Journal

Clients

How to place cookies on your website and comply with LGPD

If you have a website or even a blog and care about your users' data, you should have a clear and objective privacy policy, informing how data collected during visits or accesses are handled. That's where the cookie messages come in to obey LGPD, the general protection law [...]

· · 9 min read

How to place cookies on your website and comply with LGPD

If you have a website or even a blog and care about your users' data, you should have a clear and objective privacy policy, informing how data collected during visits or accesses are handled. That's where the cookie messages come in to obey LGPD, the general law of data protection in Brazil.

The law that came into force with penalties in August 2021 aims to ensure security and privacy in the use of personal information collected by companies. It determines rules and best practices for handling this information. 

One of them is the need for the user to give consent when a company or website collects your personal and sensitive data. As cookies can store information that can identify the user, including login, email, etc., there is a need for the request of such consent.


See also:


If you are a regular internet browser, you must have already faced the warning that a particular website uses cookies and you must have already consented to a cookie policy, even if you did not know what cookies are and what they are for.

Users can consult the cookie policy to find out what kind of data the website or third parties will collect. Therefore, being transparent about which cookies the website uses, you can avoid any negative impact on users' trust on your website.

The LGPD and the cookie warning came to stay!

Why so many cookie notices and privacy according to LGPD? 

It was inspired by a European law GDPR, and we already have several privacy laws, as it is being created all over the world. 

This does not mean more bureaucracy necessarily, but using a word of fashion, a “empowerment” indeed. Exactly, you and I, ordinary citizens, have thanks to these privacy laws, the right to authorize, deny or even withdraw companies' access to the use of our data. 

Practical example of cookie technology

Do you know when you enter your browser on any site, and it recognizes that you have already accessed it before, giving your private/logged area automatic access without asking for the password again?

This happens, therefore, that site has put a cookie, that is, a “brand” in your browser, as authorized with that access information.

This same logic happens when you give a like in a photo of the instagram, you put a product in the cart of the site, to decide whether to buy later or not. All this information is recorded in Internet cookies and can be used later.

Where to start?

Something you should keep in mind when creating the cookie policy for your website is that you should present it in an objective, clear and simple language. People who are reading may not feel comfortable with the legal jargon or complicated terms. The idea is to inform them of how you handle cookies.

The simpler the explanation, the better they will understand and trust you. To create a cookie policy in accordance with the LGPD, it should mainly include the following three parts:

Many people visiting your site may have little or no knowledge of Internet cookies. This part will be useful to them.

You can start with a general description of the cookies and then the type of cookies and their purpose. The purpose of this is to give visitors an idea of what cookies do before explaining how and why their website uses them.

What are the types of cookies?

There are several types, but I will address three known forms of classification:

1. Cookies for the owner

These are cookies defined by the website you are accessing or by third parties on behalf of the site in question.

Third party cookies: those that are not part of the website you are accessing.

2. Cookies for life

Session or temporary cookies: expire as soon as you sign off, closing your browser.

Persistent or permanent cookies: are those that remain on your device for a certain period or until you delete them.

3. Cookies as to your purpose

Cookies required: are essential for the functioning of the services and resources provided by the website. Without them, the site does not work or perform poorly.

Performance cookies: optimize the usage experience by collecting information about the pages accessed, if they present error etc.

Functionality cookies: memorize your preferences and choices (such as username) 

Advertising cookies: direct ads depending on your interests and limit the number of times the ad appears.

It is important to highlight that the cookie policy should be easily accessible on your website. The link must be available on the homepage itself, preferably in the header or footer. You can also provide the link in the privacy policy (if the cookie policy is not part of it).

Which cookie message formats are most used?

There are different ways to display the cookie message on the site. Check out the main ones: 

  • Cookie message in the footer

On most websites, the footer region contains important information about the page, such as links to the company presentation and other relevant directions. Therefore, many websites keep the cookie warning in this region.

  • Cookie message in header

The message displayed immediately in the page header draws the user's attention. In practice, a dialog box with the necessary information is shown, which will be closed as soon as the person interacts with it. 

  • Sliding Cookie Message

The slide message can be displayed at different points on the screen, and is superimposed on the content until the person gives consent to the storage of cookies.

Other

In addition to these formats presented, we can use creativity to insert the message in different ways, including:

  • floating bar;
  • minimalist message;
  • banner with image.

How to place cookie warning on your website

Many digital subscription marketing platforms have already adapted to LGPD and offer the option to enable cookies that open in pop-ups, using site monitoring codes. 

If your site or blog platform is WordPress, for example, there are several plugins on the internet that can help in this task, as well as online tools that generate a piece of code to be inserted into the page. 

One of the alternatives available is the GPDR plugin. Log in to the WordPress admin panel, access the plugins page, then click “Add New”.

Search for GDPR Cookies Consent Banner and install it. Finally, click “activate” to use it.

Configure plugin 

Now that you have installed the plugin, set it up! To do so, go to the configuration page, then cookies consent, and finally go to settings to make your configuration.

In this environment, you can choose the form of pop-up and its mode of appearance: whether it will close itself with an internal timer or if it will have an X to close.

Click “styles” and choose the color and design of the notification.

If you want to edit the text, just click on the “content” tab and enter the text you want.

You can also create a link written “read more” and buttons like “accept” or “refuse”. And if you just want to show a notification, do not put any button or link.

Made the changes? Just click “Save” and that’s it.

Editing source code

You can also add the cookie message through a source code generated by online tools that make this feature available. One of them is the TermsFeed website, which provides the Cookie Consent Solution tool.

It is essential that this alternative be done by someone with knowledge in web development, as any undue change in the code may compromise the functioning of the site. 

Conclusion

Believe me, this is very important!

There is constant concern about the use of personal data of people who browse the Internet. Therefore, there are existing legislation on the subject, such as LGPD in Brazil and GDPR in Europe. 

Using the cookie message on the website is important to comply with these laws and avoid punishments, such as the payment of fines (which is already valid), among others provided by the legislation.

However, only displaying the cookie message is not enough to ensure that the website provides adequate protection for the data used by the cookie. 

It is worth noting that you need to be hosted in a provider that offers a secure environment with SSL protocol, where server is constantly checked by protection routines.

Displaying the cookie message on the website is a necessary action for pages that use this feature. There are different ways to do this, as with the use of WordPress plugins or by editing the source code. 

In addition, the website must ensure adequate protection of the collected data. So he must be staying in a safe environment.

Finally, be very careful when deciding which information should be included in the cookie messages. Do not overdo technical details that may confuse your visitors, including only the necessary information. 

Dudu Gentil · Nacionalvox

Let's talk

What is your next move?

Tell Nacionalvox what your company wants to transform.

Let's talk