Interesting. Hadn't thought about storage in memory. I think it would be covered.
(For the purpose of copyright/database right storage or copying into memory even on a temporary basis is a restricted act. Expressly so. Not directly relevant, but thought I'd mention it.)
The question reduces to are you "storing" if its in memory?
You are still putting something into the subscriber's/user's device - albeit in memory. I think its covered. You could construct some privacy intrusive examples with such a short term cookie. If session cookies stored on a drive are covered why - construing (as European courts will always do) the language purposively - make a distinction between storage in memory and storage on drive when the privacy implications are the same.
Now because it's a session cookie, of course, it means that the assessment as to intrusiveness might well be on the "low" side and not much need to be done.
It might also be grabbed by the 4(b) exception "strictly necessary" for provision of a requested service.
Renzo Marchini
Dechert LLP
+44 (0) 20 7184 7563 direct
+44 (0) 20 7184 7001 fax
[log in to unmask]
www.dechert.com
-----Original Message-----
From: This list is for those interested in Data Protection issues [mailto:[log in to unmask]] On Behalf Of Andrew Cormack
Sent: 26 May 2011 12:01
To: [log in to unmask]
Subject: [data-protection] New PECR and session cookies
I'm trying to get the scope of the new cookie law clear. In particular does anyone have a view on whether it applies to per-session cookies that are only placed in the browser's memory and are deleted when the browser exits?
It hadn't struck me that these might be out of scope until a colleague reported that the ICO's site seems to produce one that is not mentioned in their documentation. Looking back at the wording of the law I see that it applies if you "store or gain access to information stored", so perhaps that *doesn't* cover information that's only in memory and not on disk? The ICO's explanatory note also describes a cookie as "a small FILE" (my emphasis) - I'm not sure whether that is a deliberate distinction, or an oversight?
On the other hand, if temporary storage in memory is covered, should I be checking whether we use hidden form fields as well?
:(
Andrew
--
Andrew Cormack, Chief Regulatory Adviser, JANET(UK)
Lumen House, Library Avenue, Harwell, Didcot. OX11 0SG UK
Phone: +44 (0) 1235 822302
Blog: http://webmedia.company.ja.net/edlabblogs/regulatory-developments/
JANET, the UK's education and research network
JANET(UK) is a trading name of The JNT Association, a company limited
by guarantee which is registered in England under No. 2881024
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Science and Innovation Campus, Didcot, Oxfordshire. OX11 0SG
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
This e-mail is from Dechert LLP, a law firm, and may contain information that is confidential or privileged. If you are not the intended recipient, please delete the e-mail and any attachments, and notify the sender. Dechert LLP is a limited liability partnership registered in England & Wales (Registered No. OC306029) and is regulated by the Solicitors Regulation Authority. A list of names of the members of Dechert LLP (who are solicitors or registered foreign lawyers) is available for inspection at its registered office, 160 Queen Victoria Street, London EC4V 4QQ.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|