IAB Europe's ad consent popups pose privacy problem
- Reference: 1709896930
- News link: https://www.theregister.co.uk/2024/03/08/ad_tracking_popups_in_europe/
- Source link:
On Thursday, the CJEU upheld and clarified a 2022 decision from the Belgian Data Protection Authority (APD) that the identifiers used to record responses to popup consent solicitations under IAB Europe's [1]Transparency and Consent Framework (TCF) qualify as personal information.
The TCF plays a role in the Real-Time Bidding (RTB) system used to deliver targeted ads over the internet. It's essentially a standard way to present popup requests for consent to be tracked.
[2]
And RTB, it's argued, conflicts with Europe's GDPR and ePrivacy Directive. "RTB exposes the personal data of internet users to large numbers of companies without any means of control over what happens to that data," explained Johnny Ryan, from the Irish Council for Civil Liberties (ICCL), and Cristiana Santos, of Utrecht University, in a [3]2022 academic paper . "This is a security problem and is irreconcilable with the European legal requirement that processing of personal data must be secure, accountable, and transparent."
[4]
[5]
RTB is the process by which online ads get auctioned at high speed. It includes transmitting an identifier known as the Transparency and Control String (TC String) from web browsers to participating advertisers. These auctions broadcast personal data (what the person is viewing online or where they are located), according to Ryan and Santos, but lack security controls.
The APD determined that the TC String identifier amounts to personal information under Europe's General Data Protection Regulation because it can be used to link advertising preferences to an individual through an HTTP cookie and an IP address.
[6]
The APD also found that IAB Europe – the industry trade group that developed the framework – had been acting as the data controller under GDPR, raising the possibility of legal liability for privacy violations.
IAB Europe appealed the APD [7]decision [PDF], and now the CJEU has sided with the APD.
[8]Meta sued by privacy group over pay up or click OK model
[9]Europe bans Meta from using personal data to target ads
[10]Privacy advocate challenges YouTube's ad blocking detection scripts under EU law
[11]France says non to Office 365 and Google Workspace in school
"In its judgment, the Court of Justice confirms that the TC String contains information concerning an identifiable user and therefore constitutes personal data within the meaning of the GDPR," the CJEU declared in [12]a statement [PDF]. "Where the information contained in a TC String is associated with an identifier, such as, inter alia, the IP address of the user's device, that information may make it possible to create a profile of that user and to identify him or her."
The CJEU also ruled that IAB Europe qualifies as the "joint controller" under GDPR, but not the sole controller.
The case now heads back to the Brussels Markets Court, which will "resume its examination of IAB Europe's substantive arguments in line with the answers provided by the CJEU," as IAB Europe put it. A final decision is not expected for several months.
Safety first
Separately, the CJEU [13]found [PDF] the technical safety standards for toys and games cannot be withheld from the public.
Back in 2018, the European Commission denied two advocacy organizations – Public.Resource.Org and Right to Know CLG – access to technical safety standards covering toys and chemistry sets based on copyright claims. The groups, which support public access to the law, challenged that decision and were rebuffed by the General Court in 2021.
The groups appealed to the CJEU, which has reversed the General Court and annulled the European Commission's decision based on the public interest in accessible law.
"Relying in particular on the principle of the rule of law and the principle of free access to the law, the Court considers that the possibility for citizens to acquaint themselves with those standards may be necessary in order to enable them to verify whether a given product or service actually complies with the requirements of such legislation," the CJEU explained. "Accordingly, the Court finds that there is an overriding public interest in disclosure of the harmonized standards in question."
"People across Europe have been plagued by fake 'consent' popups every day on almost every website and app since the GDPR was introduced almost six years ago," lamented Johnny Ryan, of the Irish Council for Civil Liberties, in [14]a statement . "IAB Europe has sought to evade its responsibility for this charade. But the European Court of Justice has set it straight. This decision will not only end the biggest spam operation in history. It will deal a mortal wound to the online tracking-based advertising industry."
IAB Europe argues it's just a flesh wound. The ad group [15]welcomed the CJEU's clarification, which "will allow a serene completion of the remaining legal proceedings" and maintains that the ruling does not mean its TCF itself – already [16]revised for compliance [PDF] – is illegal.
[17]
"The CJEU ruling relates solely to those two key questions ('Is the TC String personal data?' and 'Is IAB Europe a (joint) controller regarding processing further to implementation of the TCF?') and does not contain any broader considerations on consent prompts," IAB Europe stated in an [18]explanatory note [PDF].
"There is therefore nothing in the CJEU ruling that could be viewed as even remotely questioning the legality of consent prompts or prohibiting their use by the digital ecosystem to comply with legal requirements under the EU's data protection framework."
