Accepting ‘cookies’ may leave your privacy in crumbs

You browse online for a new pair of leather shoes. Soon afterwards, advertisements for similar footwear begin following you from one website or social media platform to another. Then come the marketing messages or calls.

It may feel coincidental, but the digital trail created by your browsing habits can be far more revealing than many consumers realise.

According to Prof. Danny Myburgh, a cybersecurity expert at the North-West University (NWU), and a specialist in cybersecurity and digital forensics, clicking “accept all” on a cookie banner can allow more than the basic functions needed to operate a website. Depending on the site and the permissions granted, it may also activate third-party tracking technologies capable of monitoring behaviour across different online platforms.

“What people often fail to realise is that blindly accepting all the terms and conditions may also activate third-party trackers built into the website,” he says.

“This creates persistence across websites, allowing browsing habits to be identified. Inadvertently, you may be sharing quite a lot about your online presence across multiple platforms.”

Cookies are small files placed on a device when someone visits a website. Some are essential: they keep users signed in, remember shopping baskets or store language preferences. Others are used for analytics, personalisation and targeted advertising.

These tracking technologies may identify the type of device being used, whether it is a computer, tablet or mobile phone, and connect activity across websites to construct a detailed consumer profile.

“They can identify whether you are browsing from a Mac, a PC or your phone,” says Myburgh. “They can also match your online activity and browsing history to build a profile of you, and that information may be stored for many years.”

From browsing history to marketing lead

Cookie data does not necessarily contain someone’s name or telephone number. However, when it is combined with information from other sources, an apparently anonymous record can become considerably more revealing.

Myburgh says data collected online may be shared with data-management platforms and advertising exchanges, where it can be analysed, traded or matched with other information.

“If you browse online to buy leather shoes, for example, you may suddenly see more and more advertisements for them,” he says.

“Some marketers buy records from these sites and may combine them with information available through other databases, including databases originating from data breaches and being sold on the dark web.”

This process, sometimes referred to as data enrichment, brings separate pieces of information together to create a more complete picture of an individual. Browsing interests, device identifiers, contact details and information exposed in previous breaches can potentially be cross-referenced.

“They use this information to build a profile of a person or the communication device being used,” says Myburgh. “That may enable them to make cold calls or use algorithms to push more of a particular product through social media platforms and other online channels.”

This does not mean every company using cookies sells personal information to telemarketers, nor that accepting a cookie directly hands over a telephone number. The concern lies in the wider data ecosystem and the ability to connect information collected from numerous sources.

Did you genuinely consent?

Consumers are regularly confronted with lengthy privacy notices written in language few people have the time or inclination to examine. In practice, accepting the conditions is often treated as the quickest route to the content or service they want.

From a legal perspective, however, clicking the consent button can carry weight.

“It is similar to entering into a contract in which you permit an organisation to do certain things,” says Myburgh. “By consenting, you could give it significant legal grounds to use your information in the ways described.”

Consent is not necessarily beyond challenge merely because a box was ticked. South Africa’s Protection of Personal Information Act (POPIA), as well as legislation such as the European Union’s General Data Protection Regulation, places obligations on organisations that collect and process personal information.

“Even when consent is given, it must be informed and cannot be forced,” says Myburgh. “There are open questions about whether some of these terms and conditions can be enforced, particularly when consumers do not realistically understand what they are accepting.”

He says there is growing pressure for consumer contracts and online notices to be written in plain, understandable language.

“There is definitely a drive to protect consumers against lengthy terms and conditions, especially where people feel they have little choice but to accept them if they want to get anything done. A request for consent should state clearly what permission is being requested.”

Take back some control

Myburgh’s first recommendation is simple: stop treating “accept all” as the default choice.

“I try to reject all non-essential cookies,” he says. “Instead of accepting everything, accept only what is genuinely necessary. Make a habit of not selecting all cookies and use the ‘reject’ option where it is available.”

Rejecting optional cookies should not ordinarily prevent access to a website, although users may repeatedly be asked to select their preferences and some personalised functions may be lost.

Consumers can also activate privacy controls in browsers and applications, use global opt-out signals where supported, and ask platforms not to track their activity across the internet.

“If a platform provides an option to opt out of data-broker activity or personalised marketing, use it,” says Myburgh. “If you receive marketing from an organisation and did not request it, unsubscribe or tell the organisation that you are opting out.”

Where unwanted marketing persists, consumers may formally ask an organisation to remove their information from mailing lists and direct-marketing campaigns in terms of applicable data-protection legislation.

The lesson is not that every cookie is dangerous. It is that convenience should not be confused with informed consent.

The next time a website presents two choices — “accept all” or “manage preferences” — those extra few seconds may be worth taking.

Prof. Danny Myburgh

Prof. Danny Myburgh

Submitted on