Norwegian Consumer Council and seven European consumer organisations have filed a complaint today against Google, arguing that Google uses deceptive design and misleading information in order to acquire users' consent to constant tracking (New study: Google manipulates users into constant tracking). How would the users be tracked? Well, if you have an Android phone or use Google accounts on other devices, then it is likely that you are one of the victims of constant tracking, as Google accounts have 'location history' and 'web&app activity' integrated in their settings. You may have been prompted/manipulated to switch on such location history, without having realised that. Having read the above information you may think that Google has 'simply' access to your GPS data. Would you know though how detailed this data is (incl. determining which floor you are at in a particular building, which room in the house) and that it may be linked to other information, e.g., your online search results? The combined data may, of course, then be used for targeted advertising, increasing its effectiveness. Would you know how to switch it off and how to avoid having it be switched on again? If this short post does not make you want to check your phone and its settings, maybe you should look up the whole report on the study of Google tracking practices that has been published: Every step you take.
Showing posts with label privacy issues. Show all posts
Showing posts with label privacy issues. Show all posts
Tuesday, 27 November 2018
Monday, 24 April 2017
GDPR, e-Privacy and beyond (part 2): the struggle over privacy and data protection continues
The European Union has traditionally aimed to set comparably high standards of privacy and personal data protection. Indeed, the protection of personal data constitutes a fundamental right, enshrined in Article 8 of the Charter of Fundamental Rights and in Article 16(1) of the Treaty on the Functioning of the European Union. This part of the picture is also closely linked to the protection of privacy set out in Article 7 of the Charter. Therefore, it is not surprising that the question of personal data was already addressed in 1995, in a dedicated instrument, while the importance of confidentiality and anonymity was consequently underlined in the first "e-directives": on e-privacy and on e-commerce. At the same time, processing of personal and non-personal data is an element of the freedom to conduct a business and its free flow is crucial from the point of view of the internal market and international trade. All of these dimensions are, of course, highly relevant to the European consumers and have gained even more prominence in the era of digitalisation.
Last year brought several major developments in that regard, with General Data Protection Regulation as a top highlight. While the GDPR is certainly a quantum leap, it is by no means the only measure which had spurred heated debates. Let us summarise the state of play.
GDPR and e-Privacy
Five years after first consultations about the need for a legal reform of personal data protection framework in Europe had been launched, a new instrument - General Data Protection Regulation - was finally adopted on 27 April 2016 and will soon replace the existing Directive 95/46/EC. The regulation entered into force on 24 May 2016 and will become directly applicable in all Member States from 25 May 2018 (see also our earlier post on this topic here).
One of the important novelties concerns the act's extraterritorial reach. Applicablity of the European regime will no longer depend on “the use of equipment” situated in a Member State, but rather on the context and effects of the processing of personal data. The content of the GDPR largely builds upon the existing Data Protection Directive. The instrument strengthens the conditions for a valid consent and defines an age threshold for the consent of a child. More emphasis in placed on the rights of data subjects such as the right to information and access to one’s personal data as well as to rectification and restriction of the processing. Article 22 reiterates the right not to be subject to a measure based on automated data processing and explicitly clarifies that this includes profiling. Furthermore, the GDPR introduces a widely cited right to be forgotten and an equally important right of data portability. Rights of data subjects are correlated with respective obligations of data controllers and data processors, in accordance with the newly formulated principles of data protection ‘by design’ and ‘by default’.
Throughout 2016 preparatory works on the review of the Directive 2002/58/EC on privacy and electronic communications were also carried out in order to ensure the consistency of this sector-specific instrument with the overall framework enshrined in the GDPR. As we have already reported, the proposed e-Privacy Regulation was eventually tabled on 10 January 2017.
