By the way, if you want to read the article without agreeing to their stuff, stop the page load after the article shows up.
https://guce.oath.com/collectConsent?brandType=nonEu&.done=h...
By the way, if you want to read the article without agreeing to their stuff, stop the page load after the article shows up.
https://guce.oath.com/collectConsent?brandType=nonEu&.done=h...
This is like saying a business can't make usage of a service conditional to payment.
https://edps.europa.eu/sites/edp/files/publication/16-09-23_...
It's funny though, to watch everyone talk about how people should own their data in these threads. And there's the EU proclaiming plainly that you in fact do not own your data and may not do with it as you wish.
Or to put it another way: the problem with inalienable rights is that you can't alienate them :)
There are certainly cases where one can make access to the service conditional on consent: for example, if the service is to analyze your resume/CV and give you feedback on improving it, or even job leads based on it, of course you'll need to consent to them collecting and processing the personal information on your resume. But you probably don't have to consent to them selling that data or using it to target you with ads going forward. They don't want that business model to be easily and broadly viable in Europe.
But assume you have to store some personal information about User X and you do know gender as part of it. Or have code to derive gender at data saving time (This part is tricky by my reading, you have to be able to sort of sandbox the ways that you can get personally identifying info out so that you can show regulatory agencies that you're not pulling it out to do stuff you shouldn't. If you're pulling it out to enrich data before saving, but that data is still not personally identifying the user I think it is probably ok (I'm on shaky ground on this part)
User X as a user of service with login has to allow you to keep their login information or service cannot function. User X says you cannot save my reading history, meaning it cannot be associated with them. But at the time of reading it you save reading activity (this example is of course contrived and silly) - userType: 'requestAnonymous', haslogin: true, age: deriveLikelyAge(User), gender: returnLikelyGender(User), articleId: current.articleId
and so on and so forth. You still have quite a lot of valuable analytics, and you do have some other analytics about the user that has to be saved anyway - which is they have opted out of data collection schemes 1, and 3, but not 2,4,5.
> (Article 4 ) ‘consent’ of the data subject means any freely given, ...
> Recital 42: Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.
> Article 7: 4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Additionally, you need to give a person an option to not hand over that data and still use your app/site 'without detriment' unless that data was essential to your tool.
No, it's not. Requiring extraneous consent as a precondition of service, that is, requiring consent for some processing as a precondition of provision of a service that does not depend on that processing is an indication that consent is coerced rather than freely given, and hence not effective consent, under the GDPR. But what that means on concrete terms with complex interdependent services (and whether it is a de facto ban on such services, because instead extremely granular services and granular consent is required) remains to be clarified, probably through practical enforcement. If one views, for instance, what Facebook was offering pre-GDPR as a service, then “consent for what the service entails or no service” is not extraneous consent. If you view it as a cluster of distinct services, that becomes different. Whether the monetisation model of “free” services is essential or not is another question, and it's quite possible that GDPR will result in a lot fewer free-of-charge services available in the EU.
But if the service does depend on that processing, then you don't need to ask for consent at all, so why would you? In practice, the statement is true.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Consent is only one of the six grounds for lawful data processing. Consent is not always necessary, nor is it always sufficient.
“Granular” appears nowhere in the article you cite nor the related recitals (and even if the exact phrase did, the specific degree of granularity required would still be an open question.)
> Consent is only one of the six grounds for lawful data processing.
I’d argue it's two of the six, as voluntary entry into a contract which requires certain processing is a form of consent, even if the word doesn't “consent” isn't used in that provision.
But in any case, it's the one that's going to be most important to a wide range of consumer online services.
True, though it does appear in the Guidelines for consent: https://ec.europa.eu/newsroom/article29/document.cfm?action=...
Recital 43 states:
"Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance."
Recital 42 states in part:
"Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment."
This is quite plainly worded - if you don't allow users to freely choose which data they give you and what you do with it, then you don't have valid consent. I think that "granular" is a reasonable description. There's certainly a degree of grey area, but the spirit is clear. Putting that into practice requires careful thought. Would a reasonable person understand the implications of your consent agreement? Would they be surprised or annoyed at the scope of your data collection or the use you make of that data? Could you reasonably anticipate a user being unable to properly exercise their rights to choose due to the choices you offer them?
>I’d argue it's two of the six, as voluntary entry into a contract which requires certain processing is a form of consent, even if the word doesn't “consent” isn't used in that provision.
The distinction between consent and contractual necessity is significant. If you're relying on the grounds of contractual necessity, then you can only collect and use the minimum of data for the minimum duration and process it to the minimum extent necessary to fulfil that contract (Art. 5 & recital 39). You can't keep customer data indefinitely or tack on a bunch of clauses to your T&Cs that allow you to sell that data to third parties. If you want to go beyond the absolute necessities, then you'll need to ask for consent. On the other hand, if you're relying on contractual necessity, then the conditions for consent (Art. 7) do not apply.