our-privacy

One You - Public Health England (28/07/2018)

The NHS website includes content from Public Health England.

Public Health England appear to often run health awareness campaigns, as opposed to getting directly involved in treating concerns.

Because they share a domain with the NHS, they may both leak cookies to each other and risk origin security risks.

Maybe not great, but, what about other third parties? The advertising companies, social media and analytics…

Their most recent email to me stated:

We would like to reiterate that the data our website operator obtains does not track users in a manner that identifies them personally. PHE complies with the laws governing the use of cookies, as set out by the Data Protection Act and the General Data Protection Regulation (GDPR). As stated in our previous correspondence; if users wish to restrict or block tracking information on our website, this option is available through the individual’s browser settings.

Should you remain dissatisfied with our data use policy, we would suggest you to pursue any outstanding issues through the regulatory body for information rights, The Information Commissioner’s Office (ICO).

But this isn’t true

Video of what their site does

Privacy Policy

https://www.nhs.uk/oneyou/privacy-policy/

PDF

Cookie Banner

Their Cookie Banner image/text misleads users and then their cookie policy demands users consent to a whole range of third parties and mentions tracking ids in various places.

Cookie Declaration

https://www.nhs.uk/oneyou/cookie-declaration

PDF

Website usage (12)

These types of cookies measure how you use the website, like where you click, so it can be updated and improved based on your needs.

Name Provider Purpose Expiry Type
.ASPXANONYMOUS nhs.uk Used to deliver anonymous user details when authorising applications on the website. 69 days HTTP Cookie
__cfduid d3js.org Used by the content network, Cloudflare, to identify trusted web traffic. 1 year HTTP Cookie
ARRAffinity nhs.uk Used to distribute traffic to the website on several servers in order to optimise response times. Session HTTP Cookie
ASP.NET_SessionId nhs.uk Preserves the visitor’s session state across page requests. Session HTTP Cookie
CookieConsent nhs.uk Stores the user’s cookie consent state for the current domain 1 year HTTP Cookie
homepage.modules nhs.uk Pending 1 year HTTP Cookie
huSessID healthunlocked.com Pending 10 years HTTP Cookie
seen_banner nhs.uk Pending 3 months HTTP Cookie
SRCHD bing.com Pending 1 year HTTP Cookie
SRCHUID bing.com Pending 1 year HTTP Cookie
SRCHUSR bing.com Pending 1 year HTTP Cookie
WFE nhs.uk Cookie to ensure persistent connection to a webserver Session HTTP Cookie

Site preferences (8)

These types of cookies measure how you use the website, like where you click. We use this information to improve our services.

Name Provider Purpose Expiry Type
_EDGE_S bing.com Pending Session HTTP Cookie
_EDGE_V bing.com Pending 1 year HTTP Cookie
_SS bing.com Pending Session HTTP Cookie
MUID bing.com Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains. 1 year HTTP Cookie
MUIDB bing.com Pending 1 year HTTP Cookie
nhs_heartage nhs.uk Pending Session HTTP Cookie
OGPC google.com Used by Google to save user settings when the user views pages with embedded content from Google Maps. 29 days HTTP Cookie
performance nhs.uk Pending Session HTTP Cookie

Website usage (20)

These types of cookies measure how you use the website, like where you click, so it can be updated and improved based on your needs.

