59
THE NEW EUROPEAN PRIVACY LAW THE GENERAL DATA PROTECTION REGULATION AND WHAT’S NEXT Oslo, Norway 14 September 2016

THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

THE NEW EUROPEAN PRIVACY LAW

THE GENERAL DATA PROTECTION REGULATION

AND WHAT’S NEXT

Oslo, Norway

14 September 2016

Page 2: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

CONTEXTWhy a new data protection law?

Page 3: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

April 14, 2016

May 5,2016

...May 25,

2018GDPR formal adoption GDPR publication in OJ 20 days + 24 months

GDPR taking effect

INTRO

Page 4: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

WHY A NEW DATA PROTECTION LAW?

Source: International Telecommunications Union

Internet users

Page 5: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

1995 1998 2002 2004 2007 2008 2009 2012 2013 2016

EU Cookie Directive II (opt-in)

EU GDPR Proposal

EU Data Protection Directive

WHY A NEW DATA PROTECTION LAW?

EU GDPR Adoption

EU Cookie Directive I (opt-out)

Page 6: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

WHAT TO TAKE AWAYThe definition of personal data under the GDPR and the

lawfulness of processing

Page 7: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

SCOPE OF APPLICATION

The definition of personal data under the GDPR

Page 8: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• The GDPR will apply to controllers and processors established within the territory of the European Union.

• Branch, or subsidiary located in the European Union…

• The GDPR will also apply to controllers outside of the EU if they process personal data of data subjects in the EU, e.g. for offering goods and services or for the monitoring of their behavior taking place within the EU.

• Shop or website offering goods or services to the EU… (offered in local language, sells goods in local currency)

• Company engaging in profiling of users within the EU... (OBA)

TERRITORIAL SCOPE

Page 9: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• You are in Europe: The GDPR applies to you.

• You are outside of Europe: The GDPR applies to you if you process Europeans’ data.

TERRITORIAL SCOPE

Page 10: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

anonymousinformation

identifiable

information

identified

information

PERSONAL DATA

NON-PERSONAL DATA

MATERIAL SCOPE

Page 11: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

anonymousinformation

identifiable

information

identified

information

PERSONAL DATA

NON-PERSONAL DATA

PSEUDONYMISED DATA

MATERIAL SCOPE

Page 12: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

anonymousinformation

identifiable

information

identified

information

PERSONAL DATA

NON-PERSONAL DATA

PSEUDONYMISED DATA

PII

MATERIAL SCOPE

Page 13: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Any information (the medium is irrelevant) relating to an identified or identifiable natural person

• Identifiable? Consider the “means reasonably likely to be used” to identify the individual

• taking into account all objective factors, like• the costs of identification• the amount of time required for identification• the available technology at the time of processing• technological developments

• used either by the controller or by another person

• Identification can be direct (name) or indirect (telephone number, combination of significant criteria)

• Singling out is a form of identification

MATERIAL SCOPE: PERSONAL DATA

Page 14: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Born on August 4, 1961

• Born in Honolulu, Hawaii

• Married in 1992

• Two daughters

• Alma mater: Harvard University

• Resides in Washington, D.C.

• Lives in a house built in 1792

• The house is white

• 44th President of the United States

• Barack Obama

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 15: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Unique Combinations

Barack Obama

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 16: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• If an individual can be distinguished from a group, that data is personal data (unique cookie ID)

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 17: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Barack ObamaSHA-1

(Secure Hash Algorithm)

cb8701b4202dbb46fda978884bbc21c0c9

7b538d

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 18: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Barack ObamaSHA-1

(Secure Hash Algorithm)

cb8701b4202dbb46fda978884bbc21c0c9

7b538d

personal data (identified)

personal data (identifiable)

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 19: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

IP 94.225.47.200

ad tech ???

IP 94.225.47.200

internet service provider

Matthias Matthiesen

on Friday, 22 April 2016, 9:15 AM

personal data (identifiable) personal data (identified)

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 20: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• The definition of personal data goes beyond the notion of PII• e.g. pseudonymised data is considered personal data.

