News: 1642085291

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Austrian watchdog rules German company's use of Google Analytics breached GDPR by sending data to US

(2022/01/13)


The Austrian data protection authority has ruled that use of Google Analytics by a German company is in breach of European law in light of the Schrems II EU-US data sharing ruling.

Datenschutzbehörde, or DSB, has found that a German publisher, not named in the case, was in breach of Article 44 of the General Data Protection Regulation (GDPR) in the use and operation of Google Analytics – commonly used throughout web publishing and ecommerce – because of its movement of personal data to the United States.

In 2020, the EU Court of Justice [1]struck down the so-called Privacy Shield data protection arrangements between the bloc and the US in what is now known as the Schrems II ruling, which has ramifications for US cloud providers, social media sites, and providers of online tools.

[2]

It had been thought that standard contractual clauses (SCCs) may offer a way to continue to share data legally, [3]although that was also in doubt .

[4]

[5]

The latest Austrian ruling confirms that SCCs are not sufficient to comply with EU law and that so-called technical and organisational measures (TOMs), such as data centre security and baseline encryption, are also insufficient.

The complainant in the case, legal campaign group noyb, had visited the publisher's website while logged into a Google account, which was linked to the complainant's email address. The site contained embedded HTML code for Google services, including Google Analytics. The website processed personal data such as IP address and cookie data. The data had been transferred to Google, putting them under the purview of GDPR.

[6]

DSB found the publisher had been responsible for the sharing of data in its use of Google Analytics and that standard data protection clauses did not provide adequate levels of protection under GDPR because Google can be subject to surveillance by US intelligence agencies under so-called [7]FISA 702 rules.

Other measures taken by the German company did not eliminate the possibilities of surveillance and access by US intelligence services, the authority ruled. It had "therefore not ensured an adequate level of protection pursuant to Article 44 of GDPR," the authority said.

However, the Austrian authority found no violation by Google at this stage. The Chocolate Factory "does not disclose the complainant's personal data, but (only) receives them," the ruling said. It added that a possible violation of other GDPR articles by Google would be addressed in a later decision.

[8]

The findings were made on the basis of a submission by the publisher that it failed to implement an IP anonymisation function within Google Analytics due to a code error. During the case, the publisher instructed Google to immediately delete all data collected via the Google Analytics properties.

The configuration error in connection with the IP anonymisation function was also corrected and Google confirmed the personal data had been deleted. However, the authority said in its decision that the IP address is "in any case only one of many 'puzzle pieces' of the complainant's digital footprint."

As of yet, the authority has issued no fines over the ruling. As the publisher in question was originally registered in Austria, but is now registered in Germany via a merger, DSB will refer the case to its German counterpart.

[9]UK and USA seek new world order for cross-border data sharing and privacy

[10]German court rules cookie preference service that shared IP addresses with US firm should be halted

[11]UK watchdog's punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private

[12]Max Schrems hits Irish Data Protection Commissioner with corruption complaint

Max Schrems, honorary chair of noyb and the lawyer/campaigner behind the Schrems I and Schrems II cases, said similar decisions are expected in other EU member states as regulators have cooperated on these cases via a European Data Protection Board taskforce.

"This is a very detailed and sound decision. The bottom line is: companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced.

"We expect similar decisions to now drop gradually in most EU member states. We have filed 101 complaints in almost all Member States and the authorities coordinated the response.

"In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator – not to anyone in Europe," said Schrems.

In a statement, a Google spokesperson said: "People want the websites they visit to be well designed, easy to use, and respectful of their privacy. Google Analytics helps retailers, governments, NGOs and many other organizations understand how well their sites and apps are working for their visitors – but not by identifying individuals or tracking them across the web. These organisations, not Google, control what data is collected with these tools, and how it is used. Google helps by providing a range of safeguards, controls and resources for compliance." ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/11/01/data_transfers_europe/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.dni.gov/files/icotr/Section702-Basics-Infographic.pdf

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeBatsqvag7GE@sTAQFq3wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/12/09/uk_and_us_data_flows/

[10] https://www.theregister.com/2021/12/08/germany_cookie_service/

[11] https://www.theregister.com/2021/12/01/ico_reprimands_large_organisations/

[12] https://www.theregister.com/2021/11/24/max_schrems_files_corruption_complaint/

[13] https://whitepapers.theregister.com/



Will this ruling apply in the UK ?

alain williams

Following brexit ?

I hope so.

Re: Will this ruling apply in the UK ?

Jimmy2Cows

As do I, but I wouldn't hold my breath. It'll come down to how much Bojo wants to suck up to the US.

Re: Will this ruling apply in the UK ?

Andy The Hat

UK has committed to follow EU data protection policies. In simple terms, means your answer is no - we'll have a squabble with the EU over UK data sovereignty and our lovey-doveyness with the US and allowing giga-corps to suck us dry of data for free, then we'll cave in a bit until the next EU fan starts rotating.

Re: Will this ruling apply in the UK ?

Dan 55

No because UK-GDPR and GDPR are different things and court rulings in the EU don't affect the UK now. Companies may wish to treat the EEA and the UK as the same thing anyway to make things easier for themselves technically (no problem, EU rulings are probably always going to be more restrictive than the UK) or they want to monetize that data as much as possible and treat the UK differently.

Also:

Google Analytics helps retailers, governments, NGOs and many other organizations understand how well their sites and apps are working for their visitors – but not by identifying individuals or tracking them across the web

The Google PR guy is on trend by just outlandishly lying:

[1]DDG

[1] https://duckduckgo.com/?q=google+analytics+tracking+individuals&ia=web

Re: Will this ruling apply in the UK ?

fidodogbreath

PR guy is [...] outlandishly lying

Huh.

Re: Will this ruling apply in the UK ?

Mike 137

" UK-GDPR and GDPR are different things "

As they say in pantomime "oh no they're not" - at least in this case.

The UK-GDPR differs from the GDPR only in respect of its territorial scope and the repeal of a small number of articles, none of which affect this issue. The UK's DPA 2018 does make some changes, but again not relevant to this issue. There are plans to change the UK legislation quite significantly, and apparently in the direction of 'liberalisation', but they're still at the discussion stage. Consequently, the ruling (if it stands) would apply to the UK as well at present.

What is perfectly clear, however (and has been from dot), is that the data exporter has the primary duty, so it's incumbent on it to ensure that the importer meets comparable standards to those in the EU (and thus at present the UK) legislation. Currently the US doesn't, and didn't really even when Privacy Shield was accepted as it always was a non-statutory regime that could be overriden by options open to government agencies under federal law.

Max's wishful thinking

Gordon 10

"The bottom line is: companies can't use US cloud services in Europe anymore. "

No Max - that may be your wish but the ruling actually said you cannot send improperly protected PII to the US, and to Google in particular. Once they switched on IP anonymisation they were fine.

I dont necessarily disagree with Schrems aims but I object to the lack of nuance in his statement. I get that Max wants to attack the usual suspects like Google and Facebook - (and agree) but this avenue smacks of a sideshow.

Re: Max's wishful thinking

KarMann

That's somewhat how I was interpreting that at first, but then I got to this sentence in the article:

However, the authority said in its decision that the IP address is "in any case only one of many 'puzzle pieces' of the complainant's digital footprint." Considering 'the authority' referred to there is not Max, but '[t]he Austrian data protection authority', I don't think your (and formerly my) interpretation stands.

What!? Me worry?
-- Alfred E. Newman