Category: Technology

Quit-Facebook-WhatsApp-NTIC-2021

WhatsApp forces users sharing data with Facebook: False alarm?

On 4 January 2021, WhatsApp pushed to all its users a notification screen to ACCEPT its updated terms of service (terms of use) and privacy policy (read “privacy notice”). The text displayed on users’ phone is pretty clear: accept to continue using the app or decline and stop using our service. For the time being, users can still say “not now” or continue using the App.

What are the deadlines?

WhatsApp first gave users until 8 February 2021 to decide to continue or quit the App, which was a very tight deadline. The text displayed on the user’s screen mentioned that the new terms would include sharing data with Facebook. As a result, millions of users switched to other so-called more “privacy friendly” apps. Some of them are Signal, Viber, Telegram (US), Olvid (FR) or Threema (CH) among others. After this event and huge users’ reactions, WhatsApp decided to offer a extended deadline until 15 May 2021. This would allow users to take more time to decide to continue or stop using the App.

So, what is this update all about? What are really the changes? Why would users switch or stay with WhatsApp? Are there really any privacy concerns? I will try to provide some response in this blog as a Q&A to make information easily accessible, concise, unambiguous, fair and transparent…Note that I recently moderated a webinar with international experts to discuss the changes to WhatsApp terms of service and privacy policy. Once online, I will share the link at the end of this article.

Cookie-compliance-ntic-advocado

How compliant is your cookie banner? An important German case provides more clarity!

Have you ever heard about dark patterns and deceptive designs in the context of a cookie banner and compliance with the e-Privacy directive? No? Then, this court case might be a good opportunity to learn about it. A court case issued by the Landgericht Rostock (pdf in German) on 15 September 2020, ref. 3 O 762/19 (summary in German and very good analysis in English here), which I will comment in this article.

Cookie compliance is a complex area at the intersection of technology and data privacy. What makes it more complicated in the EU, is that cookie law refers to both the e-Privacy directive (cookie directive) and the GDPR. The fact that the e-Privacy is a directive means that it requires implementation is each EU country. Guidance and interpretation can still differ from each EU country, while all industries are waiting for the e-Privacy Regulation to get finalized. 

_______________________________

THE ADVOCADO CASE EXPLAINS HOW TO DESIGN A COOKIE BANNER

A quite important German Court Case on data privacy and cookie banners (let’s call it “Advocado” case) was recently issued in the field of cookie compliance.  This ruling explains in more details the way cookie banners have to be designed. Maybe we should say: it clarifies how cookie banners should not look like! The German judgement also takes the opportunity to provides some more information about how transparent with users website operators shall treat their joint controllership relationship with third parties. In that context, website operators should take care of informing users about third parties’ plugins appropriately to avoid infringing the law.

In this court case, the German court first confirms where consent is required, which is in particular the case for non-essential cookies. This is not really new since the Planet49 ruling issued by the EU Court of Justice on 1 October 2019. Under Planet49 case law, the ECJ issued a long awaited clarification ruling about essential VS non-essential cookies, although many questions still remained unanswered. Platet49 mainly addressed the following elements (among others):

  • consent is required for all non-essential cookies
  • zero cookie load
  • no pre-ticked boxes are permitted
  • collecting personal data is not relevant for cookie compliance
  • GDPR consent requirements (and fines) apply in the context of cookies (see below summary of recent cases)

With those statements, controllers have to take clear actions for cookie compliance and, where necessary assess their banners, cookie notices, map their practices with third parties and modify them appropriately.

_______________________________

WHAT THE ADVOCADO CASE SAYS

Advocado Gmbh is a company which uses a website to offer an online service that helps people find a lawyer. The cookie banner configured on the website initially provided several pre-ticked boxes. This means that all boxes, including non-essential cookies, were activated by default. During the trial, the company changed its practice to propose an accept all / deny all banner, where the “accept all” banner was highlighted in flashy green and the “deny all” in a light grey. Obviously non-compliant one may say?

What is interesting in this German court case, is that the judgement not only explains that consent is required for non-essential cookies, that zero cookie is necessary or that it should be granular. This should be known by all website operators. It explains in more details how controllers shall design their cookie banners.

The end of dark patterns

The Landgericht Rostock explains how to remain transparent, fair, unambiguous and concise, in the short summary box that controllers / website operators have to display in first cookie banner pop-up. The first text that is displayed in the cookie compliance pop-up is very often used by simply copying and pasting information from other websites. Well, think twice before considering doing this. Especially if you use such cookies to share data, for marketing purposes or to use targeted Ads, this activity is more risky and intrusive. Data Protection Authorities are now very sensitive to every bit of text included in banners, they look at cookies notices, consent management tools and are scanning actively websites for compliance!

The explanations of the court especially bans bad practices that would constitute “dark patterns” to avoid deceptive reactions from users. With dark patterns, a cookie banner is designed is such a way that, although it provides certain degree of choice, it remains misleading by suggesting users to consent to cookies and, thus, influence their choice to a more intrusive activity.

