legal OmbudsmanYesNoYes (Privacy page)NoSession/PersistentLink
Legal Services Commission (LSC)YesNoYes (Disclaimer)NoSession/PersistentLink
Local Government OmbudsmanYesNoYes (Privacy page)NoSession/PersistentLink
Greater London Authority (GLA)YesNoYes (Privacy page)NoSession/PersistentLink
Medicines and Healthcare Products Regulatory Agency (MHRA)YesNoYes (Terms & Conditions)NoSession/PersistentLink
MET OfficeYesNo (Direct link)YesNoSession/Persistent/Third PartyLink
MI5Non/aYesNon/aLink
Money Advice ServiceYesNoYes (Privacy page)NoSession/PersistentLink
The National ArchivesYesNo (Direct link)YesNoSession/PersistentLink
National Assembly for WalesYesNoYes (Privacy page)NoSession/Persistent/Third PartyLink
The National Health Service (NHS)YesNoYes (Privacy page)NoSession/PersistentLink
National ParksYesNoYes (Terms & conditions page)NoPersistent/Third PartyLink
National Policing Improvement Agency (NPIA)YesNoYes (Legal)NoSession/PersistentLink
National Savings and InvestmentsYesNo (Direct link)YesNoSession/PersistentLink
Natural EnglandYesNoYes (Privacy page)NoSession/PersistentLink
Northern Ireland AssemblyYesNoNoNoSession/Persistentx
Northern Ireland Office (NIO)YesNoYes (Privacy page)NoSession/PersistentLink
The Nuclear Decommissioning Authority (NDA)YesNoYes (Privacy page)NoSession/Third PartyLink
10 Downing StreetYesNo (Direct link)YesNoSession/PersistentLink
Ofcom (Office of Communications)YesNo (Direct link)YesNoSession/Persistent/Third PartyLink
Ofsted (Office for Standards in Education)YesNo (Direct link)YesNoSession/PersistentLink
Office of Rail Regulation (ORR)YesNo (Direct link)YesNoSession/PersistentLink
Office of the Parliamentary and Health Service OmbudsmanYesNoYes (Site Info)NoSession/Persistent/Third PartyLink
Office of Qualifications and Examination RegulationYesNo (Direct link)YesNoSession/PersistentLink
Office for National StatisticsYesNoYes (Privacy page)NoPersistentLink
Office of Water Services (OFWAT)YesYesYesYesSessionLink
Public Services Ombudsman (Wales)YesNoYes (Privacy page)NoSession/PersistentLink
Ordnance SurveyYesYesYesNoSession/PersistentLink
Pensions OmbudsmanNon/aYesn/an/aLink
Parliament.ukYesNo (Direct link)YesNoSession/PersistentLink
Planning PortalYesNoYes (Privacy page)NoSession/PersistentLink
Prisons and Probation OmbudsmanYesNoYes (Terms & conditions page)NoSession/PersistentLink
Government Procurement ServiceYesNoNoNoSession/PersistentLink
The Royal MintYesNo (Direct link)YesNoSession/PersistentLink
Royal Parks AgencyYesNoYes (Disclaimer)NoSession/PersistentLink
Scotland OfficeYesYesYesYesSessionLink
Scottish GovernmentYesYesYesYesSessionLink
Serious Fraud Office (SFO)YesNoYes (Privacy page)NoSession/PersistentLink
Serious Organised Crime Agency (SOCA)YesNoYes (Privacy page)NoSession/PersistentLink
Stabilisation UnitYesNoYes (Privacy page)NoSession/PersistentLink
Transport ScotlandYesYesYesYesPersistentLink
Treasury Solicitor’s Department (TSOL)YesNo (Direct link)YesNoSession/PersistentLink
UK Border AgencyYesNoPartial (Privacy page)NoSession/PersistentLink
UK Office of the European ParliamentYesNoNoNoSession/Persistentx
UK Trade & Investment (UKTI)YesNo (Direct link)YesNoSession/PersistentLink
Universities and Colleges Admission Service (UCAS)YesNo (Direct link)YesNoSession/PersistentLink
Service Personnel and Veterans AgencyYesNo (Direct link)YesNoPersistentLink
Wales Audit OfficeYesNoNoNoSessionx
Wales OfficeYesNoNoNoSession/PersistentLink
Welsh GovernmentYesNoYes (Privacy page)NoSession/PersistentLink

Conclusion…

If the sites listed do not change by tomorrow this means that 90% of those government sites will be breaking the law.

This is not a list to poke holes at privacy issues, but to show the confusion… what is the right method in being open/honest about cookies? And why is the UK government so lacklustre in this department.

Should there be a prompt about consent and cookie usage? According to The ICO and the law it does, but only 6 sites actually complied with this rule… And only 2 of those used the same method as The ICO by not allowing any cookies when first visiting their sites.

Hopefully we’ll see more sites changing in the coming days; not expecting any miracles though.

Leave a Comment

Your email address will not be made public or shared. Inappropriate and irrelevant comments will be removed.

  1. Even after a week later most websites do not comply with the new law! This is probably the most ignored law that ever came out. I think that is too right because the EU is picking on troubled webmasters that have to fight for their “business lives” in troubled recession times. They cannot live without knowing who buys their products/services. They need to be focused on prospects that make money. Cookies are not a bad thing – they are essential for webmasters to make their daily turnover and being able to eat at the end of the day. Okay, there might be some criminals who try to capture info that they might use to get bank details … but a normal thinking person would only give their bank details out to websites that sell and have a secure shopping interface with encrypted communication. If they would not receive their goods after a certain time they would complain to the banks and force the money back (be sure to not pay by debit card to a company that you don’t know. Pay by Paypal or Credit Card – then you can get your money back. Bringing a whole industry down with that does not help to get us out of the recession – or does it? It seems that governments don’t think entrepreneurial nor economical. This seems to be caused by guys who invent laws to defend their desks. Sorry, but that what I think it comes down to … defending government employees desks – sad but, whatever it takes to secure ones government employee’s income.
    Therefore just comply with the law but make the people who visit your website to agree with at least that Google Analytics is necessary to carry on browsing your website. If they don’t agree don’t even let them see you content,
    If every webmaster does that the law will be ridiculous and forced down in the end.