Apart from the shift in the legal form (from a directive to a directly binding regulation), the proposal provides for a number of substantive changes. A major difference concerns the scope of the measure, which would be extended to all electronic communications providers, i.e. not only telcos, but also over-the-top players. Requirements relating, among others, to the confidentiality of electronic communications, would therefore also apply to providers of services such as voice over IP or instant messaging (Skype, Whatsapp, Messenger). The proposal also clearly refers to machine-to-machine communications - a circumstance which, together with a broad definition of personal data in the GDPR, has not been warmly welcomed by the tech companies. Other novelties include an updated approach to cookies and enhanced protection against spam. With respect to the former, the Commission eventually opted against the principle of 'privacy by default' - a reason for relief for the industry. Emphasis is now placed on the availability of privacy settings in the relevant software applications (such as internet browsers) and not on the ubiquitous pop-up windows. The reform should further ensure terminological consistency not only between the GDPR and the e-Privacy Regulation, but also with the updated telecom framework. In the proposed e-Privacy Regulation itself, the concept of ‘electronic communications data’ was introduced, covering both content data and metadata. As before, electronic communications which remain under protection may contain both personal and non-personal data, for example data related to a legal person. From the Commission’s perspective, the new framework should ideally apply from the same day as the GDPR.
As for now, preparatory works at the Council appear to be at a very early stage. The responsible committee in the European Parliament is the Civil Liberty, Justice and Home Affairs (LIBE). Two weeks ago the committee held a hearing to discuss the proposal. The plenary vote on the committee’s report is expected in October.
Transatlantic dimension
Further notheworthy developments refer to data transfers between the EU and the United States. This strand of the debate clearly shows that there is no single, universally recognised approach to data protection and privacy online. As seen from the efforts to ensure extraterritorial application of both GDPR and the proposed e-Privacy regulation, the European legislator would like to see its framework applied also where data of European citizens are processed outside the Union. A similar approach is observed with respect to cross-border data transfers. According to an established rule, dating back to the 1995 Data Protection Directive, personal data of the European citizens may only be transfered to third countries that ensure “an adequate level of protection”. In the United States, home country to the thriving tech industry, the European approach is often regarded as paternalistic. The importance of transatlantic data flows for the international trade forces European and American decision-makers to meet halfway.
Until October 2015, transfers of personal data between the EU and the U.S. had been governed by the so-called Safe Harbour Decision. Following the Snowden revelations, the decision was, however, successfully challenged before the Court of Justice. In the widely cited Schrems case, the Court confirmed that the Commission's decision, and therefore the underlying agreement with its U.S. counterparts, failed to ensure that the level of personal data protection in the United States was “essentially equivalent” to the one guaranteed within the EU. After renegotiations a new agreement was reached and, in the decision of 12 July 2016, the European Commission reconfirmed the adequacy of the American framework. The so-called EU-U.S. Privacy Shield provides for a number of new safeguards, including the entirely new Ombudsperson mechanism, the functioning of which shall be monitored annually.
As expected, a few months after the decision came into force, the Privacy Shield was challenged by privacy advocacy groups before the General Court. The Commission is naturally defending its compromise, but the stance taken by the new U.S. administration is not helping its case. Only last week the European Parliament adopted a resolution voicing its concerns about new U.S. laws allowing National Security Agency to share diverse personal data with other agencies and criticising the rejection of the rules preventing unrestricted sharing of customers’ browsing data. While in the current resolution these issues are discussed only in the context of the Privacy Shield, one may wonder if similar concerns cannot be raised with respect to the Umbrella Agreement - another transatlantic agreement adopted last year, this time in the field of law enforcement.
Have your say
As seen from above, the wealth of issues and regulatory approaches to privacy and data protection as well as the pace of new developments are astonishing. Even where new rules have already been developed with all these needs and concerns in mind, they are likely to face criticism and require further modifications. Sceptics argue that the GDPR will be out-dated from day one. For what it's worth, European policy-makers appear to be aware that the struggles over privacy and data protection are bound continue. Most recently, the European Commission launched a series of public consultations as part of its Next Generation Internet Initiative. Over the coming weeks a number of questionnaires will be available online, allowing everyone to share their views. The first questionnaire, entitled “New technologies for disrupting the economy: business, employment and skills”, is available here. We invite our readers to have a say.
Friday, 9 December 2016
Camera, Camera, on the Wall...
