First complaints under the GDPR lodged within hours
privacylawblog.fieldfisher.com
privacylawblog.fieldfisher.com
It appears the positive opt in requirement of GDPR is being universally ignored by the industry.
I'm also wondering if the cookies thing is actually just the other law, but now we're all having to look at the old "we use cookies" notifications in a GDPR light.
Yes, that seems to be what they're aiming for now. It was originally supposed to come into effect alongside the GDPR last month, repealing the analogous ePrivacy Directive that was (and for now remains) in force, and therefore allowing member states to update their national laws to remove the annoying cookie notification requirements. Sadly, it wasn't ready in time.
Many high-profile sites rely on advertising, and that makes things more complicated, since they have a clear business interest to get and share as much data as possible, instead of a "process only data strictly needed" approach others can take.
However reading cookies (and sending the content to a server) obviously is privacy sensitive, although even then it should be noted that users have full control over the cookies. This makes cookies better than e.g. a profile that's stored on Facebook's servers.
However, if you started to track people explicitly, even without a cookie, you needed to inform the user.
How that law got interpreted as a 'put a pop up on everything' is beyond me. Most sites managed to annoy the user with a pop up, and still were not on the legal side of the law as they did not inform which third parties exactly got the information.
Why didn't the EU step up and gave guidance to stop the madness? No idea. In general, they tend to bury you alive under folders when given half a chance.
I don't know what the cookie law status is today. It was supposed to be superseded by the GDPR, but i think it is still active, together with the GDPR.
While I of course fully support the protection of consumer data/privacy, the companies also have a right to decide whether they want non-compliant users using their service. They’re not running something like public transport, which must, by rights, be available to all.
Are these complaints in fact valid under GDPR?
If they are operating in the EU? they do actually. You can't just put whatever you want in your ToS/EULA and throw your hands up.
Now, for the complainants complaints to be valid, there have to be things in the ToS that are against GDPR. As far as one can see, there isn’t. BigCos have been careful enough to not step on the toes of EU regulations. But what part of the GDPR gives the EU the right to force a company to offer its service to someone who doesn’t accept the “house-rules”?
Sorry if I seem argumentative, I’m not, I’m just trying to wrap my own head around this thing.
If a shop says "no returns", what they actually mean is "changing your mind or deciding you don't like it isn't a valid reason". But you can still return something if it's faulty, isn't as described, or isn't fit for purpose - because they're your legal rights, phooey to the store's return policies.
It's my understanding (which could be wrong, is constantly evolving, and desperately needs test cases) that being able opt out of unnecessary PII collection or processing is a legal right, and phooey to the ToS that claims otherwise.
In practice, I think that's yet to be determined. GDPR is new. These rights are new. "If it's faulty" is easy for lawyers to determine. "Fit for purpose" ...isn't that hard, and the lawyers have had time to practice. "Unnecessary PII collection or processing" ... the lawyers are currently 23 wikipedia links deep^ trying to identify the aristotelian truth of the matter, presumably in order to make necessary amendments to the aforementioned contract.
Shops putting signs on walls is just not comparable to this, in practice. Normal people are signing dozens of pseudo-contracts they don't understand each day. That has been accelerating and gdpr has accelerated it further.
That’s actually a great point. Collecting PII is NOT illegal, as far as I can see. Nor can it be illegal. Same for personalized ads.
Consider a real estate agent. To show you the right kinds of houses to buy and finally make the contract, they have to have enough PII about you. If they know nothing about you, they’ll end up showing 1-bedroom studios for a family of five and a three bedroom suite for a bachelor living alone. Similar arguments can be made for all kinds of service providers.
Now onto the issue of FB, the only service they offer is “communication tools with built in personalized ads”. PII is necesary to provide that service.
Article 6 [0] is phrased negatively, making collecting PII illegal unless x or y. These points cover all the use cases the lawmakers deemed valid; a real-estate agent may collect PII because of 6.1b (taking steps to enter a contract at the request of the data subject). Should a new, possibly valid reason to collect PII come up it would first need to be checked and then added to the list.
