German court rules cookie preference service that shared IP addresses with US firm should be halted
- Reference: 1638984005
- News link: https://www.theregister.co.uk/2021/12/08/germany_cookie_service/
- Source link:
The university Hochschule RheinMain in Germany was this week prevented by Wiesbaden Administrative Court from using a cookie preference service that shares the complete IP address of the end user to the servers of a company whose headquarters are in the US.
A complainant had alleged that the CookieBot consent manager from Danish provider Cybot transmitted data such that IP addresses were shared with US-based cloud company Akamai Technologies.
What is Schrems I?
In the first case, arising from a complaint filed with the [1]Irish Data Protection Commissioner in 2011 , privacy activist Max Schrems ultimately toppled the biggest EU-US data-sharing deal, Safe Harbor. Schrems had alleged that Facebook violated the so-called Safe Harbor agreement which protects EU citizens' privacy, by transferring its users' data to the US National Security Agency (NSA).
In the [2]Schrems I ruling , in 2015, Europe’s highest court ruled that data sharing between the EU and US under the Safe Harbor framework was invalid.
What is Schrems II?
Schrems, a former law student, brought the latest edition of the long-running case (informally known as Schrems II) in 2015, [3]complaining that Ireland's data protection agency still wasn't preventing Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from beaming his data to the US under Privacy Shield.
In July last year, the [4]EU Court of Justice struck down the so-called Privacy Shield data protection arrangements between the political bloc and the US, triggering a fresh wave of legal confusion over the transfer of EU subjects' data to America.
The [5]court awarded a temporary injunction to prevent further data sharing. The ruling could be subject to a legal challenge but if upheld it could have ramifications for European companies using similar services.
The court said the data shared was personal data as the end user can be clearly identified from a combination of a key that identifies the website visitor, which is stored in the user's browser, and the transmitted full IP address.
[6]
The cookie service processes the complete IP address of the end user on the servers of a company whose corporate headquarters are in the US. This creates a reference to a third country, namely the US, which is inadmissible with regard to the so-called Schrems II decision of the European Court of Justice.
[7]
[8]
In June, the European Data Protection Board (EDPB) [9]finalised its guidance to businesses in how they should proceed following the Schrems II ruling, which struck down the Privacy Shield data-sharing arrangement between the EU and the US.
[10]UK watchdog's punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private
[11]Max Schrems hits Irish Data Protection Commissioner with corruption complaint
[12]Data transfers between the EU and the US: Still unclear on what you're supposed to do? Here's an explainer
[13]EU and US seek 'common principles' for data governance and AI
In its final version of the recommendations on supplementary measures to accommodate the ruling, EDPB said the transfer of data could be impinged on if legislation in a third country allows authorities to access data transferred from the EU, even without the importer's intervention.
In the Schrems II ruling, named after Austrian privacy activist and lawyer Max Schrems, the EU Court of Justice said that Section 702 of the US Foreign Intelligence Surveillance Act together with a US presidential order and a policy directive on data collection by spies failed to meet EU data protection requirements.
The ruling could be another reason that standard contractual clauses cannot be relied on for compliance with the law in cases where data is shared between the EU and the US. See [14]this analysis from lawyers Rafi Azim-Khan and Steve Farmer for more detail. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2011/10/19/europe_v_facebook_irish_investigation/
[2] https://www.theregister.com/2015/10/06/safe_harbour_walls_come_tumbling_down/
[3] https://curia.europa.eu/juris/document/document.jsf?text=&docid=228677&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=12312155
[4] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[5] https://verwaltungsgerichtsbarkeit.hessen.de/pressemitteilungen/cookie-dienst
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbE5JjbTZwZqJoZB843TygAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbE5JjbTZwZqJoZB843TygAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbE5JjbTZwZqJoZB843TygAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2021/06/21/final_guidance_on_schrems_ii/
[10] https://www.theregister.com/2021/12/01/ico_reprimands_large_organisations/
[11] https://www.theregister.com/2021/11/24/max_schrems_files_corruption_complaint/
[12] https://www.theregister.com/2021/11/01/data_transfers_europe/
[13] https://www.theregister.com/2021/09/30/eu_and_usa_ai_data_share/
[14] https://www.theregister.com/2021/11/01/data_transfers_europe/
[15] https://whitepapers.theregister.com/
Re: And the rest too, please
I am curious as to how long it takes after landing on a page for the site to set cookies and/or start to harvest data, particularly those sites that deliberately seem to have convoluted opt out pages, when under the current law as I understand it, they need to receive your consent.
