{"id":1423,"date":"2022-03-29T08:34:00","date_gmt":"2022-03-29T08:34:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=1423"},"modified":"2026-03-12T09:14:45","modified_gmt":"2026-03-12T08:14:45","slug":"eu-pharmacy-report","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/eu-pharmacy-report\/","title":{"rendered":"Cookiebot CMP uncovers pharmacy GDPR violations"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-lack-of-transparency-on-webshops-handling-sensitive-data\">Lack of transparency on webshops handling sensitive data<\/h2>\n\n\n\n<p>In a <a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">new scan report<\/a>, <a href=\"https:\/\/usercentrics.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Usercentrics<\/a> scanned <strong>150 popular online pharmacies in 10 EU countries<\/strong> using the scanning technology of its product <a href=\"\/\">Cookiebot CMP<\/a> and found that <strong>89%<\/strong> violated the EU\u2019s General Data Protection Regulation (GDPR) by <strong>processing sensitive personal data without the prior and explicit consent of their end-users<\/strong>, who visit the webshops to browse and buy privacy-sensitive medicines, pharmaceutical products and alternative remedies for their mental and physical health.<\/p>\n\n\n\n<p>Breaking consumer trust, risking damage to brand reputation and breaching core requirements of the EU\u2019s General Data Protection Regulation (GDPR), the pharma e-commerce market in Europe, <a href=\"https:\/\/www.businesswire.com\/news\/home\/20201117006020\/en\/Pharma-E-commerce-Market-In-Europe-to-grow-by-10.69-bn-during-2020-2024-Industry-Analysis-Market-Trends-Market-Growth-Opportunities-and-Forecast-2024-Technavio\" target=\"_blank\" rel=\"noopener\">poised to grow by \u20ac9 bn during 2020-2024<\/a>, paints a disturbing picture of massive data privacy abuse and compliance failures \u2013 three years after the GDPR took effect across the region.<\/p>\n\n\n\n<p>To see the key findings and download the full special report by Usercentrics, <a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">click here<\/a>.<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Download the full pharma e-commerce report by Usercentrics <\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4427\/pharma-report-blog2.jpg?width=500&amp;4\" alt=\"Illustration of laptop with medication and websites - Cookiebot\" width=\"500\" height=\"334\"\/><figcaption class=\"wp-element-caption\">Processing sensitive personal data (like health data) without end-user consent is breach of the EU\u2019s GDPR.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-who-are-the-150-most-popular-pharmacy-webshops-in-the-eu\">Who are the \u201c150 most popular\u201d pharmacy webshops in the EU?<\/h3>\n\n\n\n<p>The 150 online pharmacies in the research sample scanned by <a href=\"\/\">Cookiebot CMP<\/a> are websites with well-visited webshops, where EU residents shop products ranging from medical and pharmaceutical products to alternative medicines.<\/p>\n\n\n\n<p>Selected from <strong>the top results on Google<\/strong> in ten EU member states \u2013 with an <strong>average size of 7,078 subpages<\/strong> and average monthly traffic of 495,000 visits \u2013 these 150 EU webshops are <strong>some of the most popular websites<\/strong> in the online pharmacy industry in the region and constitute <strong>important EU digital infrastructure<\/strong> that not only delivers big quantities of medicines and pharmaceutical products to EU residents, but also <strong>processes large amounts of sensitive personal data<\/strong> from end-users every day.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-kind-of-data-is-being-collected\">What kind of data is being collected?<\/h3>\n\n\n\n<p>Personal data generated and processed when EU residents visit these 150 online pharmacies can include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>user purchases,<\/li>\n\n\n\n<li>search and browsing history,<\/li>\n\n\n\n<li>on-site behavior (such as scrolling speed and how their mouse moves),<\/li>\n\n\n\n<li>sites they visited before,<\/li>\n\n\n\n<li>previous web searches,<\/li>\n\n\n\n<li>IP addresses and other identifiers.<\/li>\n<\/ul>\n\n\n\n<p>This personal data can, in turn, be <strong>sold to data brokers in real time bidding auctions<\/strong> for the purpose of serving personalized, behavioral and targeted advertisement back to the end-user, when they visit other websites across the internet - ads that might be personalized on account of previous browsing and purchase histories, e.g. based on the fact that the user has bought homeopathic anti-depressants or has searched for mental health treatments on Google.<\/p>\n\n\n\n<p>Privacy-sensitive products sold on the 150 EU online pharmacies include: anti-depressants and anti-anxiety medicines, diabetes medicines, products related to women\u2019s health, e.g. menstrual and menopausal products, products related to sexual health and sexual orientation, e.g. pregnancy tests, contraceptives and LGBTQIA+ products, covid-19 antibody and antigen tests, products related to high blood pressure and heart disease, products for smoking cessation and other addiction treatments.<\/p>\n\n\n\n<p>Under the EU\u2019s General Data Protection Regulation (GDPR), data about an individual\u2019s health is <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/rules-business-and-organisations\/legal-grounds-processing-data\/sensitive-data\/what-personal-data-considered-sensitive_en\" target=\"_blank\" rel=\"noreferrer noopener\">considered sensitive personal data<\/a> and requires explicit consent from the user in order to be tracked, collected, processed, shared or sold.<\/p>\n\n\n\n<p>The EU\u2019s GDPR has extraterritorial scope, so websites that have users from inside the EU are obligated to be in GDPR compliance, regardless of where in the world each website itself is located.