ICO under fire over plans to urge G7 to tackle cookie pop-ups
The Open Rights Group says the data regulator should "follow its own conclusions and enforce the law"


The UK's Information Commissioner Elizabeth Denham is set to ask data regulators from G7 countries to join forces against online cookie pop-ups.
Denham will meet with her counterparts on Tuesday, with each country set to raise a technology problem they believe can be solved with close collaboration. However, privacy experts feel the ICO could be doing more to tackle the cookie problem itself.
Cookie pop-ups are seen as an annoying obstacle by most internet users, but privacy advocates and regulators feel there is something more nefarious about them. They suggest they can be used to 'trick' users into accepting privacy invasions rather than reading through a long list of settings for each website they visit.
"There are nearly two billion websites out there taking account of the world's privacy preferences," Denham said. "No single country can tackle this issue alone. That is why I am calling on my G7 colleagues to use our convening power. Together we can engage with technology firms and standards organisations to develop a coordinated approach to this challenge."
The ICO added that it envisions a future where web browsers, applications and device settings allow people to set lasting privacy preferences of their choosing, "rather than having to do that through pop-ups every time they visit a website."
RELATED RESOURCE
The Forrester Wave: Top security analytics platforms
The 11 providers that matter most and how they stack up
The call to tackle cookie pop-ups has backing from many in the tech industry, but there are questions being asked of the ICO and the UK government about its own enforcement of the "unlawful" data collection practices of cookie banners.
Johnny Ryan, the chief policy officer for the privacy-focused browser Brave, suggested the ICO's plan was "daft" because the government could have fixed the cookie problem "before Brexit". He has previously pointed out that it is already illegal under GDPR and that the ICO just needs to do more enforcing itself.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Jim Killock, the executive director of the Open Rights Group, also suggested the ICO should be doing more. He said that Denham's own reports have stated that most cookie banners and the data collection behind them are unlawful.
"If the ICO wants to sort out cookie banners then it should follow its own conclusions and enforce the law," Killock said. "We have waited for over two years now for the ICO to deal with this, and now they are asking the G7 to do their job for them. That is simply outrageous. We fully support their call for automated signals, but in the meantime they should enforce the law, which is their job."
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Third time lucky? Microsoft finally begins roll-out of controversial Recall feature
News The Windows Recall feature has been plagued by setbacks and backlash from security professionals
By Emma Woollacott Published
-
The UK government wants quantum technology out of the lab and in the hands of enterprises
News The UK government has unveiled plans to invest £121 million in quantum computing projects in an effort to drive real-world applications and adoption rates.
By Emma Woollacott Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly Published
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard Published
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page Published
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones Published
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard Published
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston Published