Since most websites and online services do not aim to form a contract nor fit points c-f, they have to obtain consent by the data subject (6.1a) to make collecting PII legal.
Many common purposes for data processing might come under point f (legitimate interests) depending on the circumstances. Analytics, marketing, monitoring to check for fraud or other abuses are just a few examples.
I'm also curious where other points will land in reality. eg, if I ask Apple to remove all data they have about me, will that also remove me from your address book? If I ask Google to remove all data they have about me, will that also remove any emails you've received from me?
In this light, I'm happy to see the first complaints arrive against Google and Facebook, as they're exactly the examples we all have in mind, and we need to see how they'll play out in reality.
(Albeit, I also trust the European legal systems won't commonly wield the maximum possible fines, but rather seek compliance. The scary big numbers, the source of so much FUD, should be reserved for wilful disregard after this step. "Walk softly but carry a big stick" style.
Their case will be helped by the fact that they can simply have the user “consent” to stuff. And since none of those are “critical” services, they will find ways to prove that user consent was actually voluntary, and not coerced.
So I think you’re right that only the most egregious violations will have real trouble.
The judges might also want to demonstrate to everybody (including their own system) that the big stick can in fact be wielded to real effect. If people start beliving that the stick is really just a prop, no point carrying it, is there…
We'll see if this difference is legally superficial or material, as this all plays out.
There was a lot of MOP interest in gdpr and it's friends (like the US Congress' FB stuff). Politicians got attention for their rhetoric, as they legislated. Journalists delivered coverage and opinion, including a lot of moralising too. Social media was abuzz.^ They never told the average MOP that gdpr would be a bunch of contracts she'd be signing.
From the perspective of corporations.. the party complying & implementing gdpr... they've mostly interpreted it as "Rules About The Contract Our Customers Must Sign". Their lawyers assure them this is best.
I think this was a piece of legislation that our legislative systems are particularly ill-equipped to deal with.
^Relatively to the standard interest in laws.
It‘s just that we usually don‘t notice it because it‘s all concludent action, not a signature.
Yes, it‘s strange, but it is the holy cow of German contract law.
I think what the web needs right now is to figure out what the implied contract is, and save the modals for those out of the ordinary.
In the digital/information age, personal data is the new currency. You pay for online services with that currency. If your data (money) is more valuable to you than the value you’d derive from use of a certain service, then you don’t pay for it (and by rights, don’t get to use it). I think my money is too valuable for me to spend it on bottled water, so I drink tap water. I think my personal data is too valuable for what I’d get from using FB, so I dont use it (there’s 20+ very widely used apps to “stay in touch” and “communicate” with people).
Eventually (even a couple decades maybe), it will become a question of getting the most bang for your buck (data). If two companies offer the same sort of service, but no. 1 needs all personal info all the time (like FB today), and no. 2 only wants your location twice a day, no. 2 will be cheaper and win out. When no. 2’s executives get greedy and ask for your location 4 times a day, Reddit will squeal.
There's a reason Facebook has you agree to a 10,000 words ToS and related documents, and it's not because the contract here is blindingly obvious. It would be another thing if the type and extent of their data collection was clearly spelled out and delineated so you knew exactly what you're giving up; but Facebook explicitly wants the ability to collect anything and everything and use it for whatever. Under those conditions, what kind of information they collect about you and what other data it allows them to infer is completely opaque. ("It's just an indoor photo me and a friend, surely Googlebook can't tell where this was taken?" https://nakedsecurity.sophos.com/2016/02/29/google-knows-whe...)
Despite the whole media stink about Cambridge Analytica, usage figures aren’t significantly different. This leads me to believe the average user will simply agree to whatever is put in front of them so be able to use checkout pics and read newsfeeds or play farmville or whatever else it is that people do on FB.