_______________________________

KEY TAKEAWAYS FROM THIS RULING

In this judgment of 15 September 2020, ref. 3 O 762/19, the Federation of German Consumer Organisations (vzbv) filed a complaint against “advocado”, an online service that helps people find a lawyer. The court found that:

1. Using tracking technologies for analysis and marketing purposes requires consent.

Especially, this applies when collecting personal data to share it with third parties.

  • This is interesting to read that Google analytics cookie requires consent. Not explicitly, it suggests, that if Google Analytics does not transmit any personal data to other websites, consent requirement may not apply. The reason is that there may likely not be a risk for the rights and freedoms of data subjects. This is a position that may work in Germany and validated by other data protection authorities, such as in France. This is also the position of the Swiss Commissioner. However, this a concept and a rule that requires further harmonization and clarity. When using analytics cookies, I strongly recommend to read each relevant EU country latest guidance from data protection authorities. For Germany, you may have to read the guidance from each of the 16 German Data Protection Authority. It may provide with stricter rules, including consent for analytics cookies even where no personal data is processed. You should not assume that aggregate analytics is always exempt from cookie compliance and assess on a case-by-case.
2. Cookie banners that have all pre-ticked boxes, even if a user can deselect them and chose “see more”, are unlawful.
3. It is unlawful to use cookie banner using accept all / deny all options, when highlighting the “accept all, and pre-loading cookies.

This requires to apply the following recommendations:

  • Cookie banners and the way controllers have to provide transparency requires to design them in an equal, transparent and fair manner to comply with e-Privacy and the GDPR.
  • Do not copy paste the content of a box from another website without analyzing what your website is actually doing, collecting and placing in terms of cookies. Instead, suggest privacy-default choices (less intrusive choice) and explain clearly what this means for users
  • Do not use colours to highlight what you would like users to click on. Influencing the choice of users would likely constitute a prohibited dark pattern that may be unlawful some EU countries.
  • Clicking on an “Accept All” button should not mean that all cookies have been pre-selected or that non-essential cookies are already loaded.
4. Confirmation that Google Analytics and the Facebook pixel means Joint Controllership (art. 26 GDPR).
5. Failing to provide the essence of the contract with Google and Facebook is against the GDPR.

Joint controllership means that both parties, the website operator have clear obligations together. The controller and the third party are jointly responsible to explain to the user what is the purpose of the processing of personal data, and the “essence of the arrangement” of using such plugin.

According to the Landgericht Rostock, users must receive a copy of the “essence of the arrangement” between the website owner and those third parties. This apply when integrating third-party cookies transmitting personal data. Since third-party providers (also) process personal data for their own purposes the court considered Advocado infringing privacy laws. It failed to comply with its obligation to provide information about the essence of the joint controllership agreement. This obligation applies when integrating the Google Analytics cookie on a website, which is a third partie cookie.

  • This is pretty significant and will be difficult in practice for most small to mid-size website operators to make this effort and do it on their own in compliance with art. 26 of the GDPR.
6. The burden lies with the website operator to demonstrate compliance (burden of the proof)

The website operator has to show that it uses it with a design that complies with data protection laws. This includes third-party plugins, such as Google Analytics or Facebook pixels. Those are important points for the industry to take into account. Also, it is worth noting that,  contrary to what one might think, cookie compliance is not that obvious in Germany in particular from an enforcement perspective. Reading the above commentaries show that Germany may not be the strictest country in this sector. See below more information about recent case law on cookie compliance, the e-Privacy directive and sanctions issued by data protection authorities.

_______________________________

RECENT COURT CASES ON COOKIE COMPLIANCE E-PRIVACY & GDPR

We already commented that authorities warned AdTech industries about compliance on this matter. Not only are they now actively scanning websites, but also enforcing the law. In France, the CNIL issued three fines late 2020 for breach of the e-Privacy directive and the GDPR for unlawful use of cookies.

Amazon.fr fined €35M by the CNIL:

In this case, Amazon violated both the French Data Protection Act and the GDPR (informatique et libertés), which is the implemention the e-Privacy directive, about:

  • poor information in the cookie banner about the use of Ads
  • no real way to object to the cookies, and
  • many cookies were loaded before consent was provided
Google.fr fines up to €100M by the CNIL: Google violated the French law, for:
  • Google used cookies for advertising purposes and placed them automatically on users’ computer, without requesting any action on his or her part
  • lack of information provided to the users of the search engine google.fr
  • partial failure of providing the « opposition » mechanism,
Carrefour.fr fined €3M by the CNIL

This case is not specific to cookies and there are other infringements to the GDPR.

Here, Carrefour placed Google Analytics and other tracking technologies and cookies on its French site Carrefour.fr. The CNIL found that Carrefour did not use Google Analytics exclusively to enable or facilitate electronic communications. This means that Carrefour did not use it strictly necessary for the provision of the service.

