DEFRA / design-discussions

2 stars 2 forks source link

Cookies policy and consent #9

Open cathydutton opened 4 years ago

cathydutton commented 4 years ago

What

Help users manage their personal data by telling them when you store cookies on their device.

Why

We must have users consent to store cookies or similar technologies on their device

How

cathydutton commented 4 years ago

image

matthewsolle commented 4 years ago

Reference

https://www.gov.uk/service-manual/technology/working-with-cookies-and-similar-technologies

https://docs.publishing.service.gov.uk/manual/cookie-consent-on-govuk.html

https://github.com/alphagov/govuk-design-system-backlog/issues/12

https://github.com/alphagov/govuk-design-system-backlog/issues/13

tomf87 commented 4 years ago

Just so everyone's aware, on the design system call I took part in I heard that GDS have no plans to work on a pattern for cookie banners until after they've looked at a technical solution to share cookies across departmental sites, which could take up to two years from now.

tomf87 commented 4 years ago

Pretty sure pattern 6 would be non-compliant under a stricter interpretation of GDPR, as the button design leads the user towards accepting cookies.

cathydutton commented 4 years ago

Pretty sure pattern 6 would be non-compliant under a stricter interpretation of GDPR, as the button design leads the user towards accepting cookies.

Thats the one Gov.uk blogs are now using

cathydutton commented 4 years ago

This is from the DWP backlog, I think its a good way of communicating the different flows and messages.

The part I'm unsure about is how users update their preferences. Is it enough to have that option buried in the cookies page?

75032943-a866d200-54a1-11ea-9c00-24195eefdf42

tomf87 commented 4 years ago

Pretty sure pattern 6 would be non-compliant under a stricter interpretation of GDPR, as the button design leads the user towards accepting cookies.

Thats the one Gov.uk blogs are now using

Yeah I think it depends how you interpret the policy, I'm just mentioning it because where I worked before we decided to avoid using different button styles as we wanted to avoid introducing any bias.

cathydutton commented 4 years ago

Pretty sure pattern 6 would be non-compliant under a stricter interpretation of GDPR, as the button design leads the user towards accepting cookies.

Thats the one Gov.uk blogs are now using

Yeah I think it depends how you interpret the policy, I'm just mentioning it because where I worked before we decided to avoid using different button styles as we wanted to avoid introducing any bias.

Good point, theres a thread on dark patterns around consent here - https://twitter.com/yahoo_pete/status/1230562192144994307.

I wonder if we need 3 buttons Accept all, Reject all and manage preferences?

jOnoNe commented 4 years ago

With the absence of cookie sharing across urls, is there anything we can do to reduce the need for users clicking multiple banners in the same cross-domain journey?

cathydutton commented 4 years ago

Collated examples of current designs from across Gov

cookie-consent

peter-jordan commented 4 years ago

Going back to the comments on the GOV.UK blogs design. A quick and crude comparison of the 'before' and 'after' volume of sessions shows that www.gov.uk is getting around twice as much acceptance of cookies compared to the blogging platform.

So you could argue words as much as button styles.

peter-jordan commented 4 years ago

@cathydutton What URL got you the 'Can I get Legal Aid?'/ Notify banner? I can't replicate it.

cathydutton commented 4 years ago

With the absence of cookie sharing across urls, is there anything we can do to reduce the need for users clicking multiple banners in the same cross-domain journey?

Is this happening with services using IDM? May be worth asking wider Gov teams to see if anyone else has dealt with this.

cathydutton commented 4 years ago

@cathydutton What URL got you the 'Can I get Legal Aid?'/ Notify banner? I can't replicate it.

I got it from a Slack thread so not sure how you get to it.

cathydutton commented 4 years ago

@jOnoNe - planned work to look into this at GDS - https://www.gov.uk/service-manual/technology/working-with-cookies-and-similar-technologies#discovery-into-remembering-consent-across-domains-and-subdomains

cathydutton commented 4 years ago
Screen Shot 2020-03-18 at 12 13 17

DVSA example - using two buttons instead of a link for settings

cathydutton commented 4 years ago

flow

MalcolmVonMoJ commented 4 years ago

In Check if you can get Legal Aid, we were using pattern number 3 until recently.

We have now changed to this pattern as an interim whilst research is ongoing, so it might not be our final decision.
image

Our reasoning for choosing this was:

So, we kept the current choices (yes/settings) and only amended the look and feel of the banner for the now. Our brilliant user researcher and exquisite content designer have not put this to bed yet and are continuing to look at all the above points.

However, the moment we made this change (March 6th, 2 weeks ago today), we noticed a significant increase in users accepting cookies. Approximately double. This still only puts us at 40% of pre-GDPR levels in round figures.

Google Analytics details: image

cathydutton commented 4 years ago
Screen Shot 2020-03-25 at 12 45 06

Latest update from Gov.uk

cathydutton commented 4 years ago

Artboard