• The mode of identification is irrelevant• e.g. singling out (unique cookie ID) without knowing identity is a form of

identification.

• The holder of the means of identification is irrelevant.

• The notion of personal data will expand with technological progress.

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 21: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

anonymousinformation

identifiable

information

identified

information

PERSONAL DATA

NON-PERSONAL DATA

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 22: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

identifiable

information

identified

information

PERSONAL DATA

NON-PERSONAL DATA

MATERIAL SCOPE: EXAMPLES OF PERSONAL DATA

Page 23: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

ALL DATA IS PERSONAL DATA. EVERYWHERE IS

EUROPE.Make no mistake: You are in scope.* Don’t be a fool – prepare!

*very likely

Page 24: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING

The legal justifications that allow processing of personal data

Page 25: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Processing personal data is prohibited…

…unless it is specifically allowed

• because you have the consent of the data subject to process their personal data (opt-in);

• because you have a legitimate interest to process personal data (opt-out)

• and the privacy rights of the data subject are not overriding

• and the data subject has not objected to the processing

LAWFULNESS OF PROCESSING

Page 26: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING

The consent of the data subject

Page 27: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Consent is a statement or clear affirmative action signifying agreement to the processing of personal data.

• freely given

• specific

• informed

• unambiguous

LAWFULNESS OF PROCESSING: CONSENT

Page 28: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Silence or inactivity, e.g. not using a provided opt-out, cannot be consent.

• Consent is presumed not to be freely given when provision of a service is made conditional on consent for unrelated data processing (take it or leave it).

• Consent is presumed not to be freely given when there is a “power imbalance” between the data subject and the controller (government vs individual).

LAWFULNESS OF PROCESSING: CONSENT

Page 29: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Which affirmative actions can convey consent?

• Further browsing?

• Clicking a link?

• Highlighting text?

• Scrolling the website?

LAWFULNESS OF PROCESSING: CONSENT

Page 30: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING: CONSENT

Page 31: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING: CONSENT

Page 32: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING: CONSENT

Page 33: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

PROFILING…and automated decisions

Page 34: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Profiling is automated processing, analyzing, or predicting aperson’s preferences, interests, behavior, etc.

• It must be justified through one of the legal justifications, e.g. consentor the legitimate interests of the controller.

PROFILING

Page 35: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Where an automated decision, including, profiling has legaleffects or similarly significantly affects a user, it is regulatedmore strictly.

• It can only be justified through the explicit consent of the user.

PROFILING

Page 36: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Automated review of credit applications

Automated recruitment practices, e.g. candidate selection through

algorithm

REGULATED PROFILING: EXAMPLES

Page 37: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

Automated review of credit applications,

Automated recruitment practices, e.g. candidate selection through

algorithm

REGULATED PROFILING: EXAMPLES

What about profiling for the purpose of serving interest based advertising?

Does not produce legal effects or similarly significantly affects data subjects.

Page 38: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

FINESWhy should you care to follow these rules?

Page 39: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Breach of the provisions of the GDPR can lead to fines of up to€20 million (kr 185.5 million) or 4% of global annual turnover

FINES

Page 40: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

WRAP UP…and next steps

Page 41: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• The GDPR is broader in its scope (both territorial, and material):more activities will fall under it.

• The GDPR is more restrictive in its legal grounds for processing:Activities are harder to justify.

• The GDPR lacks legal clarity: member states, DPAs and courts willneed to fill in the gaps (if they are permitted).

• As a direct result of the above, the GDPR is a far cry from”harmonization”: gaps will not be filled in the same wayeverywhere.

• It was an uphill battle from the beginning and while the outcomeis not great. The most extreme ideas have not made it in.

WRAP UP

Page 42: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

THANK YOU FOR LISTENING

Questions?