The latest issues of INsights #18 contains a short article by Joasia Luzak 'Camera, Camera, on the Wall...' which introduces to the general public a previous joint publication by P. Lewinski, J. Trzaskowski and J. Luzak 'Face and Emotion Recognition on Commercial Property under EU Data Protection Law' published in Psychology & Marketing, vol. 33, issue 9, pp. 729-746. If you are interested in issues of privacy and how new technologies may challenge it, it's worth it to give it a read. Tuesday, 2 February 2016
New safe harbour agreement reached
A quick update for our readers on the legal guarantees surrounding data flow between EU and US: today, the Commission and the American government have reached an agreement that will replace the "safe harbour" agreement struck down by the CJEU last October (see our post here). The new agreement has been labelled "EU-US privacy shield".
The deal is supposed to represent a major improvement compared to its predecessor, which, according to the Court of Justice, did not offer sufficient guarantees that the private data of European citizens would be processed in an acceptable ways once transferred to US-based companies and agencies.
According to the Commission's releases, the "privacy shield" should provide both clear rules for companies handling data and limitations on the US government's access to such data. Further, European citizens fearing that their data is being mishandled should have several remedies available.
According to the Commission's releases, the "privacy shield" should provide both clear rules for companies handling data and limitations on the US government's access to such data. Further, European citizens fearing that their data is being mishandled should have several remedies available.
Also this time, take a look at the Guardian's nice article on the topic for some more context.
Tuesday, 6 October 2015
ECJ "Facebook" case: EU -US safe harbour agreement invalid
Just today, the European Court of Justice declared (Schrems v Data Protection Commissioner, C-362/14) that the 2000 Commission decision which allowed the transmission of EU citizen's data to the United States is invalid. The decision, according to the Court, failed to show that the Commision had actually considered whether the United States guaranteed a level of protection of fundamental rights "essentially equivalent" to the one afforded in the European legal order.
See more extensively the excellent coverage by the Guardian here and, here (with some speculations on what the decision entails.
PS the case was initiated by the same guy whose other actions we had talked about some time ago.
Tuesday, 28 July 2015
EDPS's data protection recommendations: "Europe's big opportunity"
Yesterday the European Data Protection Supervisor published his recommendations on the EU's options for data protection reform - Opinion 3/2015 Europe's big opportunity (see here). Also, a new app has been launched - EU Data Protection - that allows everyone to compare on their smartphones the latest texts of the new law on data protection, as they've been proposed by various European legislators. These have been issued in the past 3 years (starting with the Commission's proposal of January 2012) and the intention is to finalize the text of the new law by the end of this year.
The EDPS argues, among other, for:
- possibility for users to have control also over pseudonymised data;
- data only being able to be used for original purposes of its collection;
- preventing "coercive tick boxes" - forcing internet users to agree to data collection and processing when there is no need for it;
- providing an option to give broad or narrow consent to data collection and processing (instead of "all or nothing" approach);
- establishing "an effective system of liability and compensation for damage caused by the unlawful data processing" with a possibility of consumer organisations, among others, claiming these damages for internet users;
- introducing the principles of data protection by design and by default with more transparency and simpler wording when rights of internet users are integrated in default settings;
- upon internet users' request data controllers could directly transfer data to other controllers;
Wednesday, 15 July 2015
Reading tip: Guardian article on Google "right to be forgotten" requests
Our readers will remember that since last year's ECJ decision in Google Spain, it is possible for individuals who think certain information concerning them should not be featured among Google's search results to demand the search engine to put a filter in place by filling in a simple form.
The Guardian has perused Google's transparency report from last year and found some interesting information as to the way this possibility has been made use of so far. The ensuing article really makes a worthy read.
Thursday, 2 July 2015
1:0 for Goliath - short update
Regarding the collective action against Facebook's data protection laws initiated by Max Schrems that we discussed previously the Regional Civil Court Vienna (“Landesgericht Wien”) dismissed the case on formal grounds. Schrems announced to appeal the decision.
For further details in German click here.