"The CJEU ruling furthermore does not examine whether any activities of IAB Europe or TCF participants could be deemed any GDPR breaches. Instead, it only provides clarifications regarding the concepts of personal data and controllership and how they could apply depending on the circumstances." ®
Get our [19]Tech Resources
[1] https://iabeurope.eu/transparency-consent-framework/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZetEOWT@GgReI3ybYSZ-bwAAAU0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4064729
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZetEOWT@GgReI3ybYSZ-bwAAAU0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZetEOWT@GgReI3ybYSZ-bwAAAU0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZetEOWT@GgReI3ybYSZ-bwAAAU0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.autoriteprotectiondonnees.be/publications/decision-quant-au-fond-n-21-2022.pdf
[8] https://www.theregister.com/2023/11/28/metas_eu_privacy_fee_triggers/
[9] https://www.theregister.com/2023/11/01/eu_data_meta_networking/
[10] https://www.theregister.com/2023/10/26/privacy_advocate_challenges_youtube/
[11] https://www.theregister.com/2022/11/22/france_no_windows_google/
[12] https://curia.europa.eu/jcms/upload/docs/application/pdf/2024-03/cp240044en.pdf
[13] https://curia.europa.eu/jcms/upload/docs/application/pdf/2024-03/cp240041en.pdf
[14] https://www.iccl.ie/digital-data/european-court-of-justice-finds-iab-europe-responsible-for-tcf-consent-spam-popups-across-the-internet/
[15] https://iabeurope.eu/cjeu-ruling-clarifies-limited-role-of-iab-europe-in-tcf/
[16] https://iabeurope.eu/wp-content/uploads/2023/05/TCF_V-CMP_comms_TCFv2.2LaunchTimeline_160523_IABEurope.pdf
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZetEOWT@GgReI3ybYSZ-bwAAAU0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://iabeurope.eu/wp-content/uploads/20240223-FAQ_-APD-DECISION-ON-IAB-EUROPE-AND-TCF-Updated-March-2024-1.pdf
[19] https://whitepapers.theregister.com/
Re: Shut it all down, please
Oh - and what happens in the UK???
At least one Brit is asking themselves how to find/block/spoof the "TC Strings" generated by their devices. Why this isn't a default OS or browser choice is somewhat puzzling, as is a generic opt-out for all stalking and tracking garbage.
Re: Shut it all down, please
Long list of companies? Due to a potentially unlawful "interpretation" of the rules (my opinion), the French authorities have allowed for users to be given a choice to "accept all this tracking" or "pay/subscribe". There's no free choice possible so I don't know what mind twisting is necessary to think that is acceptable.
At any rate, a site I briefly stopped by (comment ça marche) had a pop-up that explained this and stated what would be done with my information and cookies placed on my machine by both them and their 275 partners .
Fuck that noise, I hit back so hard the shock wave created a singularity.
Re: Shut it all down, please
I'm pretty sure that you're right in that it is illegal. I thought that the judgement was that a choice has to be free and "otherwise you pay" isn't a real choice.
I've only seen this once on a French site... but I don't visit that many to be fair.
Re: Shut it all down, please
"Fuck that noise, I hit back so hard the shock wave created a singularity."
No sarcasm intended - how DO you hit back? Surely the choice is to walk away or accept, and that's it.
But here in Blighty ...
' either a "mortal wound" for online ad tracking, or a welcome clarification '
The current proposal in the UK (the Data Protection and Digital Information Bill) is to scrap the need to obtain consent, so apparently the problem is quite easy to "solve".
Re: But here in Blighty ...
Another Brexit benefit.
Open for business & stuff the consumer.
a "mortal wound" for online ad tracking
Kill it with fire.
"deal a mortal wound to the online tracking-based advertising industry"
Yeah. I believe in Santa Claus as well.
I only wish it could be true, but experience tells me that fucking assholes full of money generally get their way, whatever the law says.
Aliens
Best nuke it from space, it’s the only safe way
Shut it all down, please
The term 'charade' is used in this article, which is not strong enough.
It is a murky morass.
We are pestered several times a day by these stupid popups which are still designed to beat us into submission (consent). They are not transparent! Who reads the long list of companies under each category, let alone understands who they are or what they do - and what they do with 'your' data?
And more recently the notion that you also consent to 'legitimate interest', adding further sliders you have to undo (I thought that was illegal already).
Solution:
Make 'no consent' the default and not require removing consent from legitimate interest categories. Have a button on a website where the operator can put forward all the arguments why someone should consent. And if someone continues to browse, they don't...
Simple. And overdue.
Oh - and what happens in the UK???