Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, 18 May 2025

CfP: Collective Redress and Digital Fairness, deadline 1 June 2025

Dear readers, 

a quick note to highlight a great conference opportunity at the University of Amsterdam. 

The organisers of the conference "Collective Redress and Digital Fairness", which will be held at the University of Amsterdam on 10 and 11 December 2025,  have issued a call for papers open to scholars and practitioners who are interested in engaging with the conference's broad theme, namely "the intersection of collective redress and digital fairness, understood as the equitable treatment of individuals and society in the digital space" and who will bring an own insight with emphasis on (but not limited to) a number of central questions:

  • CfP flyer
    What are the theoretical and normative foundations of collective redress?
  • How effective is collective redress in the digital legal sphere at international, European, and national levels?
  • How do digital rights intersect with other branches of law (e.g., consumer and competition law), and what does this mean for collective actions?
  • What impact does litigation have on the compliance and governance of digital corporations?
  • How do private and public enforcement interact, and what role do collective actions play within this regulatory framework?
  • What is the role of private law and private law remedies in shaping digital fairness, and how does it constrain or contribute to collective redress mechanisms?

Contributions may focus on procedural and substantive law aspects, as well as theoretical, doctrinal, and empirical studies from national, European, and transnational perspectives. 


Thanks to sponsoring by the Dutch foundation for Collective Actions research, selected speakers will be provided one night of accommodation in Amsterdam and a reasonable travel budget. How to apply? You find the submission requirements on ACT's website and in the flyer! Deadline for application is 1 June 20225.

Monday, 22 November 2021

European Data Protection authorities speak up on targeted advertisement

 Dear readers, 

this is a teaching-intensive autumn across European universities - with all the excitement, uncertainty and overall strains of being mostly back in class after over a year of mostly living room lecturing. 

This, however, should not mean that we let crucial developments go unnoticed: last week, in fact, the European Data Protection Board (EDPB) has issued its most resolved opinion yet on the matter of privacy and behavioural tracking. Cookies, in other words - a staple not only of many people's secret kitchen stashes but also of equally elusive locations on our devices. 

The occasion for issuing this opinion is commenting on the Commission's Digital Services Act, which according to the Board should be brought more clearly in line with data protection rules. Couched among guidelines and standpoints on a number of highly salient issues - from counterterrorism to face recognition AI - the EDBP has called for 

1) considering a phase-out of targeted ads based on "pervasive tracking";

2) in any event, prohibiting targeted ads addressed at children.   

The opinion does not expand on the reasons for such standpoint, but mainly refers to previous positions  contained in comments on the DSA by the European Data Protection Supervisor (EDPS) and the European Parliament. In fact, criticism of the current rules' focus on informed consent has been around at least for the better part of the past decade (see for a classic Frederik Borgesius). 

The European data protection board is composed of representatives from the national data protection authorities. As a collective body mirroring positions in the Member States, its position can perhaps have more sway than the occasionally more principled stances of the EDPS. 

Wednesday, 25 August 2021

Update: Air passenger rights

In the busy past academic year we might have missed to report important consumer news. We will try to update the blog with the relevant references in the coming weeks, starting with this short update on air passenger rights.


Order in KLM Royal Dutch Airlines (C-367/20)

On 12 November 2020 the CJEU issued an order in this case asking for the clarification of some provisions of Regulation No 261/2004. The facts of the case concerned passenger travelling from outside of the EU to the EU via connecting flights (NYC-Amsterdam-Hamburg). The first connecting flight was operated by a non-Community air carrier under a code-share agreement, whilst the second one was operated by KLM (Community air carrier). The first flight was delayed to the extent that the final destination was reached with a delay of more than 3 hours. 

The main point of this order was that in case of connecting flights covered by a single reservation, if at least one of the connecting flights was operated by a Community air carrier, the connecting flights as a whole should be perceived as operated by a Community air carrier - and they fall, therefore, within the scope of the Regulation, pursuant to its Art. 3(1)(b) (para 23). As such, the long delay in reaching the final destination, which occurred as a result of events taking place during the first flight, could entitle the passenger to claim compensation under provisions of the Regulation. This claim could be made against the operator of the second flight, the Community air carrier involved in the performance of the connecting flights, despite them not being the cause of the delay.

