And if the user understand s/he's entering into a contract with Facebook.
It's very unusual to digitally/personally sign a contract when entering a relationship with a site like Facebook giving away a service for no money. It's very usual or inevitable (and expected) to do it when starting an online bank account or for a car sharing service, internet and phone providers, even a subscription to music/movie streaming or online news, something you pay for. There are usually a lot of forms to fill to enter into those contracts and that makes those contracts very visible and understood.
I hope this will be overruled at EU level.
Where the law requires explicit consent it is perfectly valid to include this consent in a contract. An important aspect, though, especially in relation to consumer protection laws is that this must be clear and attention may even need to be specifically brought to it.
Article 13 is a long list of mandatory disclosures that data controllers have to provide to data subjects, informing them of the identity of the data controller, categories of data collected, data retention periods, etc.
This means that a Facebook user cannot both use the service and require Facebook not to process their personal data by refusing to provide consent.
My understanding is that where you rely on consent, you are not allowed to refuse to offer the service based on refusal to provide consent, otherwise consent is not considered to be 'freely given'.
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
It will be interesting to see how this pans out, because the link says 'Consent isn’t freely given [...] when a business/organisation requires individuals to consent to the processing of unnecessary personal data as a pre-condition to fulfil a contract or service.'
Note also that in the text you quote there is an important word, "unnecessary". So the question is whether the data Facebook collects is unnecessary. The specific circumstances are key here. One argument is that what Facebook collects is necessary since it is the very business model here: you get access and in exchange Facebook shows you targeted ads, for which the data are necessary.
I have never been clear about the basis for claiming that consent is not freely given if it is linked to accessing the service. To me that negates the very nature of contracts, which is an exchange. People freely agree or they don't.
Sometimes it seems that 'freely' is interpreted as meaning 'gratis', but that would not be what is typical meant by 'freely given' when discussing agreement or consent, which usually means 'without being coerced or misled'.
However, I do agree 'unnecessary' is an odd choice of word from the EU here, as 'consent' is the only legal basis for data processing which does not include the word 'necessary' in the actual regulation.
> I have never been clear about the basis for claiming that consent is not freely given if it is linked to accessing the service.
The basis for this is Article 7.4.
As an example, if I walk in to a restaurant, it would be 'unnecessary' to require me to provide a name before serving me. They can still require it, and they can refuse to serve me if I don't.
HOWEVER, if I do provide my name they cannot claim that I have consented to doing so (and therefore, they must have another legitimate basis for processing my personal data - a good recent example might be a track and trace scheme, where they have a legitimate basis to process personal data as it is in the vital interests of both myself and other patrons).
However, it would not be unnecessary to require me to provide a name before reserving a table, as the name would be necessary to identify me as the person who reserved the table, and so they can rely on consent as a basis for processing my personal data here.
Moving back to Facebook:
It is necessary for Facebook to process some personal data in order to provide the service of allowing me to communicate with my friends - for example, my name, my friends' network graph, maybe my email address, information that I upload to the site, etc. As a result, this personal data can be processed under the basis of consent.
It is not necessary for Facebook to share that information with advertisers, so they cannot use consent as a basis for processing this data, and they must have another legitimate basis for doing so (and they may well do, I would imagine they could build a pretty solid case either for performance of a contract or legitimate business interests).
This means that either: Facebook agree that they are processing this data based on consent, in which case consent can be withdrawn or refused for specific purposes (which is not possible), or they cannot rely on consent as a basis. It is important which legal basis is used for processing personal data as the paperwork and thresholds for passing PIAs vary.