yalla-coop / chiltern-website

0 stars 0 forks source link

Cookiebot report #105

Closed katieshuster closed 9 months ago

katieshuster commented 1 year ago

This isn't really a feature request but please could someone have a look at this cookibot report and see if we need to change anything on the site? Email below. Thank you!

Please find attached your Cookie Report.

Our recent scan of your website has identified potential compliance issues where cookies are being set in your users’ browsers before their consent has been submitted. Under GDPR and other legislations, only cookies that are strictly necessary for the website to function can be set prior to the user’s consent.

Domain Group: Domain Group #1 Domains: www.chilternmusictherapy.co.uk (04/04/2023) - Prior consent fully enabled: no

Based on your scan report we have identified one or more of the following issues:

Other scripts that may be setting cookies are loaded before the Cookiebot script Make sure that the Cookiebot script is the very first script to load on your website. This is essential for our script’s ability to hold back cookies until consent has been obtained.

Some scripts on your website may not be marked up properly Check the attached report to find out which scripts are loaded before consent and see our guide on how to mark these up manually. Consider switching to autoblocking mode, if you haven’t already done so, to let the Cookiebot script handle all the technical stuff automatically.

Some scripts may be loaded through Google Tag Manager before consent has been submitted Make sure your GTM is set up to use Cookiebot consent values before loading tags that may set cookies. See our GTM installation guide here.

Your website uses cookies set by your webserver before user consent has been obtained In your Cookie Report you may have cookies that are set by your webserver, also known as “server-side cookies”, these are marked like this:

Initiator: Webserver

These you will have to block through server-side code, holding back the cookies until consent has been given. You may have to contact your webhost or web solution vendor to find out more about these cookies. See the last part of our developer documentation for server-side usage of Cookiebot.

Unclassified cookies Your report shows one or more unclassified cookies. You must log into your account and categorize these appropriately and add a description to ensure transparency to your website users. See more about unclassified cookies and how to work with them.

Still having problems with missing prior consent?

In cases where none of the points above apply, we would be very happy to take a closer look at the problem and have our technicians investigate the issue. Please contact Cookiebot Technical Support and tell us about the issue – just reply to this email and we will get back to you as soon as possible.

Thank you for using Cookiebot!

Best regards, The Cookiebot Team

Team - do not edit @thejoefriel @fadeomar @@Israa91

cyberteenie commented 1 year ago

@katieshuster - I will have the dev team have a look and get back to you!

fadeomar commented 1 year ago

generally, I think everything is fine, and not sure what action should do from our side maybe your inputs @thejoefriel OR @RamyAlshurafa would be helpful, also @katieshuster can you send the login details to @cyberteenie to Cookiebot

katieshuster commented 1 year ago

Thanks for looking into it. @cyberteenie I have shared the login details with you

RamyAlshurafa commented 1 year ago

Hey @katieshuster, Can you share the report attached to the email, please?

katieshuster commented 1 year ago

Hey @RamyAlshurafa it won't let me attach the file but I will email it to you

cyberteenie commented 1 year ago

@katieshuster - I just wanted to double check, is this issue now ready to be closed?

katieshuster commented 1 year ago

Hi @cyberteenie I'm not sure if I've had an update about this yet - unless I've missed it somewhere?

cyberteenie commented 1 year ago

Ah, ok! Let me speak to the team and get back to you.

On Wed, May 31, 2023 at 4:52 PM Katie Dunne @.***> wrote:

Hi @cyberteenie https://github.com/cyberteenie I'm not sure if I've had an update about this yet - unless I've missed it somewhere?

— Reply to this email directly, view it on GitHub https://github.com/yalla-coop/chiltern-website/issues/105#issuecomment-1570389403, or unsubscribe https://github.com/notifications/unsubscribe-auth/AXHQJWUSE5ID3PNWLPSNC5DXI5LKPANCNFSM6AAAAAAWT32HCI . You are receiving this because you were mentioned.Message ID: @.***>

-- Kristina Jaggard Design and Project Management at Yalla Cooperative yallacooperative.com https://github.com/yalla-coop/internal/issues/yallacooperative.com (she / her / hers)

cyberteenie commented 1 year ago

Actually @katieshuster would you mind please also forwarding the email to me? That way I can be sure that someone from the team can look at it.

katieshuster commented 1 year ago

@cyberteenie I've just forwarded the email

cyberteenie commented 1 year ago

Thanks Katie!

cyberteenie commented 1 year ago

Just to update you @katieshuster - @RamyAlshurafa is looking into this but he was blocked from making some of the suggested changes. Another member is going to be updating Google Analytics this weekend as that is what may be causing an issue. We will keep you updated!

cyberteenie commented 1 year ago

@katieshuster - just wanted to let you know that Ramy submitted a support request directly with Cookiebot and will update us once they reply

cyberteenie commented 1 year ago

Just updating this issue to say that Ramy has fixed the a prior consent issue. I am now conducting research on the problem of transmitting data to "adeduate" countries only

cyberteenie commented 1 year ago

Tracking this here as part of the research, but more research needed: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en#:~:text=The%20European%20Commission%20has%20so,Uruguay%20as%20providing%20adequate%20protection.

cyberteenie commented 9 months ago

Closing this issue as the cookies that were sending data to inadequate regions have been removed since the last scan.