Update on the revision of Regulation No 261/2004

This Regulation has been in the process of being revised since 2013, but the Council was at a stalemate in its discussion on it, partially due to the dispute between Spain and the UK as to the position of the airport in Gibraltar. Before the Covid-19 pandemic hit, the works in the Council moved forward - between November 2019 and March 2020. Then other issues took priority, but the revision of this measure is listed by the Commission on its priority list of its work programme for 2021 (See more on the EP website dedicated to this issue).

Vaccination Passports

Travelling during Covid-19 pandemic has been problematic and is meant to be facilitated nowadays by the use of vaccination passports. Notwithstanding various problems associated with the use of these passports (related to privacy, equal treatment, etc - see e.g. a paper by Ana Beduschi 'Covid-19 health status certificates: Key considerations for data privacy and human rights'), the technical process of not only putting them in place but also national passports being recognised in other countries (the ultimate goal for the travel industry) still is somewhat wonky. Just today The Independent reported on the British NHS Covid vaccine passports not being recognised in all of the Member States at the moment - e.g. Hungary, Italy and Latvia are mentioned as problematic. This apparently follows on the EU not having yet linked the UK's certification scheme to the EU one (although this has now been done for Swiss and Turkish schemes). See further: UK's NHS Covid Passport Still Not Recognised in Parts of Europe.

Monday, 29 June 2020

How concerned are Europeans about their privacy?

Under the European Commission’s request, the European Union Agency for Fundamental Rights recently prepared a report about the Europeans’ perspective on their online privacy and personal data (here). This report is based on a survey where 35 000 Europeans were asked about their views on privacy and about their awareness of the GDPR. The survey is from pre-pandemic times (January-October 2019), but its conclusions are highly relevant in a time where several European countries consider using technology to track the spread of COVID-19. For example, the Netherlands will soon launch an app that will keep track of who the app holder was in contact with, so as to quickly notify them in case of a possible contact with a COVID-19 infected person (see more about this here).

The report showed some interesting results, particularly a difference between the level of trust in private and public bodies. While 23% of respondents claimed that they do not want to share any personal data with public bodies, 41% do not want to share personal data with private companies. The results also show that the willingness to share personal data depends on the specific data to be shared: for example, while 63% of willing-to-share respondents would share their home address with public bodies, a mere 7% would share their political views.

The report also touched upon another well-known issue: people do not read terms and conditions before agreeing to them. Surprisingly, in this study, 22% of respondents claim to always read terms and conditions (approx. one in five) and 44% claim to read them sometimes. This means that in total 66% of respondents read at least sometimes the terms and conditions of the products or services they acquire. While still far from ideal, these numbers are higher than those reported in other similar studies (see, for example, the study by the Behavioural Insights Team on which we reported here). More worrying is the percentage of respondents who read the terms and conditions but do not understand them (27%). There are, however, relevant differences between Member States: for example, while in Belgium 47% of respondents do not read terms and conditions, in Estonia that number drops to 22%.

Finally, there is a high number of respondents who are aware of both the GDPR and of their national data protection supervisory authority (around 70%). 60% of respondents are aware that they are legally entitled to access their personal data held by public administrations (although this number decreases to 51% regarding private companies). Moreover, most respondents stated that they are aware of privacy settings on their smartphones (72%), although the results are not as positive regarding the privacy settings of specific apps (31%).

Wednesday, 11 April 2018

The Facebook-Cambridge Analytica fallout and user privacy

Dear readers, this time we need to refer to slightly less usual sources to report on some rather interesting developments concerning themes that have been often brought up on this platform. 

First, yesterday Facebook's CEO Mark Zuckerberg had the chance to exchange views for over five hours with a number of US representatives and said something interesting about privacy policies. In the most extensive coverage I could find on the issue, ie on Vice (!) he is reported to have responded to a question on data privacy and what the company intends to change going forward that 

“This  gets into an issue that we and others in the tech industry have found challenging which is that long privacy policies are very confusing,” Zuckerberg said. “One of the things we’ve struggled with over time is to make things as simple as possible so people can understand it. We don’t expect that most people will want to go through and read a full legal document.
While making disclosures more effective is certainly a theme which is dear to many of us, the conundrum which Facebook seems to struggle with would probably best be addressed by means of more stringent rules on what data can be shared by social media and other service providers, with whom, and for what purposes. According to the Vice piece, Facebook is also taking a number of other steps to improve its practices in data use and encourage whistleblowing on "abusive" advertising.