I also find the 'legitimate interests' that seem to always be set to on are for the most part not legal without specific consent even though it appears so because there is no explanation of what they are.
Here from the ICO:
"the term ‘legitimate purpose’ refers to facilitating the provision of an information society service – ie, a service the user explicitly requests. This does not include third parties such as analytics services or online advertising."
On most sites legitimate purpose or interest is used as a catch all to con the user into leaving a lot of undesirable data scraping live.
Re: And the rest too, please
All the third-party systems that people use, like TrustArc, do that. It's utterly irritating.
Why would a cookie consent service use the IP address?
I always decline consent for cookies. That is a clear statement that I do not want to be tracked or recorded in any way. Why would sending my IP address to the cookie consent tracking service be allowed even if it was not in the US? IP addresses are very important personal data.
The obvious way to handle cookie consent is to place a cookie with just a UUID. When I visit again, send the UUID (only) to the consent service and get the answer. Sending the IP address is clearly not "necessary" and should be disallowed unless I consent.
Dare I say?
There should be NO tracking until consent is given, which is stored in a cookie. No consent cookie means do nothing until the opt-in button is clicked. If the user has DNT enabled then don't show the banner in the first place.
I believe that advertisers have deliberately confused and conflated the mass collection and sharing of data between their servers, with the individual motes of data in our browsers. By pushing the cookie banner in all of our faces we forget about the huge databases that exist without permission. This is like producers of disposable plastics paying for anti-litter campaigns or oil companies promoting home insulation - important issues to be sure but it evades the bigger questions.
Re: Dare I say?
@AC "There should be NO tracking until consent is given"
That does not go far enough consent should not be an option. Tracking should never be allowed and can't be consented to. Consent can never requested or given.
'Legitimate purposes'
A lot of sites are using the 'legitimate purposes' test of the six lawful grounds for allowable processing of personal data.
[1]https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/#what
(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)
[2]https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/
The ICO's view is
It is likely to be most appropriate where you use people’s data in ways they would reasonably expect and which have a minimal privacy impact, or where there is a compelling justification for the processing.
(More at the link)
I'd love to see the use for profiling/advertising challenged. It really needs a test case.
[1] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/#what
[2] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/
Re: 'Legitimate purposes'
If you're an advertiser, there's no such thing as "legitimate interests". You're a parasite, bugger off.
(and notice how the many "legitimate interests" options are always enabled by default with no "disallow all" option, but there's always an "allow all pillaging" button, it's subtle psychological conditioning)
Re: 'Legitimate purposes'
I've noticed more and more often, reputable UK and EU sites, if you got to their "customise" page, default all but essential cookies as off. Essential cookies, of course, can't be turned off (but can be blocked by you and I). To get there, of course, involves either clicking "Yes/OK" to everything, but at least if you choose the option, they are all off by default. On the down side, Yes is a simple click and the banner goes away while to turn them off is two clicks and an extra page load. But still miles better than some of those disgusting US sites with 120 tracking options, all on by default and must be clicked off one at a time.
(or just block all of them locally)
And the rest too, please
When will they finally kill google ad/tag manager and the like? That is illegal too. You cannot prevent them from loading, unless you block it beforehand(*). The "opt-out" is post-factum, which means that google already has your data. That is bad, very bad. EU sites using any third party service (and specifically those outside EU) should be prohibited by default unless the user consents.
(*) I do use NoScript, Greasemonkey and Privacy Badger. But the wwwnet is a tracking pain.