Labels:
data protection,
online transactions,
privacy issues
Monday, 15 June 2015
Comeback of the EU data protection reform
Today the Council announced that its ministers agreed to open negotiations with the European Parliament on the new data protection rules. The Data Protection Directive has been under review for quite some time, with the European Commission proposing new rules in January 2012 (see our previous post EU data protection reform announced) and the European Parliament supporting them in March 2014 (New EU data protection rules - one step forward). It's quite controversial whether data protection can be improved, whether and to what extent this improvement is desirable (considering e.g. often conflicting consumer interests - in privacy but also in lowering transaction costs). The reform is, therefore, still likely to take some time. However, the first talks between European legislators are to commence already this month. As a result of the reform consumers rights are to be strengthened through the right to be forgotten, a right to data portability, data protection by design and by default, a right to be notified of personal data breaches. Enforcement of data protection is to be strengthened to. (see Stronger data protection rules for Europe) Wednesday, 18 February 2015
Consumer law as a solution to online privacy issues?
Can (European) consumer law be used to help increase privacy protection online? Other solutions applied so far (e.g. mandatory disclosures about privacy policies; informed consent requirement) are constantly being evaluated as insufficiently effective. Consumer protection organisations, etc. are, therefore, starting to consider the application of more traditional consumer protection measures to protect privacy online. Together with my colleague, Marco Loos, we have already considered whether, e.g., consumer protection against unfair contract terms and private international law rules protecting consumers could apply to contracts for the provision of online services and what scope of protection they could guarantee consumers (see Wanted: A Bigger Stick. On Unfair Terms in Consumer Contracts with Online Service Providers). Some national courts (in France and Germany) are already engaged in evaluating the applicability of such consumer protection measures to online privacy policies and other online terms and conditions (see European Consumer Legislation and Online Privacy Policies: Opening Pandora's Box). French consumer agency DGCCRF also published certain recommendations as to what clauses could be considered abusive or illicit under French consumer law (Recommendation no. 2014-02). The authors of the online article (M. Kuschewsky, C. Ryckman) worry about the possibility that the consumer protection measures could apply to the evaluation of online privacy policies, since this could: 1. complicate the legal environment for the assessment of the validity of such terms (consumer legislation applying next to and not instead data protection legislation); 2. increase competence quarrels between the authorities supervising online traders and service providers (consumer authorities next to data protection authorities). These worries may, of course, be justified to an extent. However, the (European) courts and legislators could introduce legal certainty as to the scope of application of consumer protection measures to online privacy policies and consumer and data protection authorities could work together enforcing compliance therewith. This could give enough incentive to online service providers and traders to introduce more transparent, user-friendly terms and conditions, also in their privacy policies. Indeed, this could signify that these traders/ service providers would need to provide two sets of terms and conditions: EU and global ones, but as long as the protection in the EU would be harmonised and not country-specific, the costs thereof could be limited. Wednesday, 11 February 2015
Coupling Data Protection measures and the Passenger Name Record proposal
Today, the European Parliament adopted a joint resolution pledging to proceed speedily towards the adoption of various anti-terrorism measures. In this context, as we noticed earlier, also the proposal for a Passenger Name Record directive is again on the table. To this regard, the Parliament insists on the need to adopt a comprehensive and possibly consistent framework on data protection.
Important steps in order to match anti-terrorism efforts and a reasonable protection of citizens' privacy include encouraging Member States to make progress on the Data Protection Package and, importantly assessing the consequences of the EU Court of Justice’s annulment of the
Data Retention Directive. To this end, the Parliament hopes that the Commission will seek independent experts' views on the
"necessity and proportionality" of the PNR proposal
Monday, 26 January 2015
The Passenger Name Record proposal reloaded
The directive would make the collection of data concerning the identity of passengers flying to and from outside the EU (and possibly also within its borders) more widespread and systematic.
More information on the proposal, the state of the debate and existing PNR agreements with third parties can be found on the EP's information page.
Monday, 24 November 2014
Press digest
Mobile banking
The Financial Times Adviser discusses the ongoing plans to regulate on the European level mobile banking (Getting mobile banking working). Currently, the revision of the Payment Services Directive and of the Regulation on Multilateral Interchange Fees is being negotiated among the European institutions.
On review of the mobile banking industry in the UK conducted by the Financial Conduct Authority see: Mobile Banking and Payments - FCA Industry Review. Important: no evidence of consumer harm was found in the mobile banking and payments area.