Meanwhile, quite appropriately it seems, the GDPR will enter into force next month! While previously much criticism had been raised by the industry about the new and somewhat more restrictive rules introduced by the regulation, Zuckerberg has recently announced that Facebook will - with adaptations - seek to comply with the regulation's standard across its worldwide operations (see coverage on Gizmodo). In the wake of the Cambridge Analytica scandal, it seems that somewhat more privacy protection is in fashion after all. 

Tuesday, 2 January 2018

Data protection in 2018: waiting for the GDPR...

Happy 2018 dear readers! 
The new General Data Protection Regulation, which may make it more difficult for websites and other providers to collect our data without express consent, will only come into force in a few months. 

Meanwhile, national authorities seem to be reaching a point where they are ready to adopt less straightforward strategies to put a halt to what feels to many as excessive practices. See for instance the German competition authority, Bundeskartellamt, whose president has just announced in the press (with an interview in the Rheinischen Post, see also here a summary in Die Zeit) that the authority is investigating Facebook's data collection activities as an abuse of dominant position.

Although Facebook has no German subsidiary, action under competition law seems to be made possible as long as the practice exerts its effects in German territory. The authority had already put Facebook on notice a few weeks ago, especially with reference to the practice of collecting data when consumers browse outside of the social network to later reconnect such data to the user's Facebook account. 

Facebook's main defence against the charge is that they are just one social network and users can easily opt for one of their competitors, so they do not enjoy the position of market dominance which is a precondition for any charge of abuse under competition law. Looking forward to seeing this issue develop!

Thursday, 20 October 2016

ECJ: dynamic IP addresses can be personal data- and yet websites may be able to store them without consent

Yesterday, the Court of Justice delivered its decision in Breyer v Bundesrepublik Deutschland (C-582/14, not yet available in English), a case concerning the lawfulness of the retention of dynamic IP addresses and other information by internet service providers. 

Mr Breyer contested the practice of the German federal government's websites, which keep a register of all IP addresses accessing information on their pages, together with a record of the pages visited and the time of each visit. The purpose of this information storage, according to the German government, is to prevent and/or readily prosecute cyberattacks. 

Two questions were raised before the Court of Justice: 1) whether, contrary to the assumptions of the Government when devising this practice, the information concerned constituted personal data under Directive 95/46; 2) if so, whether the German rules applicable to the retention of personal data by websites, which would make the Government's practice illegal, were compatible with the directive.

As to the first question, the Court of Justice answered that the collection of dynamic IP can be qualified as collection of personal data. The main issue to be discussed in this context was whether dynamic IP information, which is by definition not constantly associated to an individual user, can nevertheless be considered as capable of identifying that user. This is materially possible only through obtaining additional information from the internet service provider which has issued the IP number. 

Making reference to the directive's 26th recital, the Court reasoned that the answer to the question depends on the ability, for the website's owners, to obtain the "missing" information legally and without disproportionate expenditure. The ECJ considers that this possibility is clearly present in a case such as the one under scrutiny, especially in the event of a cyberattack. 

Therefore, the answer to the first question is that dynamic IP addresses are to be considered and treated as personal data by a provider which has the possibility to use them, in case of need, in order to identify the users associated to them. 

As to question 2), the Court had to consider the compatibility with Directive 95/46 of the German provision according to which- thus the interpretation prevailing in Germany- online service providers are only allowed to collect personal data for purposes related to their service provision- and charging of potentially ensuing fees. 

In particular, the Court considered whether a similarly interpreted restriction was compatible with article 7 letter f of the Directive, according to which providers can collect and preserve data in pursuit of their legitimate interests, provided they do not disproportionately impinge on the user's fundamental rights and liberties. The national legislation implementing the directive must leave some room for the balancing required by this provision. 

According to the Court, therefore, article 7 letter f of Directive 95/46 stands in the way of a national rule that generally disallows providers to store personal data with the purpose of securing the website's continued workability- which, inter alia, encompasses the prevention and prosecution of cyberattacks.

Thus, the answer of the second question is that the Directive does not allow national legislation to be interpreted in such a manner that would render the collection of personal data (ie dynamic IP addresses and access information) for the prevention of cyberattacks illegal.    