Name Provider Purpose Expiry Type
@@History/@@scroll# [x2] nhs.uk
optimizely.com
Pending Persistent HTML Local Storage
_ga [x4] gov.uk
nhs.uk
play.google.com
service.nhs.uk
Registers a unique ID that is used to generate statistical data on how the visitor uses the website. 2 years HTTP Cookie
_gat [x2] nhs.uk
play.google.com
Used by Google Analytics to throttle request rate Session HTTP Cookie
_gid [x4] gov.uk
nhs.uk
play.google.com
service.nhs.uk
Registers a unique ID that is used to generate statistical data on how the visitor uses the website. Session HTTP Cookie
ACOOKIE statse.webtrendslive.com Collects anonymous data on the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded with the purpose of generating reports for optimising the website content. 29 months HTTP Cookie
collect google-analytics.com Used to send data to Google Analytics about the visitor’s device and behaviour. Tracks the visitor across devices and marketing channels. Session Pixel Tracker
dcs222rfg0jh2hpdaqwc2gmki_9r4q/dcs.gif statse.webtrendslive.com Pending Session Pixel Tracker
dcss9yzisf9xjyg74mgbihg8p_8d2u/dcs.gif statse.webtrendslive.com Pending Session Pixel Tracker
optimizelyDomainTestCookie nhs.uk Pending 179 days HTTP Cookie
optimizelyEndUserId nhs.uk Used to measure how selected users react to targeted changes to the website’s content and functionality, in order to determine what variation is most efficacious in terms of converting users to customers. 179 days HTTP Cookie
tracking/tracker.gif preview.antbits.com Pending Session Pixel Tracker
WT_# nhs.uk Used for gathering anonymous technical information regarding the user’s browser, operating system, IP address and screen resolution as well as the user’s navigation on the website. 2 years HTTP Cookie

Health campaigns (26)

We run health awareness campaigns with trusted partners. These cookies see how they perform across the internet and social media. Such as whether you clicked an advert to come to our site.

Name Provider Purpose Expiry Type
_dc_gtm_UA-# service.nhs.uk Used by Google Tag Manager to control the loading of a Google Analytics script tag. Session HTTP Cookie
_isp-form_session nhs.uk Pending Session HTTP Cookie
1P_JAR google.com Pending 29 days HTTP Cookie
ads/ga-audiences google.com Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor’s online behaviour across websites. Session Pixel Tracker
CAM nhs.uk Pending Session HTTP Cookie
CRAFT_CSRF_TOKEN findarace.com Pending Session HTTP Cookie
CraftSessionId findarace.com Pending Session HTTP Cookie
IDE doubleclick.net Used by Google DoubleClick to register and report the website user’s actions after viewing or clicking one of the advertiser’s ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user. 2 years HTTP Cookie
NID google.com Registers a unique ID that identifies a returning user’s device. The ID is used for targeted ads. 6 months HTTP Cookie
optimizely_dataevent_queue nhs.uk Pending Persistent HTML Local Storage
optimizely_dataevents nhs.uk Pending Persistent HTML Local Storage
optimizely_datalayer_map nhs.uk Pending Persistent HTML Local Storage
optimizely_datalayer_states nhs.uk Pending Persistent HTML Local Storage
optimizely_datasession_state nhs.uk Pending Persistent HTML Local Storage
optimizely_datatracker_optimizely nhs.uk Pending Persistent HTML Local Storage
optimizely_datavariation_map nhs.uk Pending Persistent HTML Local Storage
optimizely_datavisitor_profile nhs.uk Pending Persistent HTML Local Storage
r/collect doubleclick.net Pending Session Pixel Tracker
r1/pixel/x45742r677448176 gwallet.com Pending Session Pixel Tracker
ra1_sgm gwallet.com Pending 1 year HTTP Cookie
ra1sgm# gwallet.com Pending 1 year HTTP Cookie
ra1_sid gwallet.com Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user’s movement on websites that use the same ad network. 1 year HTTP Cookie
ra1_uid gwallet.com Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user’s movement on websites that use the same ad network. 1 year HTTP Cookie
RA1balancer gwallet.com Registers anonymised user data, such as IP address, geographical location, visited websites, and what ads the user has clicked, with the purpose of optimising ad display based on the user’s movement on websites that use the same ad network. 1 year HTTP Cookie
test_cookie doubleclick.net Used to check if the user’s browser supports cookies. Session HTTP Cookie
v2/tracker brightcove.com Pending Session Pixel Tracker

Unclassified (5)

Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.

Name Provider Purpose Expiry Type
DYNSRV webfusion.co.uk Pending Session HTTP Cookie
JS-Detection gov.uk Pending 34 days HTTP Cookie
OTZ play.google.com Pending 29 days HTTP Cookie
seen_cookie_message gov.uk Pending 27 days HTTP Cookie \
TLSversion gov.uk Pending Session HTTP Cookie