Page 43: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

MATTHIAS MATTHIESENPublic Policy Manager, IAB Europe

[email protected]

GET IN TOUCH

Page 44: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

BONUS

Page 45: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

LAWFULNESS OF PROCESSING

The legitimate interests of the controller or of a third party

Page 46: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

legitimate interests

pursued by the controller

fundamental rights and

interests of the data subject

controllerdata

subject

privacy

reasonable expectations

running a business

direct marketing processingcontroller

no processingdata

subject

LAWFULNESS OF PROCESSING: LEGITIMATE INTERESTS

Page 47: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

legitimate interests

pursued by the controller

fundamental rights and

interests of the data subject

controllerdata

subject

no_processingdata

subject

LAWFULNESS OF PROCESSING: LEGITIMATE INTERESTS

Page 48: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

legitimate interests

pursued by the controller

fundamental rights and

interests of the data subject

controllerdata

subject

processingcontroller

LAWFULNESS OF PROCESSING: LEGITIMATE INTERESTS

Page 49: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Real balancing test, not a mere formality

• Provide information (transparency)

• Provide the right to object (opt-out)

• Unfortunately unavailable for OBA in practice because of the cookie directive

• consent required for storing or accessing any information on a user device• cookies• advertising id• device finger printing• javascript?

LAWFULNESS OF PROCESSING: LEGITIMATE INTERESTS

Page 50: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

EU LAW MAKING 101An intro to decision making procedures – official and unofficial

Page 51: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

CHANGES

CONCILIATION

INFORMAL AGREEMENT

LEGISLATIVE PROCEDURE

Page 52: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

FORMAL PROPOSAL OF INFORMALLY AGREED CHANGES

INSTITUTIONS NEGOTIATE INFORMALLY

INFORMAL AGREEMENT

82% of laws adopted 2009-2014 were agreed in trilogue96% of laws adopted in 2014 were agreed in trilogue

Only 2% of laws negotiated in trilogue fail *

* Source: EBD

TRILOGUES

LEGISLATIVE PROCEDURE

Page 53: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Trilogues sidestep the formal democratic process with little chance for the public to intervene.

• Time between decisions can be as little as a couple of days.

“Bloody Brussels bureaucrats making rules behind closed doors.”

LEGISLATIVE PROCEDURE

Page 54: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Trilogues sidestep the formal democratic process with little chance for the public to intervene.

• Time between decisions can be as little as a couple of days.

“Bloody Brussels bureaucrats making rules behind closed doors.”

LEGISLATIVE PROCEDURE

Page 55: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

THE REVIEW OF THE EPRIVACY DIRECTIVE

Fixing or worsening the cookie law

Page 56: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• The ePrivacy Directive, better known as the “Cookie Directive”• applies to “storing and accessing information on a terminal device”,

which could be everything• cookies, device identifiers, advertising identifiers, fingerprinting, even Javascript?

• Requires that the user grants their consent before storing oraccessing information, making alternative legal bases such, as thelegitimate interest, unavailable.

• Only exception is where the technology is strictly necessary fordelivering the service requested by the user.

• e.g. session cookies for providing shopping basket functionality

REVIEW OF THE ePRIVACY DIRECTIVE

Page 57: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

The European Commission has announced a review of theePrivacy Directive (”cookie law”), to “bring it in line with theGDPR”.

• Chance to deregulate cookies?• some new exceptions…• removing limitation to consent...

• Risk that cookies will be regulated more strictly?

• Risk that other limitations will be imposed on top of the GDPR?• consent could be made even stricter than under the GDPR

REVIEW OF THE ePRIVACY DIRECTIVE

Page 58: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

REVIEW OF THE ePRIVACY DIRECTIVE

Page 59: THE NEW EUROPEAN PRIVACY LAW€¦ · 14/09/2016  · Directive II (opt-in) EU GDPR Proposal EU Data Protection Directive WHY A NEW DATA PROTECTION LAW? EU GDPR Adoption EU Cookie

• Taking away publishers’ freedom to decide on their own business model.

• Obligation to provide subscription-based access to website content.

• Forcing publishers to provide their service for free.• No right to turn a user away that does not agree to seeing advertising.

• And more!

REVIEW OF THE ePRIVACY DIRECTIVE