Tobacco Products Directive
Another company - Philip Morris International - was granted a right by the English courts to apply for a preliminary ruling in front of the Court of Justice with regards to the interpretation of the Tobacco Products Directive. This time it is the competence of the EU to regulate in this area that is being questioned: the argument is that the Directive does not aim to improve the internal market (e.g. it prohibits menthol even though it's legal in all Member States); that the Directive infringes consumers fundamental rights to information about the products they are choosing (through forcing companies to adopt plain packaging); as well as whether the delegation of power to the Commission to specify certain issue was validly defined (Philip Morris International Granted Right to Challenge EU's Tobacco Products Directive Before the Court of Justicce of the European Union).
Mortgage Credit Directive
Telegraph reports on the uncertainties related to the implementation of the new Mortgage Credit Directive in the UK - who exactly may be seen as consumer and fall under the Directive's scope? "Accidental landlords" - that is persons who became landlords "as a result of circumstance rather than through their own active business decision" will be seen as consumers. Who is that exactly? And what rules shall apply to buy-to-let mortgages? (Would this buy-to-let couple be caught out by new EU rules?)
Privacy online
If you are interested to see which applications and which online tools have what sort of privacy protection, check this data on the Secure Messaging Scorecard (A project of the Electronic Frontier Foundation).
US consumer news (just for fun)
Verizon fights against the Federal Communications Commission plan to introduce net neutrality, threatening to take them to court: Verizon: We Will Sue FCC Again If "Hybrid" Net Neutrality Happens.
Berkeley, California becomes the first American city to introduce a tax on sugary drinks: California City Votes In The Nation's First Soda Tax
Apple is being sued for an equivalent of wiretapping due to users who switched from an iPhone to an Android phone not receiving their iMessages (More Former iPhone Users Suing Apple, Claiming iMessage "Intercepts" Texts Meant for Android Phones).
Federal Trade Commission sues Gerber Products Co. for falsely advertising that its Good Start Gentle formula prevents or reduces the risk of children developing allergies (FTC Sues Gerber For False Advertising Over Claims Its Formula Can Prevent Allergies).
Wednesday, 22 October 2014
Press digest
Telecommunication
The European Commission announces not to further regulate fixed telephone lines, since the market moved towards mobile and online telecommunication. (Europe says goodbye to fixed line regulation, hello to mobile era)
Tobacco Products Directive
UK e-cigarette manufacturer, Totally Wicked, challenges the validity of art. 20 of the Tobacco Products Directive at the CJEU, claiming that e-cigarettes should not be regulated as "tobacco related products" if they don't contain tobacco. (E-cig manufacturer wins right to challenge Brussels in EU courts; Totally Wicked vs. the EU's tobacco directive; First e-cig TV adverts from next month)
EU Data Protection and ePrivacy rules
Worries are being expressed about strengthening existing data protection rules even when businesses do not seem to be able to hold to currently existing ones (EU set to strengthen data protection laws). Data Protection Authorities across the EU are currently stepping up enforcement of the compliance with the existing EU data protection rules, by conducting a widespread cookie sweep (Are you ready? The EU "Cookie Sweep" is upon us). Other sources report widespread non-compliance of cloud-based storage service providers with the existing EU data protection rules (Most cloud apps flout EU data protection rules - study).
Tourism sector
TUI Travel argues in the UK for more support to be given to the reform of the Package Travel Directive and the Regulation No 261/2004 on air passenger rights. (TUI Travel calls on UK government to support the travel and tourism sector at home and abroad)
Competition
European booksellers plead with the European Commission and BEUC to set up investigation into the monopoly position of Amazon in the online book market, which harms European consumers by depriving them of a rich and diversified online book offering. (Booksellers raise Amazon monopoly concerns with European Commission)
Health claims
The new rules on food labelling (EU Regulation 1169/2011 on food information to consumers) are to enter into force as of December 2014 (nutrition information as of December 2016). Especially the sport nutrition sector may have to invest time and money to adjust the labels of their products to the new rules. While this regulation forces producers to be very specific in listing ingredients of their products, it may be even more difficult for the producers to justify placement of easy claims on how certain products may boost energy etc. (which are also regulated by Regulation 1924/2006). (Claim, set and match)
Consumer behaviour
Two new survey results have been published showing us growing trends of consumer online shopping habits. (UK leads European online shopping; Northern European web shoppers spent €1,780 each in 2013) In the meantime, Facebook sets up a new division - Facebook IQ - to try to understand consumer behaviour better... (Facebook forms new unit to study consumer behaviour).
