Yes, insane seem like it's not actually an overstatement for once.
Yes, insane seem like it's not actually an overstatement for once.
>they have a contract with you – for example, a contract to supply goods or services (i.e. when you buy something online), or an employee contract
You just have the right to request that your data is deleted but as long as you don't do that, why should your data not be processed?
Additionally, it is allowed to process private data without a contract if it is necessary. Then, an excessive use of private data is illegal.
But most services will have a contract and thus it is legal.
Minor detail: services cannot be restricted if you don't agree to share your private data. But that doesn't touch sharing the data that was signed away with a contract.
[1] https://europa.eu/youreurope/citizens/consumers/internet-tel...
With Grindr, they only need to process data to provide the service by making it available to you and to other users. What they definitely don't need to do in order to provide the core service is to share your data with third parties who can then use it for their own purposes.
Any argument that the processing is necessary because it's an ad-funded service would not be acceptable under data protection law.
On that basis, performance of a contract would not be a relevant ground. You're also looking at e-Privacy Directive considerations in the EU where either a cookie or similar is essential to provide the service, or you need consent. Similar for location data, you will generally need consent.
So you not only have GDPR issues but also e-Privacy Directive issues where your processing grounds are actually incredibly limited anyway.
That was my point. People sign contracts where they consent to sharing. The advertising industry is not breaking the law because they don't use the data that is necessary for the performance but they use the data that is voluntarily shared.
That's not minor, it's major. It invalidates any sort of "let us use your data in order to use the app" profiteering clickwrap nonsense, and any kind of "contract" derived from that would be void.
It is the same with ad-blockers. Youtube would be bankrupt if people weren't lazy.
>It states that you should integrate data protection from the designing stage of processing activities. Article 25 of GDPR lists the requirements for data protection by design and default.
But that's the processing, not the agreement.
And about consent [2]:
>Freely given - the person must not be pressured into giving consent or suffer any detriment if they refuse.
>Specific - the person must be asked to consent to individual types of data processing.
>Informed - the person must be told what they're consenting to.
>Unambiguous - language must be clear and simple.
>Clear affirmative action - the person must expressly consent by doing or saying something.
But freely given doesn't forbid using the default or does it?
[1]https://www.cookielawinfo.com/gdpr-privacy-by-design-and-def... [2]https://www.privacypolicies.com/blog/gdpr-consent-examples/
>>Clear affirmative action - the person must expressly consent by doing or saying something
It's not "clearly affirmative" if it's a default that's difficult to find the alternative to, or easy to select by mistake.
Pretending this isnt a delicate issue creates more loopholes and bench time than helping consumers.
You can also cover it under "easy to select by mistake [the unintended answer]".
I think the root of the problem in most cases is that companies don't want to help consumers, they actively want to mislead them and then claim plausible deniability.
I don't understand which sense you mean by "pretending this isn't a delicate issue..." here. I can't even tell if you are pro-GDPR or anti-GDPR from that, and which of those positions you consider to be helping consumers more. Ironic, Y/N? :-)
They, like I, are not arguing for a side (I assume). We are pointing out that the legal situation is not as clear as the article suggests.
Judging by the lack of won cases, a default ok button seems to be 'clearly affirmative' enough.
The law states [1]:
>It shall be as easy to withdraw as to give consent.
Nothing states that consent has to be more difficult than non-consenting.
>the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
The request has to be distinguishable, not the consent.
Nobody is arguing that consent should be more difficult.
The complaint is that non-consent is often much more difficult than consent, sometimes ridiculously so.
In my personal experience I have been unable to find the no-consent option at all on some sites. Just links that go around in circles, sometimes to hundreds of ambiguous and mixed-polarity yes/no-or-was-it-no/yes-style options (one for each of hundreds of "partner sites" I've never heard of), with the only clear option being consent-to-all.
If I eventually click on "ok" that is not freely given consent, it's coerced due to me being unable to find or understand how to decline it.
It is technically easy to provide a "decline-to-all" option whenever they have provided a "consent-to-all" option.
Therefore, clearly companies which provide an easy consent-to-all but make decline-to-all virtually impossible to select, or actually impossible, are doing so deliberately, intending to frustrate the consumer from exercising their rights.
The law says that a person should be able to decline if they choose, that it should be easy enough to do, and easy to understand which option they are choosing. Such sites are not compliant with that principle, and it looks like deliberate non-compliance to me.
> The request has to be distinguishable, not the consent.
Well, "the request" is what we've been talking about. It means the UI. Things like "Ok" and "decline" buttons, how the options are presented, how they are explained clearly and unambiguously, the ease and accessibility of selecting the freely chosen option, that sort of thing.
Yes, that's their business concept and it is legal.
>The law says that a person should be able to decline if they choose, that it should be easy enough to do, and easy to understand which option they are choosing.
The law states:
>>It shall be as easy to withdraw as to give consent.
>Such sites are not compliant with that principle, and it looks like deliberate non-compliance to me.
