News
Tracking trouble: AS Watson's €600,000 fine and Google’s Privacy Sandbox under scrutiny
Recently, two notable cases have emerged demonstrating that the consent requirement for cookies is not always adhered to. The Dutch Data Protection Authority (AP) fined AS Watson B.V., the parent company of the Dutch drugstore chain Kruidvat, €600,000 for placing tracking cookies on Kruidvat.nl without the required consent. At the same time, concerns are being raised about Google’s Privacy Sandbox, which critics claim is also not fully compliant with the consent requirement.
In this article, we will discuss these two recent cases. Additionally, we will delve into future regulations regarding cookies and the subsequent consent requirements. We will conclude with some practical tips.

Cookie Legislation
From Directive to Regulation
Currently, cookies are governed by the GDPR and the e-Privacy Directive. In the Netherlands, the e-Privacy Directive has been implemented via the Telecommunications Act. However, the 2002 e-Privacy Directive is due for replacement. The long-awaited successor is the e-Privacy Regulation. The exact implementation date for this regulation is still uncertain; member states are currently still negotiating some articles.
The arrival of the e-Privacy Regulation will replace the relevant provisions in the Dutch Telecommunications Act. Unlike a directive, a regulation is directly applicable in all EU member states, without the need for transposition into national law.
The New Cookie Rules
The e-Privacy Regulation aims to make the use of cookies simpler and more user-friendly. Cookies that have a limited impact on privacy can still be placed without consent. However, consent will still be required for tracking cookies. The current strict rules result in an abundance of different cookie notices that users have to deal with. To make this more user-friendly, the new rules encourage browser developers and mobile operators to add a ‘tracking consent option’. This allows users to set their privacy preferences once in their browser instead of on each individual website. Much more convenient!
Many browsers have already adapted to this. For example, Safari and Firefox block third-party tracking cookies by default. These cookies are placed by companies not directly involved with the website you are visiting, usually for targeted advertising purposes. Google had also announced it would ban third-party tracking cookies in Chrome by default but recently revised this plan. More on this can be read below.
Consent Requirement
Websites must inform their visitors about the use of cookies. Additionally, consent must be obtained for the use of cookies. Exceptions to this requirement are cookies that are strictly necessary for the functioning of the website or analytical cookies with limited privacy impact. Analytical cookies, for instance, help in collecting visitor statistics to improve website performance.
Tracking cookies follow and analyze users’ browsing behavior over an extended period, thus impacting privacy. Consent is required for tracking cookies and analytical cookies with privacy implications. Consent for this cookies must be given freely, specifically, informed, and unambiguously. This is a strict requirement. For example, using pre-checked boxes or silence does not count as valid consent, a mistake many companies make.
This was also the case with Kruidvat.nl.
The Violation by Kruidvat.nl
The AP discovered that Kruidvat.nl was placing tracking cookies without valid consent from visitors. Additionally, the boxes for tracking cookies were pre-checked in the cookie banner, which is also in conflict with the consent requirement from the GDPR.
The AP’s investigation report shows:
- When visiting Kruidvat.nl, cookies were placed on the user's device before they had given consent.
- The cookie banner had the “agree” box pre-selected by default, making users automatically (by default) consent to the placement of advertising (tracking) cookies. The cookie banner was also complex and required users to go through several steps before cookies could be refused, making their choice not genuinely ‘free’.
These findings led the AP to conclude that AS Watson was guilty of unlawful data processing with its website Kruidvat.nl. As a result, a fine of €600,000 was imposed.
Google’s Privacy Sandbox: Improvement or Privacy Washing?
Google also fases criticism regarding compliance with the consent requirement. The company introduced the Privacy Sandbox as a privacy-friendly alternative to third-party cookies in its Chrome browser, aiming to eliminate these cookies entirely. Users could activate this new feature with the “Turn on ad privacy features” button. However, critics argue that this so-called ‘ad privacy feature’ is not as privacy-friendly as claimed. Instead of eliminating third-party tracking cookies, it shifts tracking to first-party tracking within Chrome itself, managed by Google. By labeling this as a ‘privacy feature,’ users may be misled, resulting in no free, specific, informed, and unambiguous consent.
Max Schrems, a prominent privacy lawyer and activist, expressed his concerns:
“People are increasingly critical of the fact that big tech companies are making billions from invasive ad tracking technologies. Instead of actually improving the situation, Google is responding with a kind of unlawful ‘privacy washing’ by introducing a new tracking system.”
Recently, Google decided not to completely ban third-party cookies after all. Instead, the company will request explicit consent from Chrome users for the use of these cookies. Meanwhile, Google continues to work on alternatives for third-party cookies with its Privacy Sandbox, hopefully this time genuinely privacy-proof.
