News: 1670477406

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Using personal info for ads without consent puts Meta in EU's gunsights

(2022/12/08)


European privacy regulators have determined that Meta's use of personalized advertising in Facebook, Instagram, and WhatApp violates data protection laws.

Specifically, the European Data Protection Board (EDPB), a group of EU privacy regulators, has [1]invalidated a prior decision by the Irish Data Protection Commission (DPC) that allowed Meta to bypass data use consent requirements through its apps' terms of service.

Under Europe's General Data Protection Regulation, which took effect in 2018, consumers must be allowed to decide whether companies can use their personal data. Shortly after the law took effect, privacy group Noyb [2]filed a complaint against Google, Instagram, WhatsApp, and Facebook for allegedly using personal data without adequate consent.

[3]

Meta, which became Facebook's parent company last year, tried to claim its use of personal information for advertising and tracking was contractually necessary – a GDPR consent exception generally extended to required data, like street addresses when shipping goods.

[4]

[5]

Max Schrems, an Austrian privacy advocate, lawyer, and founder of Noyb, said that Meta, rather than providing app users with a yes-or-no option for personalized ads, simply moved the consent clause into its apps' terms and conditions.

"This is not just unfair but clearly illegal," said Schrems in [6]a statement . "We are not aware of any other company that has tried to ignore the GDPR in such an arrogant way."

The long and winding road

After more than four years, the EDPB finally appears to have agreed with Schrems.

"This is a huge blow to Meta's profits in the EU," said Schrems. "People now need to be asked if they want their data to be used for ads or not. They must have a 'yes or no' answer and can change their mind at any time. The decision also ensures a level playing field with other advertisers that also need to get opt-in consent."

[7]

The decision means that the Irish DPC – which oversees Meta in the EU – is expected to issue a public ruling and potentially significant fines within a month.

According to Noyb, the EDPB decision means that Meta must alter its apps to provide a way to use them without providing personal data. It doesn't preclude the display of ads in general.

[8]EU Data Protection Board probes public sector use of cloud

[9]US commerce bosses view EU rules as threat to its clouds

[10]Dutch govt issues data protection report card for Microsoft

[11]EU and US seek 'common principles' for data governance and AI

The decision is not yet final: Meta has the option to appeal both the EDPB finding and Irish DPC ruling, whenever that appears. And the ad biz has made a habit of doing so.

Meta has been fined more than $900 million in privacy cases over the past year and a half: About $276 million in November 2022 [12]for failing to protect user's phone numbers from online scraping; about $402 million in September 2022 for [13]failing to protect children's data in Instagram; and about $266 million in September 2021 for [14]WhatsApp data collection .

Meta is currently challenging the Instagram and WhatsApp decisions. The social network did not immediately respond to a request to comment on how it intends to respond to the EDPB decision. ®

Get our [15]Tech Resources



[1] https://edpb.europa.eu/news/news/2022/edpb-adopts-art-65-dispute-resolution-binding-decisions-regarding-facebook-instagram_en

[2] https://noyb.eu/en/noybeu-filed-complaints-over-forced-consent-against-google-instagram-whatsapp-and-facebook

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5HD0YPmE@Hu0hkvQBxb0gAAAMk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5HD0YPmE@Hu0hkvQBxb0gAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5HD0YPmE@Hu0hkvQBxb0gAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://noyb.eu/en/noyb-win-personalized-ads-facebook-instagram-and-whatsapp-declared-illegal

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5HD0YPmE@Hu0hkvQBxb0gAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/02/15/edpb_cloud/

[9] https://www.theregister.com/2022/12/02/us_eu_cloud_regulation/

[10] https://www.theregister.com/2022/02/23/dpia_microsoft/

[11] https://www.theregister.com/2021/09/30/eu_and_usa_ai_data_share/

[12] https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-in-facebook-data-scraping-inquiry

[13] https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-instagram-inquiry

[14] https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-whatsapp-inquiry

[15] https://whitepapers.theregister.com/



Who else does this apply to ?

alain williams

For instance Google ?

Re: Who else does this apply to ?

Dinanziame

Google does ask for your consent, for example every time you do a search in incognito mode. It used to be you needed more clicks to reject all cookies than to accept all cookies, and they got fined for that, so now it's one click for both.

Re: Who else does this apply to ?

Screepy

Not quite on topic but since consent options have been mentioned...

A couple of months back Ghostery implemented their automatically 'opt out of all' functionality in their browser plugin.

It works surprisingly well I find.

Whenever I visit a new site, I see the consent pop-up window appear and then disappear as Ghostery automatically says no to all.

It makes me happy each time it happens - small victories :)

Re: Who else does this apply to ?

NopetyNope

If only there were some kind of way that browsers were able to pre-signal that decision without interruption. Maybe some kind of header would work, perhaps "do no tracking" or maybe better "do not track"...

Malicious compliance at it's finest from the entire tech sector at play here.

Re: Who else does this apply to ?

Anonymous Coward

But who Guards the Ghostery?

Schrems

Kevin Johnston

Can we get some sort of round of honours for this guy? With a very small number of politically driven exceptions he seems to be the only person willing/able to stand up and point to all the ways that big Corporations (and some politicians who may bear closer checks/cheques) are ignoring laws around data privacy to maximise profits

Clearly Illegal

Lil Endian

"This is not just unfair but clearly illegal," said Schrems in a statement.

Statute Law is not avoidable via Contract Law[1], so yeah, clearly illegal. Yet it still takes four years to move on a step, with the option of an appeal to further put the case in a holding pattern. That doesn't seem quite right to me.

Make the fine big . (Not advisable to hold one's breath.)

[1] Otherwise I'd bet all of Zuck's & Muck's ToSs would contain things like prima nocta and power of attorney.

Appeals

Pete B

There needs to be a change to stop this inevitable "appeal things as far as we can" and don't change anything until we've exhausted that route - maybe something along the lines of "If you appeal it and lose then the fine goes up by a factor of 10".

<Endy> taniwha: Have you TESTED this one? :)
<taniwha> Endy: of course not