28th May 2013
CEI Compliance: Email Signatures and Cookies
In the UK we are legally required to include certain information in every email that we send, if the email is being sent by a UK Company. Not everyone includes all of the information in their email signature and, in theory at least, you can be fined for not including this information.
Email Mandatory information
If your business is a private or public limited company or a Limited Liability Partnership, the Companies Act 1985 requires all of your business emails (and your letterhead and order forms) to include the following details in legible characters:
- Your company's registered name (e.g. XYZ Ltd)
- Your company registration number;
- Your place of registration (e.g. Scotland or England & Wales); and
- Your registered office address
This information should also appear on your company's website (and for an overview of other information that is required on a website, see our guide to the UK's E-commerce Regulations). Failure to comply with these requirements puts a company at risk of a fine of £1,000.
The duty has existed for business letters for many years. But some people were unsure whether this duty extended to email communication. Any doubt was removed by an amendment to the Companies Act 1985 that took effect on 1st January 2007. The duty is now contained in the Companies (Trading Disclosures) Regulations 2008, which came into force on 1st October.
It is not enough to provide a link to this information from an email footer. The Regulations provide that any ‘display’ or disclosure of information required by the Regulations must be "in characters that can be read with the naked eye."
Not all emails will be relevant to your business but most companies will find it easier to add the information to all outgoing emails, including those messages that forward or reply to any third party's email.
Cookies
On reviewing some adviser's websites I am surprised to see, even after 2 years, the number of them that have no cookie disclaimer/explanation on their pages. These should be on all pages where a client can land from a search or other link.
The EU cookie law is a piece of privacy legislation that was originally adopted by all EU countries on May 26th 2011. The UK was given one year to comply with the EU directive after it updated its Privacy and Electronic Communications Regulations, which brought the EU directive in to UK law.
The cookie law originally required websites to gain consent from visitors to store or receive any information on a computer or any other web connected devices (e.g. smartphone or tablet). The cookie law has been designed to protect online privacy of customers by making them aware, and giving them a choice, about the amount of information collected by websites. Each EU member has its own approach to the law; however the basic requirements of the directive remain the same.
The Information Commissioners Office (ICO) is responsible for ensuring that organisations comply with the cookie law. The ICO has issue two sets of guidelines, so far, with the latest one reminding those concerned that the law ‘will not go away.’ However, the ICO has tempered it's original guidance, stating in January 2013; "that anyone who visits its website from "the end of January" will receive cookies. It said individuals will be given "clear, detailed information" about what cookies have been set and will also be given access to an "easy way to remove them" if they do not want them set on their machines or devices." (source: http://www.out-law.com/en/articles/2013/january/ico-to-change-cookie-policy-to-recognise-implied-consent)
After May 26th 2012 if a business is not compliant, or is not visibly working towards compliance, it will run the risk of enforcement action and a possible fine of up to half a million pounds.
The ICO's move should not be seen as permission to ignore this bumbling and ill defined law. You still need to take action in line with the latest guidance.
What to Do Even If You Don't Have Subscribers or Client Areas
The problem for most firms is that they may not have subscribe options, client private areas or other data logging that is visible, and may think that the law does not apply. Log files are generated by system processes to record activities for subsequent analysis. They can be useful tools for troubleshooting system problems and also to check for inappropriate activity. If you have a website it will use Log Files. The information in the log files include IP (internet protocol) address, ISP (internet service provider, such as AOL, BT, Virgin etc), the browser used to visit your site (such as Internet Explorer, Chrome, Safari, Firefox etc), the time you visited the site and which pages you visited throughout the site.
You may use cookies to store information, such as visitors personal preferences when they visit the site but you should inform them which ones, and how to remove them should they wish to.
You may use third party advertisements to support your site. Some of these advertisers may use technology such as cookies and web beacons when they advertise on our site, which will also send these advertisers (such as Google through the Google AdSense program) information including IP address, ISP , the browser used to visit the site, and in some cases, even whether you have "Flash" installed. This is generally used for geotargeting purposes (showing London property ads to someone in London, for example) or showing certain ads based on specific sites visited (such as showing cooking ads to someone who frequents cooking sites).
You could also use DART cookies for ad serving through Google’s DoubleClick, which places a cookie on your computer when you are browsing the web and visit a site using DoubleClick advertising (including some Google AdSense advertisements). This cookie is used to serve ads specific to you and your interests (“interest based targeting”). The ads served will be targeted based on your previous browsing history (For example, if you have been viewing sites about visiting Paris, you may see Paris hotel advertisements when viewing a non-related site, such as on a site about fishing). DART uses “non personally identifiable information”. It does NOT track personal information about visitors, such as name, email address, physical address, telephone number, bank account numbers or credit card numbers. If you do use any third party advertisements such as Google or Amazon, you will need to include a privacy policy section as part of the terms of service, where visitors can opt-out of this ad serving on all sites using this type of advertising by visiting http://www.doubleclick.com/privacy/dart_adserving.aspx
Visitors can choose to disable or selectively turn off your cookies or third-party cookies in their browser settings, or by managing preferences in programs such as Norton Internet Security. However, this can affect how you are able to interact with our site as well as other websites. This could include the inability to login to services or programs, such as logging into forums or accounts.
Deleting cookies does not mean you are permanently opted out of any advertising program. Unless you have settings that disallow cookies, the next time you visit a site running the advertisements, a new cookie will be added.
Your web hosting provider should be able to implement a script that explains the status of cookies and giving an option to learn more or opt out. Ideally this could be included only showing them a popup or strip banner once in their visit.
Sources: http://www.ico.org.uk/news/current_topics/changes-to-cookies-on-our-website
http://www.doubleclick.com/privacy/dart_adserving.aspx
For more information about CEI Compliance and the services they offer, please click here
Not yet registered?
Please complete this form to join our community