General warning on compliance with legal obligations regarding transparency and information on the processing of personal data on websites
The Information and Privacy Agency (AIP), within the framework of its legal mandate and inspection plan for the implementation of Law No. 06/L-082 on the Protection of Personal Data, has identified that a number of controllers operating through websites have not established adequate mechanisms for transparency and information on the processing of personal data during users' visits to those websites.
It has been particularly noted that some websites lack an initial notice on the use of cookies, a cookie policy, and clear, complete and accessible information on the fact that visitors' personal data may be collected and processed during their visit to the website. This may include IP address, online identifiers, device data, data on users' behavior on the website, as well as other data that, according to applicable legislation, are considered personal data.
We remind you that, as a controller, you have an obligation to process personal data in accordance with the principles of lawfulness, fairness and transparency, and to ensure that the data subject is clearly, accurately and in a timely manner informed of any processing of their personal data.
For this reason, you are required to take the necessary measures to comply with legal obligations, ensuring that:
• your website contains a clear, complete and easily accessible privacy policy;
• your website contains a specific cookie policy, in cases where cookies or similar technologies are used;
• website visitors are informed already when entering the site about the use of cookies and other tracking technologies;
• the information includes at least the types of data collected, the purposes of the processing, the legal basis, the categories of cookies, the period of their storage, the recipients or categories of recipients of the data, as well as the rights of the data subject;
• in cases where necessary cookies requiring consent are used, this consent must be obtained in advance, freely, specifically, informed and unambiguously.
We inform you that AIP has established mechanisms and tools for the identification, verification and inspection of websites that process personal data without informing data subjects in accordance with the requirements of Law No. 06/L-082 on the Protection of Personal Data.
As part of these activities, websites that collect personal data through cookies, IP addresses, online forms, analytical tools, plug-ins and other similar technologies, without ensuring the necessary transparency towards their visitors, will be systematically checked.
This notice is a general warning before initiating inspections of controllers operating through websites and processing personal data without fulfilling legal obligations regarding information and transparency.
In cases where irregularities or violations of the provisions of Law No. 06/L-082 on the Protection of Personal Data, all findings will be analyzed by the Agency and, in accordance with the legal competences and the nature of the violations identified, appropriate measures will be taken in accordance with the law, including the imposition of penalties.
The lack of a privacy policy, the lack of a cookie policy, the lack of prior notification of the use of cookies and similar technologies, as well as the lack of information on the processing of personal data during a visit to the website constitute a failure to comply with the obligations arising from Law No. 06/L-082 on the Protection of Personal Data and violate the right of the data subject to be informed about the processing of their personal data.
Therefore, you are requested to take all necessary actions within 15 days from the date of receipt of this notification to comply with the legal requirements of your website and to ensure that the information provided to data subjects is complete, clear and in accordance with the law.
Upon the expiry of this period, the Agency will continue to conduct supervisory and inspection activities in accordance with the inspection plan and its legal competences.