Practical Advice
In practice, many companies still struggle with the correct application of legal cookie rules. The use of pre-checked consent boxes and unclear cookie banners is common, despite being illegal. Such practices lead to unlawful data processing and can result in significant fines and reputational damage. It is important for companies to regularly review their cookie policies and ensure compliance with current regulations to avoid such mistakes.
Here are some key lessons:
- Clear Information: Ensure your cookie banner provides clear information about the purpose of the cookies and what data is collected.
- Active Consent: Do not use pre-checked boxes. Users must actively give consent.
- Easy Opt-Out: Make it easy for users to refuse cookies.
Conclusion
The fine imposed on AS Watson for unlawful use of tracking cookies highlights the importance of compliance with legal rules. Companies must be transparent about their cookie use and ensure that consent is obtained correctly. This not only prevents legal consequences but also helps maintain customer trust.
AS Watson has now made the necessary adjustments, ensuring that only strictly necessary cookies are pre-checked by default in the cookie banner on its Kruidvat.nl website. Hopefully, Google will also take the criticism seriously and provide a true ‘privacy feature’ with its Privacy Sandbox.
Craving a cookie after reading this article? Don’t worry, you don’t need consent for that!
The AP’s fine decision regarding AS Watson can be read here (in Dutch):
www.autoriteitpersoonsgegevens.nl/documenten/besluit-boete-as-watson-kruidvat.
Article provided by INPLP members: Bob Cordemeyer, Hanneke Slager and Emmely Schaaphok (Cordemeyer & Slager Advocaten B.V., Netherlands)
Discover more about the INPLP and the INPLP-Members
Dr. Tobias Höllwarth (Managing Director INPLP)
News Archiv
- Alle zeigen
- Jänner 2025
- Dezember 2024
- November 2024
- Oktober 2024
- September 2024
- August 2024
- Juli 2024
- Juni 2024
- Mai 2024
- April 2024
- März 2024
- Februar 2024
- Jänner 2024
- Dezember 2023
- November 2023
- Oktober 2023
- September 2023
- August 2023
- Juli 2023
- Juni 2023
- Mai 2023
- April 2023
- März 2023
- Februar 2023
- Jänner 2023
- Dezember 2022
- November 2022
- Oktober 2022
- September 2022
- August 2022
- Juli 2022
- Mai 2022
- April 2022
- März 2022
- Februar 2022
- November 2021
- September 2021
- Juli 2021
- Mai 2021
- April 2021
- Dezember 2020
- November 2020
- Oktober 2020
- Juni 2020
- März 2020
- Dezember 2019
- Oktober 2019
- September 2019
- August 2019
- Juli 2019
- Juni 2019
- Mai 2019
- April 2019
- März 2019
- Februar 2019
- Jänner 2019
- Dezember 2018
- November 2018
- Oktober 2018
- September 2018
- August 2018
- Juli 2018
- Juni 2018
- Mai 2018
- April 2018
- März 2018
- Februar 2018
- Dezember 2017
- November 2017
- Oktober 2017
- September 2017
- August 2017
- Juli 2017
- Juni 2017
- Mai 2017
- April 2017
- März 2017
- Februar 2017
- November 2016
- Oktober 2016
- September 2016
- Juli 2016
- Juni 2016
- Mai 2016
- April 2016
- März 2016
- Februar 2016
- Jänner 2016
- Dezember 2015
- November 2015
- Oktober 2015
- September 2015
- August 2015
- Juli 2015
- Juni 2015
- Mai 2015
- April 2015
- März 2015
- Februar 2015
- Jänner 2015
- Dezember 2014
- November 2014
- Oktober 2014
- September 2014
- August 2014
- Juli 2014
- Juni 2014
- Mai 2014
- April 2014
- März 2014
- Februar 2014
- Jänner 2014
- Dezember 2013
- November 2013
- Oktober 2013
- September 2013
- August 2013
- Juli 2013
- Juni 2013
- Mai 2013
- April 2013
- März 2013
- Februar 2013
- Jänner 2013
- Dezember 2012
- November 2012
- Oktober 2012
- September 2012
- August 2012
- Juli 2012
- Juni 2012
- Mai 2012
- April 2012
- März 2012
- Februar 2012
- Jänner 2012
- Dezember 2011
- November 2011
- Oktober 2011
- September 2011
- Juli 2011
- Juni 2011
- Mai 2011
- April 2011
- März 2011
- Februar 2011
- Jänner 2011
- November 2010
- Oktober 2010
- September 2010
- Juli 2010