This decision is rather double-faced: on the one hand, it has a privacy-friendly attitude insomuch as it makes clear that all information can be personal data when the provider collecting it has the possibility to, at some point in time, use it to identify people who have accessed its webpages. On the other hand, though, it threatens to preempt national legislations giving a strict interpretation of the legitimate interests allowing data collection. It will be interesting to see which of the two faces will become more visible in the decision's aftermath. 

Monday, 19 September 2016

GDPR, e-Privacy and beyond: more certainty and coherence for the online sector (or quite the opposite)?

The interplay of GDPR and e-Privacy Directive

One of the objectives of the General Data Protection Regulation (GDPR), which was adopted earlier this year and will effectively replace Directive 95/46/EC in 2018, was to make the European data protection framework fit for the 21st century. The extensive regulation does indeed bring the existing framework up to date and promises greater uniformity of national standards and interpretations. Driven by the desire to empower data subjects to fully exercise their right to personal data protection (Article 8 of the European Charter of Fundamental Rights, Article 16 TFEU, Article 8 ECHR), the instrument builds on the existing safeguards and extends or clarifies them where it deems necessary. Among many other things, the new data protection regulation strengthens the conditions for a valid consent, ensures that data subjects are provided with information and access to their data and can effectively object to the processing, reiterates the right not to be subject to a measure based on automated data processing and explicitly clarifies that this includes profiling. It also introduces a widely cited right to be forgotten and the equally important right of data portability. All these are correlated with the corresponding obligations of data controllers according to the newly formulated principles of data protection ‘by design’ and ‘by default’. Both principles bring about a significant paradigm shift as they not only require data controllers to ensure data protection compliance ex ante (i.e. already at the planning stage), but also to design standard settings in a way that only the minimum amount of personal data necessary is being processed. The regulation also elaborates on the data controller’s obligation to ensure data security and report data breaches.

In line with the previous personal data protection directive, the principles laid down in GDPR apply to any information concerning an identified or identifiable person (as explained in recital 26). The novelty, however, lies in the clarification that online identifiers provided by devices, applications and protocols as well as location data may be used to identify a person (see further clarification in recital 30). Without going into detail, it seems fair to assume that under the new regime many online identifiers – such as IP addresses, device IDs and cookies, in particular third-party cookies used for profiling and targeting – will be regarded as personal data.

In short, what emerges from the updated data protection act is an increasingly comprehensive regime with an intentionally broad scope of application. Nevertheless, believe it or not, there are still several issues that have not been addressed by data protection framework. These relate more broadly to the protection of privacy (Article 7 of the Charter), and have so far been regulated by Directive 2002/58/EC on privacy and electronic communications (e-Privacy Directive). In the words of the European Commission the directive “sets out rules on how providers of electronic communication services, such as telecoms companies and Internet Service Providers, should manage their subscribers’ data”. It touches upon issues such as: confidentiality of communications, security of networks and services, data breach notifications as well as requirements regarding, among other things, unsolicited commercial communications (spam), storing of information in subscribers’ terminal equipment [Article 5(3) – the source of the ubiquitous cookie consent pop-ups] and processing of traffic and location data. The interplay between e-Privacy Directive and the general personal data protection legislation is mentioned in recital 173 of the GDPR, which stipulates that:

This Regulation should apply to all matters concerning the protection of fundamental rights and freedoms vis-à-vis the processing of personal data which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC of the European Parliament and of the Council, including the obligations on the controller and the rights of natural persons. In order to clarify the relationship between this Regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this Regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this Regulation

As a result, the directive is currently undergoing review and has yet again attracted considerable public interest. In August the European Commission presented a summary report on the public consultations which were carried out in this context. A careful, consumer-oriented analysis was, as usual, submitted by BEUC and is now available on its website.

Review of e-Privacy Directive and BEUC response

Why do we need an e-privacy instrument and which services should be included in its scope?