What the EU could mandate is a max 1000 word ToS, that the more concerned user without legal training could actually grok. The GDPR just makes sure companies cover themselves legally - not that hard, if they can get away with a humongous ToS which almost no one will ever read.
I agree. Still, I think that there is a difference between implied contract/obligations and an actual piece of paper with your signature (or checkbox) on it.
As far as I understood, it doesn’t mandate the exact nature of the ToS between the service provider and user, leaving that to be a free-will agreement between two parties.
It doesn't really say that. There are six lawful reasons to process data. User consent is only one of them. The one that's useful for most companies is "legitimate interest".
https://gdpr-info.eu/art-6-gdpr/
See, for example, advice from the UK regulator about potentially using legitimate interest for marketing (something that many people are saying needs explicit consent): https://ico.org.uk/for-organisations/guide-to-the-general-da...
Yes indeed, there is a list of reasons. I pick the one based on consent, because it seems the most relevant for a company. Process the users’ data, but get their permission first.
>The one that's useful for most companies is "legitimate interest”.
I would have thought that one was a bit nebulous. No one has given a hard and fast definition of that term. And rather than risk a court’s interpretation or benefit of the doubt, I figured it might be safer to rely on the consent approach.
But if you can argue with legitimate interest (which is more burdensome), the person cannot decline and still use the service.
Choose: either easy basis and accepting that you might not get your way, or difficult basis and getting your way.
That‘s not how it works.
Now If I made a “communication tool” exclusively for registered gun dealers and people with valid (and verified) hunting licenses, it would in fact be perfectly legal. Similarly, if the tool were for use by government agencies and defense contractors or registered weapons manufacturers, it would also be legit.
In the context of “chat tool with personalized ads on the side” - there is nothing specifically illegal about “personalized ads”. Is there? (As long as there is user consent of course). So what’s the specific legal hurdle? Which paragraph of the GDPR prevents this?
Consent is required to be "freely given", which isn't the case if it is required. E.g. Article 7:
> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Or in Recital 43:
> Consent is presumed not to be freely given [...] if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.
Thus, where they do give "consent" as the basis on which they process data as part of Terms of Service the user has to accept, that's highly critical if they do not query for that consent independently, and in a way the user clearly can deny. You can't require consent in something the user has to accept to use your service.
(You can find the full complaint against Facebook here: https://noyb.eu/wp-content/uploads/2018/05/complaint-faceboo...)
Yes, indeed. That just leaves the matter to specifying the exact nature of the contract. So the service being provisioned can be “access to the tools to connect with one’s friends and such tools have personalized ads built into them”. Does my approach misinterpret things? I don’t think anything is specified about what kinds of contracts can or cannot be offered. And in a reasonably free market, it cannot. And of course, it should not - hardly any of the biggest internet companies could make money without ads.
Now if FB or Google, or another company were to be regulated as a utility company, then yes, the nature of their contracts can also be regulated.
They could go a step further, and simply ban “all personalized ads” - I’m not sure how feasible that is, but that would give the EU the right to regulate the kinds of ads shown by FB and ergo, the kind of data collected. But personalized ads is a immensely vague term that could even catch tv and radio ads (targeting based on demographics, and time of day the show is being broadcast, etc.) in the dragnet.
To be a bit glib, if Ads are a core part of the offering, surely the facebook.com front page should mention them?
Of course, like another commenter mentioned about face recognition and image processing, that is hardly relevant to most kinds of advertizing.
The question is one of legal basis and also of specifying explicitly what is being done with the data.
That leads to the next question - how will things be verified? Will an entity get to audit FB algorithms in toto to sign off that they’re secretly processing facial recognition data?…that’ll be the real challenge.
This point in GDPR could be clearer, and I hope the national regulators provide better advice.
Also, lots of complainants don't understand GDPR and so we will see a bunch of complaints based on incorrect understanding of GDPR.
https://gdpr-info.eu/art-7-gdpr/
> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Indeed, probably lots of entitled people who believe Facebook (though I’m no fan, and haven’t used it in years) ought to behave as a charity or govt-funded entity.