Labels:
air travel,
cloud computing,
competition,
consumer behavior,
consumer health,
cookies,
data protection,
digest,
food,
labelling,
package travel,
privacy issues,
telecommunication,
tobacco,
tourism
Tuesday, 2 September 2014
The Data Brokers
Good video on dangers to consumers' privacy, on how data is gathered, trafficked and how we remain oblivious to it. See CBS' "60 Minutes - The Data Brokers" on YouTube or here.
Wednesday, 30 July 2014
Smart chips in your clothes, groceries, e-tickets
Tuesday, 13 May 2014
Google as data controller and right to be forgotten - CJEU in Google Spain (C-131/12)
13 May 2014: CJEU judgment in Google Spain (C-131/12)
We have previously discussed the opinion of AG Jääskinenin the Google Spain case, where he argued that an online service provider like Google (providing search engine services) should not be considered to fall under the definition of a data controller, meaning that it would not be obliged to comply with the data protection requirements and control what data is revealed through its search results. (see No forgetting...) Interestingly, in today's judgment the CJEU takes a different stand on these issues.
"According to Google Spain and Google Inc., the
activity of search engines cannot be regarded as processing of the data
which appear on third parties’ web pages displayed in the list of
search results, given that search engines process all the information
available on the internet without effecting a selection between personal
data and other information. Furthermore, even if that activity must be
classified as ‘data processing’, the operator of a search engine cannot
be regarded as a ‘controller’ in respect of that processing since it has
no knowledge of those data and does not exercise control over the data." (Par 22)
While, Google Spain claimed that it should not be seen as either a data controller or a subject of data protection rules, the CJEU disagreed, mentioning that already previously loading of personal data on a website that was considered as falling under the data processing definition from the Data Protection Directive. (Par. 26)
"Therefore, it must be found that, in exploring
the internet automatically, constantly and systematically in search of
the information which is published there, the operator of a search
engine ‘collects’ such data which it subsequently ‘retrieves’, ‘records’
and ‘organises’ within the framework of its indexing programmes,
‘stores’ on its servers and, as the case may be, ‘discloses’ and ‘makes
available’ to its users in the form of lists of search results. As those
operations are referred to expressly and unconditionally in
Article 2(b) of Directive 95/46, they must be classified as ‘processing’
within the meaning of that provision, regardless of the fact that the
operator of the search engine also carries out the same operations in
respect of other types of information and does not distinguish between
the latter and the personal data." (Par. 28)
This finding cannot be contradicted by a claim that personal data has already been published somewhere else online and not changed by the search engine. (Par. 29, 31) Moreover, since the definition of data controller in the Directive should be broadly understood, the fact that Google may not have control over what's posted on other websites doesn't exclude it from under this definition. (Par. 33-37)
The CJEU also reminds the need to protect both private life and personal data, since these are among the fundamental rights mentioned in the Chapter. (Par. 69) While the data subject may request revision or removal of his personal data from the search engine's results, this request for data protection can clash with the freedom of expression and other people's right to information.
"In the light of the potential seriousness of
that interference, it is clear that it cannot be justified by merely the
economic interest which the operator of such an engine has in that
processing. However, inasmuch as the removal of links from the list of
results could, depending on the information at issue, have effects upon
the legitimate interest of internet users potentially interested in
having access to that information, in situations such as that at issue
in the main proceedings a fair balance should be sought in particular
between that interest and the data subject’s fundamental rights under
Articles 7 and 8 of the Charter. Whilst it is true that the data
subject’s rights protected by those articles also override, as a general
rule, that interest of internet users, that balance may however depend,
in specific cases, on the nature of the information in question and its
sensitivity for the data subject’s private life and on the interest of
the public in having that information, an interest which may vary, in
particular, according to the role played by the data subject in public
life." (Par. 81)
Keeping this in mind, the CJEU then decides that "the operator of a search engine is obliged to
remove from the list of results displayed following a search made on the
basis of a person’s name links to web pages, published by third parties
and containing information relating to that person, also in a case
where that name or information is not erased beforehand or
simultaneously from those web pages, and even, as the case may be, when
its publication in itself on those pages is lawful.". (Par. 88)
Finally, the CJEU recognizes the "right to be forgotten". The data controller, like Google may need to remove data that originally was published lawfully, but which became with time "no longer necessary in the light of the
purposes for which they were collected or processed. That is so in
particular where they appear to be inadequate, irrelevant or no longer
relevant, or excessive in relation to those purposes and in the light of
the time that has elapsed." (Par. 93)
For the applicability of the Directive to Google's services, please read the judgment further (replies to question 1) where the CJEU debates the matter of, among others, establishment's definition. (Par. 45-61)
This is an interesting decision that might lead to some practical difficulties in its application. Imagine that consumers start now asking Google to remove various links leading to websites containing information about them en masse. How long would Google have to react to these requests/demands, when would it be able to refuse to remove a link from a search engine (who decides whether the content on that website was lawfully published or stopped being relevant etc.?), etc?