BEUC: While recognising the important developments within the framework of personal data protection, BEUC remains convinced that the e-Privacy Directive should continue to form a lex specialis for the online sector, complementing and particularising the provisions of GDPR. In view of BEUC, sector-specific rules should address, in particular, the issue of data mining and tracking/profiling of users as well as confidentiality of communications. The scope of such an act (ideally – a regulation) should cover both traditional electronic communication services and over-the-top (OTT) services such as Voice over IP and instant messaging (Skype, Whatsapp, Messenger). OTTs are currently outside the scope of e-Privacy Directive, as they do not fall under the definition of an electronic communication service, which requires inter alia "conveyance of signals".

Which issues remain unresolved under the current data protection regime?

Security and confidentiality

BEUC: Providers of electronic communication services should be obliged to secure all communications by using the best available techniques to ensure security and confidentiality. Users should remain free to apply other techniques.

Comment: While the need to ensure security of electronic communications seems undisputed, a potential overlap of the e-Privacy instrument and other pieces of legislation, in particular GDPR, NIS Directive and their implementing acts, should be taken into account. At the same time, there seems to be a strong case to maintain and even extend the scope of existing provisions referring to confidentiality to OTTs, as this issue does not seem to be addressed elsewhere.

Accessing users’ devices (e.g. in order to place a cookie)

BEUC supports the existing consent requirement laid down in Article 5(3) of e-Privacy Directive. More importantly, however, it argues that users should not be prevented from accessing non-subscription based services if they refuse the storing of identifiers (i.e. cookies) that are not necessary to provide the service. Furthermore, according to BEUC, the lifespan of cookies should be linked to their purpose.

Comment: Five years after the implementation of the cookie consent provision, no one dares to deny that the directive failed to achieve its desired impact. Indeed, consent requests are generally treated as a formality and essentially confront the users with a take-it-or-leave-it situation. BEUC proposal appears suitable to address this problem. At the same time, questions relating to the interface between e-Privacy Directive and the remaining EU acquis continue to arise. Couldn’t the requirement to provide users with a clearer and more granular choice and to adhere to the principle of data minimisation be derived from GDPR (now that online identifiers are clearly in its scope)? To what extent could the collection of data for purposes of tracking/profiling, without the knowledge of the user, be considered a misleading omission of material information and potentially an unfair commercial practice? Does anyone still remember the recent UCPD guidance which has actually elaborated on this matter? What about the proposed Digital Content Directive and Distance Sales Directive - shouldn't they have something more to say about this? Is the privacy rationale sufficient to extend the legal effects of Article 5(3) and, consequently, is the e-Privacy Directive the right instrument to regulate this issue? Before reopening of the whole cookie debate once again, it would seem reasonable to first assess where we stand.

Traffic and location data

BEUC: The consent requirement for the processing of traffic and location data should be maintained and the exemptions to this rule should not be broadened. On the contrary, the scope of the provision should be extended to cover GPS location data and Wi-Fi network location data used by information society services in mobile devices.

Comment: Stricter conditions for the lawful processing of traffic and location data (consent requirement for certain types of the processing) along with specific requirements as to erasure or anonymisation of data can indeed be seen as justifiable, given the undeniable privacy concerns at hand. There also seem to be no convincing reasons for maintaining a distinction between data collected by electronic communications service providers and by other information society services providers. At the same time, while understanding BEUC concerns about anonymisation, it needs to be recognised that traffic and location data are essential for the proper functioning of many digital services. The European legislator should therefore make sure that the revised instrument does not throw the baby out with the bathwater.

Unsolicited commercial communications

BEUC argues that marketing messages sent through social media should be subject to the same opt-in obligation that applies to email. Indeed, both channels of communication share certain similarities. In fact, however, unsolicited commercial messages on social media do not seem to present a serious problem and in this domain the issue of targeted advertisements appears much more pressing. 

Conclusion

Beyond doubt, the principles of personal data protection ‘by design’ and ‘by default’ enshrined in GDPR constitute a significant development in the data protection regime. In the technologically-mediated digital ecosystem, where traditional concepts are often difficult to apply and even harder to enforce, an increased focus on ex ante compliance (e.g. already at the stage of designing products/services or programming algorithms) could present a promising way forward. According to BEUC, the concepts of ‘privacy by design’ and ‘privacy by default’ should become “fundamental guiding principles in the online environment”. Given the growing importance of data-driven business models this appears to be a noble aim. The European legislator should, however, also make sure that innovation is not killed on the way – and to ensure that, more clarity as to the practical application and the interdependence of particular legal acts is necessary.