Austrian watchdog rules German company's use of Google Analytics breached GDPR by sending data to US
- Reference: 1642085291
- News link: https://www.theregister.co.uk/2022/01/13/google_analytics_gdpr/
- Source link:
Datenschutzbehörde, or DSB, has found that a German publisher, not named in the case, was in breach of Article 44 of the General Data Protection Regulation (GDPR) in the use and operation of Google Analytics – commonly used throughout web publishing and ecommerce – because of its movement of personal data to the United States.
In 2020, the EU Court of Justice [1]struck down the so-called Privacy Shield data protection arrangements between the bloc and the US in what is now known as the Schrems II ruling, which has ramifications for US cloud providers, social media sites, and providers of online tools.
[2]
It had been thought that standard contractual clauses (SCCs) may offer a way to continue to share data legally, [3]although that was also in doubt .
[4]
[5]
The latest Austrian ruling confirms that SCCs are not sufficient to comply with EU law and that so-called technical and organisational measures (TOMs), such as data centre security and baseline encryption, are also insufficient.
The complainant in the case, legal campaign group noyb, had visited the publisher's website while logged into a Google account, which was linked to the complainant's email address. The site contained embedded HTML code for Google services, including Google Analytics. The website processed personal data such as IP address and cookie data. The data had been transferred to Google, putting them under the purview of GDPR.
[6]
DSB found the publisher had been responsible for the sharing of data in its use of Google Analytics and that standard data protection clauses did not provide adequate levels of protection under GDPR because Google can be subject to surveillance by US intelligence agencies under so-called [7]FISA 702 rules.
Other measures taken by the German company did not eliminate the possibilities of surveillance and access by US intelligence services, the authority ruled. It had "therefore not ensured an adequate level of protection pursuant to Article 44 of GDPR," the authority said.
However, the Austrian authority found no violation by Google at this stage. The Chocolate Factory "does not disclose the complainant's personal data, but (only) receives them," the ruling said. It added that a possible violation of other GDPR articles by Google would be addressed in a later decision.
[8]
The findings were made on the basis of a submission by the publisher that it failed to implement an IP anonymisation function within Google Analytics due to a code error. During the case, the publisher instructed Google to immediately delete all data collected via the Google Analytics properties.
The configuration error in connection with the IP anonymisation function was also corrected and Google confirmed the personal data had been deleted. However, the authority said in its decision that the IP address is "in any case only one of many 'puzzle pieces' of the complainant's digital footprint."
As of yet, the authority has issued no fines over the ruling. As the publisher in question was originally registered in Austria, but is now registered in Germany via a merger, DSB will refer the case to its German counterpart.
[9]UK and USA seek new world order for cross-border data sharing and privacy
[10]German court rules cookie preference service that shared IP addresses with US firm should be halted
[11]UK watchdog's punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private
[12]Max Schrems hits Irish Data Protection Commissioner with corruption complaint
Max Schrems, honorary chair of noyb and the lawyer/campaigner behind the Schrems I and Schrems II cases, said similar decisions are expected in other EU member states as regulators have cooperated on these cases via a European Data Protection Board taskforce.
"This is a very detailed and sound decision. The bottom line is: companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced.
"We expect similar decisions to now drop gradually in most EU member states. We have filed 101 complaints in almost all Member States and the authorities coordinated the response.
"In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator – not to anyone in Europe," said Schrems.
In a statement, a Google spokesperson said: "People want the websites they visit to be well designed, easy to use, and respectful of their privacy. Google Analytics helps retailers, governments, NGOs and many other organizations understand how well their sites and apps are working for their visitors – but not by identifying individuals or tracking them across the web. These organisations, not Google, control what data is collected with these tools, and how it is used. Google helps by providing a range of safeguards, controls and resources for compliance." ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/11/01/data_transfers_europe/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.dni.gov/files/icotr/Section702-Basics-Infographic.pdf
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2021/12/09/uk_and_us_data_flows/
[10] https://www.theregister.com/2021/12/08/germany_cookie_service/
[11] https://www.theregister.com/2021/12/01/ico_reprimands_large_organisations/
[12] https://www.theregister.com/2021/11/24/max_schrems_files_corruption_complaint/
[13] https://whitepapers.theregister.com/
Re: Will this ruling apply in the UK ?
As do I, but I wouldn't hold my breath. It'll come down to how much Bojo wants to suck up to the US.
Re: Will this ruling apply in the UK ?
UK has committed to follow EU data protection policies. In simple terms, means your answer is no - we'll have a squabble with the EU over UK data sovereignty and our lovey-doveyness with the US and allowing giga-corps to suck us dry of data for free, then we'll cave in a bit until the next EU fan starts rotating.
Re: Will this ruling apply in the UK ?
No because UK-GDPR and GDPR are different things and court rulings in the EU don't affect the UK now. Companies may wish to treat the EEA and the UK as the same thing anyway to make things easier for themselves technically (no problem, EU rulings are probably always going to be more restrictive than the UK) or they want to monetize that data as much as possible and treat the UK differently.
Also:
Google Analytics helps retailers, governments, NGOs and many other organizations understand how well their sites and apps are working for their visitors – but not by identifying individuals or tracking them across the web
The Google PR guy is on trend by just outlandishly lying:
[1]DDG
[1] https://duckduckgo.com/?q=google+analytics+tracking+individuals&ia=web
Re: Will this ruling apply in the UK ?
PR guy is [...] outlandishly lying
Huh.
Re: Will this ruling apply in the UK ?
" UK-GDPR and GDPR are different things "
As they say in pantomime "oh no they're not" - at least in this case.
The UK-GDPR differs from the GDPR only in respect of its territorial scope and the repeal of a small number of articles, none of which affect this issue. The UK's DPA 2018 does make some changes, but again not relevant to this issue. There are plans to change the UK legislation quite significantly, and apparently in the direction of 'liberalisation', but they're still at the discussion stage. Consequently, the ruling (if it stands) would apply to the UK as well at present.
What is perfectly clear, however (and has been from dot), is that the data exporter has the primary duty, so it's incumbent on it to ensure that the importer meets comparable standards to those in the EU (and thus at present the UK) legislation. Currently the US doesn't, and didn't really even when Privacy Shield was accepted as it always was a non-statutory regime that could be overriden by options open to government agencies under federal law.
Max's wishful thinking
"The bottom line is: companies can't use US cloud services in Europe anymore. "
No Max - that may be your wish but the ruling actually said you cannot send improperly protected PII to the US, and to Google in particular. Once they switched on IP anonymisation they were fine.
I dont necessarily disagree with Schrems aims but I object to the lack of nuance in his statement. I get that Max wants to attack the usual suspects like Google and Facebook - (and agree) but this avenue smacks of a sideshow.
Re: Max's wishful thinking
That's somewhat how I was interpreting that at first, but then I got to this sentence in the article:
However, the authority said in its decision that the IP address is "in any case only one of many 'puzzle pieces' of the complainant's digital footprint." Considering 'the authority' referred to there is not Max, but '[t]he Austrian data protection authority', I don't think your (and formerly my) interpretation stands.
Will this ruling apply in the UK ?
Following brexit ?
I hope so.