This is an interesting decision that might lead to some practical difficulties in its application. Imagine that consumers start now asking Google to remove various links leading to websites containing information about them en masse. How long would Google have to react to these requests/demands, when would it be able to refuse to remove a link from a search engine (who decides whether the content on that website was lawfully published or stopped being relevant etc.?), etc?
Tuesday, 8 April 2014
CJEU declares Data Retention Directive invalid (Joined Cases C-293/12 and C-594/12)
With today's decision, the Court of Justice has declared the Data Retention Directive invalid. (see our previous post on the opinion in this case: Challenging the Data Retention Directive...)
The Directive concerned the harmonisation of Member States' legislations as to the storage of data which are generated or processed by providers of publicly available electronic communications services or of public communications networks, to the end of fighting terrorism and other forms of organised crime. In this context, providers must retain traffic and location data as well as related data necessary to identify the subscriber or user.
The Court observed that such large-scale collection and retention of data represents a serious interference with fundamental rights such as the right to private life and respect of personal data. It then sought to ascertain whether such interference was justified in light of the objectives pursued by the Directive.
While acknowledging that the infringement of fundamental rights brought about by the Directive is limited and linked to genuine public interest, "the Court is of the opinion that, by adopting the Data Retention Directive, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality".
First, "the directive covers, in a generalised manner, all individuals, all means of electronic communication and all traffic data without any differentiation, limitation or exception";
Second, it "fails to lay down any objective criterion which would ensure that the competent national authorities have access to the data and can use them" only in relation to the crimes that the directive was meant to prevent/fight;
Third, the data retention period seems to be established without giving any meaningful indication as to how differences could be made among different subjects and different categories of data.
Finally, the Directive doesn't seem to provide sufficient guarantees against abuse and does not "ensure the irreversible destruction of the data at the end of their retention period", and furthermore does not require the data to be kept within Europe, which leaves unclear what authorities will, in fact, have access to the data.
The decision, which is making privacy advocates rather happy, will of course have consequences. Stay tuned for updates!
Saturday, 5 April 2014
Informed consent online
Jennifer Golbeck, director of the Human-Computer Interaction Lab at the University of Maryland, talked at TED about the need to protect our data better online and how this could be achieved. For anyone interested in improved disclosures and privacy issues this is an interesting talk: The curly fry conundrum: Why social media "likes" say more than you might think.
Thursday, 13 March 2014
New EU data protection rules- one step forward
Yesterday, the European Parliament adopted the commission-proposed data protection reform package. While the proposed regulation (with 621 votes in favour, 10 against and 22 abstentions) received overwhelming support, the directive was endorsed with a somewhat divided vote (371 votes in favour, 276 against and 30 abstentions).
This does not make sure that the package will become law, since the
Council will also have to vote and previous debate indicates that this
passage might not be smooth. However, yesterday's vote at least secures a
definite progress in the procedure against the potential delaying
effects of the impending European elections.
While (as the chart shows) the concern of European citizens concerning their privacy is addressed through four key points (right to be forgotten, easier access to own data, "privacy by default"+no implied consent), the package tries to also limit the burden on enterprises, and especially for SMEs, by allowing for a certain degree of flexibility in the bureaucratic management of customer data.
Subscribe to:
Posts (Atom)