<\/p>\n\n\n\n<p class=\"has-text-align-right\">&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"\/en\/gdpr-cookies\/\">Learn more about the EU\u2019s GDPR and cookies<\/a><\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Download the pharma e-commerce report by Usercentrics <\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4428\/pharma-report-blog3.jpg?width=500&amp;\" alt=\"Illustration of Medication and Syringes - Cookiebot\" width=\"500\" height=\"334\"\/><figcaption class=\"wp-element-caption\">Consumers want more data privacy, so being GDPR compliant is an increasing focus of online businesses.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-user-consent-is-key-to-successful-data-driven-business\">User consent is key to successful data-driven business<\/h2>\n\n\n\n<p>In contrast with the GDPR compliance failures and data privacy infringements happening on 89% of the most popular pharmacy webshops in the EU, consumer demand for more data protection and enhanced data privacy through transparency and control.<\/p>\n\n\n\n<p>According to <a href=\"https:\/\/www.cisco.com\/c\/dam\/en_us\/about\/doing_business\/trust-center\/docs\/cisco-cybersecurity-series-2021-cps.pdf?CCID=cc000742&amp;DTID=esootr000875&amp;OID=rptsc027438\" target=\"_blank\" rel=\"noopener\" data-anchor=\"?CCID=cc000742&amp;DTID=esootr000875&amp;OID=rptsc027438\">a 2021 study by Cisco<\/a> \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>79%<\/strong> of consumers say that <strong>data privacy is a buying factor<\/strong> for them.<\/li>\n\n\n\n<li><strong>47%<\/strong> of consumers say they have <strong>switched companies<\/strong> over the company\u2019s data policies or data sharing practices.<\/li>\n\n\n\n<li><strong>19%<\/strong> of consumers say they <strong>have terminated a relationship<\/strong> with a retailer, e-commerce websites or online businesses over their data policies or data sharing practices.<\/li>\n<\/ul>\n\n\n\n<p>These numbers paint a clear picture: <strong>data privacy is becoming a consumer demand and a metric of brand reputation<\/strong>, influencing customer choices in ways similar to how \u201csustainability\u201d and \u201cbeing organic\u201d now add value to brand image.<\/p>\n\n\n\n<p>For an e-commerce website, <strong>taking data privacy legislations seriously as an e-commerce website is taking customer demand seriously too<\/strong>.<\/p>\n\n\n\n<p>In other words, building consumer confidence by being compliant with local data laws is and will be <strong>a must for online businesses in the coming years<\/strong>, especially considering the expectation of a steady increase in the number who are willing to act to protect their privacy over time.<\/p>\n\n\n\n<p>Balancing data privacy with data-driven business will be a sign of healthy success for any company in the emerging post third-party cookie internet economy that puts the user and their consent at center.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4429\/pharma-report-blog4.jpg?width=500&amp;\" alt=\"Illustration of magnifying glass over a bottle of medication - Cookiebot\" width=\"500\" height=\"334\"\/><figcaption class=\"wp-element-caption\">Don\u2019t break the trust of your customers, become GDPR compliant today with Cookiebot CMP.<\/figcaption><\/figure>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Download the pharma e-commerce report by Usercentrics <\/a><\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a> \u2013 or forever if you have a small website.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-does-your-website-have-a-cmp\">Does your website have a CMP?<\/h2>\n\n\n\n<p><a href=\"\/\">Cookiebot<\/a> CMP by <a href=\"https:\/\/usercentrics.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Usercentrics<\/a> helps your website balance data privacy and data-driven business by automating the entire compliance process surrounding cookies, trackers and end-user consent on your domain.<\/p>\n\n\n\n<p>The unique scanning technology at the heart of <a href=\"\/\">Cookiebot CMP<\/a> can not only be used to attain compliance with the world\u2019s comprehensive data laws (like the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, <a href=\"\/en\/what-is-ccpa\/\">California\u2019s CCPA<\/a>, <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>, <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a> and many others): it can also be used for investigative purposes, such as <a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">this special scan report<\/a> uncovering GDPR compliance fails in the EU pharma e-commerce market, and <a href=\"\/en\/cookiebot-report\/\">Cookiebot CMP report from 2019<\/a> that revealed unconsented third-party tracking on EU government domains.<\/p>\n\n\n\n<p>If your website does not currently have a consent management platform, <a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">try Cookiebot CMP free for 14 days<\/a>, or forever if your domain has less than 50 subpages.<\/p>\n\n\n\n<p>Visit <a href=\"\/\">cookiebot.com<\/a> or <a href=\"https:\/\/usercentrics.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">usercentrics.com<\/a> to learn more.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-about-cookiebot-cmp\">About Cookiebot CMP<\/h2>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a> is a tool to help websites of any shape and size balance data privacy and data-driven business for true compliance and better customer relations.<\/p>\n\n\n\n<p>Built around an unrivaled scanning technology that detects and controls all cookies and similar tracking technologies on websites, <a href=\"\/\">Cookiebot CMP<\/a> empowers the end-user with transparency and control over their data and enables websites to become compliant with the world\u2019s major data privacy legislations.