>https://gdpr-info.eu/art-7-gdpr/
Thanks for that (I’ll be reading through the link more fully).
>When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
So, the company needs to phrase/frame/present the “service” carefully enough - to take the example of FB again, the service they offer could be phrased as "a means to communicate with and see updates from your connections, together with ads that have been targeted based on your profile details”. Naturally a contract to execute such a service cannot be fulfilled without them processing personal data, and this is the only service they offer. Does this understanding seem correct?
Because online privacy is now an inalienable right. Users can't sign it away permanently, and companies can't ask for it in return for something.
> No business is obliged to allow all and sundry to use their product/service
No, but they can't discriminate with regards to submission to online tracking.
> the companies also have a right to decide whether they want non-compliant users using their service.
In the EU there are no "non-compliant" users when it comes to agreeing to tracking; there are only non-compliant publishers. These publishers are free to shut down EU operations and block EU ip-addresses, and I wish they would instead of these now common "opt out of any of our 50+ 'partners' individually through this terrible interface" shenanigans, designed to make it cumbersome to exercise one's right not to be tracked online.
> Are these complaints in fact valid under GDPR?
I believe so, and if not, they should be.
If you go to https://www.independent.co.uk/ for example on mobile, most of the screen is filled with a consent message. But it isn't "yes / no" like the GDPR would like, it's "yes / visit a difficult-to-navigate consent manager to not give your consent".
Surely not allowed.
It is perfectly reasonably to have two versions of a service - one with ads/cookies and one without. The user uses the one they want.
If one considers personal information as a currency, it is something one can choose to or not to pay. If the user's privacy is important enough to them, they won’t give the company the right to track them or do whatever else with their data. The user decides whether access to that service is worth paying the price in terms of privacy. I think Facebook is too expensive (in terms of my personal data they get) so I don’t use the service. But I cannot complain that FB doesn’t service me for nothing. It is a for-profit company. The company is not obligated to service everyone - it is not public transport or the electricity company.
You may argue against the GDPR, but it doesn't change the law as it stands today.
There is nothing illegal about having the above two lines of services. But when a user wants service no. 1, their personal data becomes neccessary to show personalized ads. If the user chooses to not “pay” in the curreny of personal data, it is perfectly fine, they can use service no. 2.
Why is this illegal? Please, be specific with which part of the law prohibits this.
Morally, ethically, I agree with you. 100%. I was in fact involved in a spread-the-word about GDPR campaign few months back. This discussion is about the legality and the technicality.
> Processing shall be lawful only if and to the extent that at least one of the following applies: > > 1. the data subject has given consent to the processing of his or her personal data for one or more specific purposes; > > 2. processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; > > (there are a few more cases)
Given that there is no contract for which the personal information is necessary when you view a news site, they have to ask for consent. Which is why they ask for consent. However:
> Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data [...]. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject’s acceptance [...]. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. [...] the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
I would say that this especially violates the last sentence. It is definitely unnecessarily disruptive.
Unfortunately this is in a "Recital", not in the main text. I have no idea what that means but I expect we will have to wait for a court case to find out the real answer.
The only real solution is to stop letting these companies invade your privacy, by ceasing to use their services.
That doesn't mean "THIS.. IS.. STALLMAN!", but it will be less convenient than letting them continue.
How do you explain the GDPR then?
I'm not sure what you mean.
Is it not obvious that politicians don't want to bust their biggest (potential) campaign contributors for GDPR violations?
Isn't it obvious that we don't have any more privacy now than before GDPR, because governments are still spying the shit out of us all?
In light of that, is it not obvious that GDPR's real goal is something other than improving our privacy?
Do you genuinely think governments (or EU bureaucrats) actually care about us or our privacy? If not, why would you think GDPR was devised for our benefit?
And gosh, it sure makes it more difficult for small businesses to stay viable, and wouldn't it be nice for big corporations to have fewer potential competitors/disruptors around?