I rather think that they follow the law to the T. People would love if their behavior would be illegal but they forgot that companies are involved in the law making process, too. The EU wants its companies to be competitive on the internet. Making it impossible for companies to finance themselves with advertising in their home market would kill their already weak internet economy. Who would accept the sharing of private data if a rejecting would be as easy as accepting?
GDPR is a compromise between the protection of the netizens and the business interest of the economy. As such, it protects against the worst abuse but the world is not free. In one way or the other, somebody has to pay.
>>Such sites are not compliant with that principle, and it looks like deliberate non-compliance to me.
> I rather think that they follow the law to the T.
I think "as easy" is plainly incompatible with "much harder" or "impossible".
You cannot make something plainly much harder than something else, and still pass the "as easy" test in the law to a T.
You also cannot pass the "accessible" test that way.
>> intending to frustrate the consumer from exercising their rights.
> Yes, that's their business concept and it is legal.
I don't believe it is legal, because these are statutory rights.
To use an analogy that involves another statutory right, it would be like a company preventing you from exercising your right to return a broken product "because it's their business model to ship defective products and we cannot kill the economy by preventing that business". Companies do get away with that, because people can't find the energy to pursue it, especially for small violations, but when sued those companies do lose.
You cannot determine that it's legal just from the fact that companies get away with it.
The companies can make the rejection difficult as long as the withdrawal is as easy as the giving.
Clicking the "ok I consent" button does not count as consent under the law if the user believes they have to click it to use the service, assuming what is attached to that button isn't technically necessary for delivery of the service.
And holding PII for marketing and tracking purposes does not count as necessary, despite any economic argument that it pays for the service. That argument is disallowed.
On which part of the law do you base your first paragraph? The text that fits for me is all about the consent, not the rejection. It must be easy to understand to which a person consents, but the rejection can be difficult.
There is also:
>When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Services have to point out that consent is not necessary. If that's usual not done, then this abuse can be ended by notifying the EU. I thus assume that most services offer that notice. Then it is very difficult to argue in court that a user still believed that they didn't mean to give consent. People have to argue for their legal incapability if they want to get out. Who would do that?
The compromise of the law is that people in general mindlessly click ok so that targeted advertising is possible. People who mind tracking can easily opt out. This leaves the ignorant to be tracked. How else should free services be financed? The only other option is making people pay for everything which is ok but a radical shift for the internet.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
See ICO's guidance on consent: https://ico.org.uk/for-organisations/guide-to-data-protectio...
The GDPR is clearer that an indication of consent must be unambiguous and involve a clear affirmative action (an opt-in). It specifically bans pre-ticked opt-in boxes. It also requires distinct (‘granular’) consent options for distinct processing operations. Consent should be separate from other terms and conditions and should not generally be a precondition of signing up to a service.
The GDPR gives a specific right to withdraw consent. You need to tell people about their right to withdraw, and offer them easy ways to withdraw consent at any time.
If you make consent a precondition of a service, it is unlikely to be the most appropriate lawful basis.
So yes it's law, unless and until someone manages to appeal some interpretation of a point all the way up the chain.
Since most people press ok, it doesn't matter to also offer the service to those who cancel. Actually those people still leave a signal and you can show special ads to anybody who isn't part of the ok-clicker database.
I don't see how this would violate the GDPR:
- unambigous and clear affirmative action. People press ok and not the closing cross.
- no pre-ticket opt-in box
- distinct consent to advertisement processing
- separation from other terms
- not a precondition of signing up
- remaining right to withdraw consent
- ability to also tell people about their right to withdraw in that box
- possible to offer an easy way to withdraw
Actually withdrawal has to be as easy as consent. The law states:
>It shall be as easy to withdraw as to give consent.
That's the point where everybody is violating the law because the opt-out button is not constantly shown like the ok-button for opt-in.
This isn't true. The actual GDPR text on consent states [1]:
the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
-> So processing of data based on consent is limited to the purposes agreed to.
or
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject
-> So processing of data is necessary to fulfill a request made by the data subject.
This is a far cry from "processing the data which you have signed away". The only blanket allowance for data processing is this item:
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data
Which again limits the processing allowed under GDPR: processing of data under this rule requires the legitimate business interest to be weighed against the subject's personal rights.
Why does this exclude a broad clause, e.g. one that states that the data is used to show the most fitting advertisements. You can see that purpose on many webpages. Almost any current data processing will fall within that area.
In conclusion, I still think that you can sign away the right to process your data.
> The extent of tracking makes it impossible for us to make informed choices about how our personal data is collected, shared and used, says Finn Myrstad, director of digital policy in the Norwegian Consumer Council.
The Council's point is that the average consumer is not capable of meaningful consent due to the extent and obfuscation of the tracking involved. Much of contract law, afaik, requires a person to be capable of consent at the time of signing for a contract to be valid. The Council's argument, therefore, is that even if technically a consumer has "signed away" the right to process their data, the contract is not valid because the consumer is not able to, and/or cannot get the information required to, make an informed choice when signing.