This site here e.g. does it: https://www.spiegel.de/
imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.
This site here e.g. does it: https://www.spiegel.de/
imprint is still reachable, but if you want to read this news site you'll have to allow all the tracking crap.
They call it Nudging.
I might translate this to a proper blog post in English.
Both via legitimate interest and consent.
So you can supply an ad supported version and a paid version without ads, but you cannot require that those that choose the ad supported version must accept tracking ads.
You can’t segregate the same service, two distinct services one that is provided with ads that include 3rd party cookies and a separate paid service that does not is perfectly fine.
What you cannot do is to create multiple tiers in a free service based on different levels of tracking.
What you are describing sounds like a business can simply declare “well untargeted ads doesn’t pay enough so the options are tracking ads or paid subscriptions”. The regulation shouldn’t and doesn’t let a site make that decision. It would make it completely useless!
You can’t force someone to provide their business at a loss.
As long as you don’t penalize or segregate users based on their decision alone it does not run afoul of GDPR, neither does blocking someone completely you just need to have a valid business reason for doing that and it has to be tied to the nature of the service including how it’s funded.
Of course not. But no one is forced to provide the ad funded service at all.
It’s not upto the DPAs to regulate things at this level just like you could run an astrology service and collect PII to give people readings, astrology is horseshit but you won’t run into issues with GDPR if you request users to give you their birthday and email to get spammed with BS on a daily basis.
Processing or possibly even keeping a birthdate for an astrology newsletter is clearly a legitiamate interest for the subscriber of that newsletter.
> but it’s a valid business model.
What is? Showing ads to provide a service is a valid business model yes. Showing tracking ads or blocking those who don't accept the ads - no.
But "I need to show the ads to keep the lights on" is NOT a legitimate interest to the visitor. The reason for handling the personal infrmation needs to be a hard requirement to provide service itself. Not merely part of the "business model". You cannot set up a separate service (paid subscription) and argue that because that other service exists, your ad-funded service deserves special exceptions from the GDPR e.g. that it can show ads which are tracked or else users are blocked. It's pretty clear in the regulation that "cookie walls" aren't allowed, just like pre-checked/assumed consent isn't.
You can provide users with a binary choice, as long as it’s all or nothing and the free service and paid service are separate it’s acceptable.
I too thought GDPR is much stricter but in reality it’s not. Both the ICO and several continental DPAs including the German one allow for binary choice.