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4430\/pharma-report-blog5.jpg?width=500&amp;4\" alt=\"Illustration of a laptop with medication to the side of it - Cookiebot\" width=\"500\" height=\"334\"\/><figcaption class=\"wp-element-caption\">Cookiebot CMP is built around an unrivaled scanning technology. <a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Sign up today!<\/a><\/figcaption><\/figure>\n\n\n\n<p>The <a href=\"\/\">Cookiebot CMP<\/a> scanner finds more cookies and trackers than any competitor and is able to detect whether cookies and trackers are being set without user consent (i.e. activated and in use on the website\u2019s landing page despite no consent from end-users).<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a> \u2013 or forever if you have a small website.<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"\/\">Scan your website for free to find all cookies and trackers <\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-does-the-cookiebot-cmp-scanner-work\">How does the Cookiebot CMP scanner work?<\/h3>\n\n\n\n<p>The <a href=\"\/\">Cookiebot CMP<\/a> scanner performs fully rendered user simulations to discover, locate and identify all cookies and trackers that are active on all subpages of any given website.<\/p>\n\n\n\n<p>The <a href=\"\/\">Cookiebot CMP<\/a> scanner does that by simulating multiple users (7-8 on average) visiting a website simultaneously and performs all actions that real users potentially would. The simulated users will scroll through up to 10,000 sub-pages, clicking all links, menu points and buttons. They will move their cursors around, play and pause embedded video or audio content.<\/p>\n\n\n\n<p>During these simulated sessions, the scanner monitors all network traffic between the website and the \u201cbrowsers\u201d of the simulated users \u2013 as well as any traffic sent to other websites. The scanner uses this data to identify all cookies and trackers that are activated as result of the simulated users and their on-site behavior.<\/p>\n\n\n\n<p>The <a href=\"\/\">Cookiebot CMP<\/a> scanner detects all cookies and trackers and catalogues all technical properties, such as name, type, duration\/expiry period, their exact location within the source code of the website, and monitors domain data to determine if third parties are controlling the cookie.<\/p>\n\n\n\n<p>All the information that the <a href=\"\/\">Cookiebot CMP<\/a> scanner finds is automatically logged in a global repository, which consists of millions of trackers that the scanner has encountered across the web.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"\/en\/cookie-consent\/\">Learn more about consent and Cookiebot CMP<\/a><\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"\/\">Scan your website for free to find all cookies and trackers<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-does-cookiebot-cmp-determine-non-compliance\">How does Cookiebot CMP determine \u201cnon-compliance\u201d?<\/h3>\n\n\n\n<p>The <a href=\"\/\">Cookiebot CMP<\/a> scanning technology does not state compliance, but only detects non-compliance.<\/p>\n\n\n\n<p>The way <a href=\"\/\">Cookiebot CMP<\/a> determines non-compliance is to detect whether there are any cookies that are being activated without end-user consent. If any of these cookies can be classified as non-necessary (e.g. by being from a third-party provider or for the purpose of running analytics or marketing services), Cookiebot CMP is able to determine that the website does not meet the compliance requirements of the EU\u2019s GDPR.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4431\/pharma-report-blog.jpg?width=500&amp;\" alt=\"Illustration of medication &amp; magnifying glass - Cookiebot\" width=\"500\" height=\"334\"\/><\/figure>\n\n\n\n<p class=\"has-text-align-left\"><a href=\"https:\/\/usercentrics.com\/resources\/pharma-ecommerce-gdpr-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the key findings and download the full Usercentrics report here. <\/a><\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a> classifies unclassified cookies as necessary and does not state non-compliance for cookies set when imitating users (e.g. in the possible event of implied consent, despite not being best practice and specifically non-compliant according to several EU data protection authorities).<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a> does not find cookies that are set behind log-in, or cookies properly withheld before end-user consent across all subpages on a website and does not find cookies properly withheld across all sub-pages nor cookies in use behind logins or restricted areas.<\/p>\n\n\n\n<p class=\"has-text-align-right\">&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"\/en\/cookie-consent\/\">Learn more about the EU\u2019s GDPR and cookie consent <\/a><\/p>\n\n\n\n<p class=\"has-text-align-right\"><a href=\"https:\/\/manage.cookiebot.com\/en\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a> \u2013 or forever if you have a small website.<\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Lack of transparency on webshops handling sensitive data In a new scan report, Usercentrics scanned 150 popular online pharmacies in 10 EU countries using the scanning technology of its product Cookiebot CMP and found that 89% violated the EU\u2019s General Data Protection Regulation (GDPR) by processing sensitive personal data without the prior and explicit consent [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1444,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1423","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/06\/pharma-report-blog_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=1423"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1423\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/1444"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=1423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=1423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=1423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}