This page will contain various nuggets of information regarding what to do to comply with the current EU Cookie Law that comes into effect on 26 May 2012.
Currently we have no technical advice, only George's helpful summary of why and what at http://www.dice.inf.ed.ac.uk/org/Cookies.html
Our interpretation is that you need to get consent if you are using Google Analytics - or you're breaking the law. However, the current advice from the University's records management, is that only informing the user that you are using Google Analytics is enough! So we are going with what the University suggests for now.
Even "Strictly necessary" cookies, which you don't need consent for, do need to be disclosed, eg in your "Privacy and Cookies" page.
Generally to make "our" sites comply, we've just made sure there's a "Cookies" link somewhere on every page (usually in the footer) and linked it to a page explaining the use of Google Analytics cookies.
-- NeilBrown - 03 May 2012