Yes
> And gosh, it sure makes it more difficult for small businesses to stay viable, and wouldn't it be nice for big corporations to have fewer potential competitors/disruptors around?
This is just ridiculous. Politics is still driven by the will to improve societies instead of just a cold grab of money and power. Your level of cynicism is just over the charts.
Maybe you should be a little more cynical.
Or maybe you should consider that good government and regulation, of which there is still much, is actually the most effective protection against uncontrolled corporate interest.
Why do you think tax money goes to ship amazon packages?
https://en.wikipedia.org/wiki/Chamber_of_Representatives_(Be...
There is a 'kiesdrempel' declaring you need 5% of a district's votes before you can function as a party. There are I think 11 districts, so the theoretical maximum is (100/5)*11=220 political parties.
New parties create a document, the 'voordrachtsacte' which needs a minimal number of signatures. When you get enough people to sign it (again apercentage of the inhabitants of the region that's holding an election), you have managed to start a new party.
In practice there are about 3-5 big ones for each half of the country, plus a lot of small parties which are mostly ignored as background noise and are mostly dead at the next election.
Some background noise parties I remember because of their humoristic values were WOW (Gething older with grace), and BANAAN (banana, who had a slogan like: dont be a pear, vote banana)
in EE, a lot of countries are still dealinig with the intertia of the post-communist goverment and its institutions.
And yes I can confirm, in Northern Europe there is a fundamental trust on the government. I, for one, believe that none of our politicians are outright bought; some of them may drive pro-business policies, but from my vantage point the level of cynicism exhibited in this discussion falls squarely to a bucket of loony conspiracy theories.
In the approach towards regulation, I think the major difference compared to the US is that Europeans mistrust businesses just as much as politicians. GDPR is a result of mistrust in businesses. Stating that politicians are corrupt, as Americans are wont to do, is not really an argument against regulation like GDPR unless you believe businesses never act against the interests of the public.
In the UK, campaign contributions are almost completely irrelevant. Political parties can spend no more than £46,000 per candidate at each election. Our major parties literally have more money than they can spend. Most European countries have similarly strict campaign finance legislation.
>Isn't it obvious that we don't have any more privacy now than before GDPR, because governments are still spying the shit out of us all?
Corporate data mining and political surveillance are somewhat distinct issues. Here in the UK, government agencies have relatively broad powers to collect and use data on citizens. In Germany, privacy rules are extraordinarily strict. As long as member states are abiding by the ECHR, it's a matter for their national parliaments.
>In light of that, is it not obvious that GDPR's real goal is something other than improving our privacy?
No.
>Do you genuinely think governments (or EU bureaucrats) actually care about us or our privacy?
Some politicians are obviously pro-surveillance. Some are strongly pro-privacy. That's sort of how democracy works - a democracy where all politicians agree on everything isn't much of a democracy at all. There are major differences of opinion between member states and within member states, differences of opinion between parties and within parties. There are three parties in Germany's current coalition government, all of whom have significantly different policies with respect to privacy.
>And gosh, it sure makes it more difficult for small businesses to stay viable, and wouldn't it be nice for big corporations to have fewer potential competitors/disruptors around?
GDPR has little or no impact on a large proportion of small businesses, because their businesses don't depend on the processing of personal data. If your data processing operations are small-scale, straightforward and legitimate, it isn't hard to comply with GDPR. Some small businesses have been significantly impacted, mainly because they have been flagrantly disregarding the Data Protection Directive for many years. Most of the GDPR isn't new, it's just the old data protection laws with credible powers of enforcement.
The changes made by the GDPR are mostly updates to reflect the changing nature of personal data processing. The Data Protection Directive came into force in 1995. At that time, nobody really anticipated the sheer scale and pervasiveness of personal data harvesting that the internet would facilitate.
In Europe, members of the judicial branch are not up for direct popular election and therefore does not campaign. I guess this is less democratic, but it means the judicial branch (which decides who to "bust") is not beholden to campaign contributors which is a good thing.