yalla-coop / shannon-trust-website

0 stars 0 forks source link

Cookiebot GDPR compliance #100

Closed ShannonTrust closed 10 months ago

ShannonTrust commented 1 year ago

Please select the priority level by adding one of the following labels to this issue?

Priority-2 (High e.g. Core functionality is not working)

Describe the bug and the expected behaviour.

We received an email from Cookiebot today explaining that the way we collect cookies might not be GDPR compliant, as cookies are being collected before people consent. Email attached below.

Steps To Reproduce

No response

Screenshots or a link to a Loom Recording

Cookie scan report October 2023.pdf

What browsers are you seeing the problem on?

Other

Anything else?

No response

cyberteenie commented 1 year ago

Thanks for adding this to Github @ShannonTrust - we are looking into this!

cyberteenie commented 1 year ago

Hi @ShannonTrust - I really apologise for the delay on this. As you can expect, the last month has been a bit full on due to the war in Gaza. Please know that we are working on this and we aim to get this sorted for you before the end of the month.

ShannonTrust commented 1 year ago

Hi @cyberteenie, no need to apologise, we completely understand. Thank you for the update though.

redahaq commented 1 year ago

Hi @ShannonTrust, thank you so much for your patience. This should be fixed now - I'm running a Cookiebot scan so you may get a report in the next 24hrs or so, just FYI.

cyberteenie commented 1 year ago

@ShannonTrust - let us know if the report looks good and we can close this issue!

ShannonTrust commented 1 year ago

Thanks, @redahaq and @cyberteenie. No issues were flagged on the new report. Thanks for sorting.

ShannonTrust commented 11 months ago

@cyberteenie - this issue seems to have come up again on our most recent report, can you look into it again, please?

Cookie scan report December 2023.pdf

cyberteenie commented 11 months ago

@ShannonTrust - I think this may actually be due to Google Analytics, but let me speak to Ramy and get back to you on this!

redahaq commented 10 months ago

Hi @ShannonTrust, cc @cyberteenie; so the reason this issue came up again was due to the embedded YouYube video on the Big Give Christmas Challenge story - the YouTube cookies have now been classified and prior consent is required before displaying the embedded video.

I've reviewed the lastest Cookiebot scan report, and there doesn't seem to be a a prior consent issue any more but please let me know if any issues have come up in Jan's report, as you are emailed a more detailed report than what is available by logging in to Cookiebot. If all is clear we can close the issue.

For future YouTube embedded videos, we'd recommend ticking the 'Enable enhanced privacy mode' checkbox. This prevents the tracking cookies being added.

Screenshot 2024-01-12 at 03 29 21
ShannonTrust commented 10 months ago

Thanks, @redahaq. That's really useful to know. Nothing was flagged in our latest report, so thanks for looking into this.