In particular, Carrefour used such analytics cookie together with Google Ads to measure the conversion rate of users. Carrefour then pushed Ads with a better auction in order to monetize this activity done by tracking the user’s navigation. It is worth mentioning that the CNIL considered the violation for the use of such cookies and Google Analytics on art. 82 of the French data protection Act, implementing the e-Privacy Directive, but calculated the fines under the GDPR.

_______________________________

CONCLUSION

Cookie law is a complex matter, that has not reached harmonization yet. This ruling and other recent cases in France demonstrate the importance of cookie law. It has become an important and requires due care to protect user’s use of electronic communications. 2021 will be an important year to observe the privacy landscape. In particular, every awaits the enactment of the e-Privacy Regulation to harmonize what has become a difficult area.

I anticipate 2021 and 2022 years of Data Protection Authorities. Also we may see more innovation in the cookies and consent management tools sector. Data Protection Authorities are showing tech giants and Adtech companies that monetizing EU personal data requires compliance. Without such compliance with cookies privacy rules, the use of tracking technologies may not be the best idea.

We are  seeing initiatives to advertise privacy as a marketing advantage, such as Safari blocking cookies by default apple devices. Will this become the next trend? Is this for the good of consumers or for the benefit of large organizations that do not need competitors? What about abuse of dominant positions encouraging to increase certain GAFAM’s monopoly?

Interesting to see how the cookie banner design will influence the use of tracking technologies!

__

By Gabriel Avigdor, CIPP/E

Attorney at law

Specialised in emerging and New Technologies, AI and Privacy

NTIC.ch

Covid-19

Covid-19 mini-series | Legal advice for Switzerland Privacy, Health & Technologies

With Covid-19, the world is facing a huge crisis and the economy will be massively impacted.

New coronavirus, known as “Covid-19“, spreads itself from China (Wuhan province) to Europe, and then to the world leading to unprecedented measures from authorities in various countries, including Switzerland. Public health issues combine health law, protection of personal data & Privacy and the use of new technologies to fight and help during this tough historical time. Remote work and the use of online conferencing tools has flourished and turned from B2B to B2C with down sides of using online tools in an urgency mode without proper diligence.

To support as much as we can on providing useful information, we have started a legal mini-series, including tips and downloadable documents for business and organizations. This series of guidance and materials aim at providing simple and practical information to better understand and tackle legal issues and economic repercussions due to the coronavirus.

Both public and private organisations are suffering. We intend to publish regular posts on our LinkedIn page and our dedicated Covid-19 website on datalex, our new digital legal platform for organizations seeking legal advice and services.

_______________________________

ABOUT OUR MINI LEGAL SERIES 

We are committed to providing legal advice and guidance to individuals and companies in connection with Covid-19.  As usual, this series is bilingual (FR/EN) with some episodes in Italian!  The first episode provides information on the application of the law on epidemics and its federal ordinance. For the other ones, here is the list of our episodes:

Episode 1Federal Act on Epidemics

Episode 2: Telemedicine & Law

Episode 3: Criminal sanctions: what are the risks?

Episode 4: Ethics guidelines: rules for triage of patients in intensive care units

_______________________________

DATA PRIVACY PERSPECTIVE FOR SWITZERLAND / GERMANY / BELGIUM

To provide further legal guidance on technology and data protection to businesses, we regularly participate webinars with law firms around the world that are part of the PrivacyRules network on data privacy matters. We have started with the following webinar in 4 parts, in collaboration with German and Belgian experts for comparative data protection considerations between these three countries.

Part 1What Data Protection Authorities are saying

Part 2Challenges and possible solutions

Part 3Top tips and advice for organizations

Part 4 What may happen post-Covid-19

Note that the episodes of this webinar are in English only.

_______________________________

IMPACT ON THE ECONOMY

While Switzerland’s historic decision to limit events to a maximum of 1,000 people intends to reduce the risk of the virus spreading, it has a major impact on event organisers and other sectors of industry. Employers have to deal with teleworking solutions and implement health and remote work policies and deal with travel and distance restrictions. Employers also need to ensure that they do not interrupt the supply of goods, and have to potentially deal with contract termination or damages for non-performance. This includes, where necessary, to invoke force majeure or reject force majeure arguments from suppliers who are under the impossibility to deliver their services.

The economic repercussions in Switzerland and around the world are enormous. The Watches and Wonders exhibition decied to cancel the event on 27 February 2020. After this, the lucrative Geneva International Motor Show (GIMS), took the same path on 28 February 2020. After this, the famous Cully Jazz Festival had to accounce cancellation of its 2020 Edition on March 10, 2020. The organisers of this festival declared that, except with donation and external financial support and given the considerable losses, this cancellation may jeopardise future editions.

When it came to Italy deciding on 9 March 2020 to quarantine the country, the EU population was in shock, realizing the seriousness of the facts. France decided to limit the events to a maximum of 1000 people. In Spain, the World Mobile Exhibition in Barcelona cancelled the event, which was expecting more than 110k visitors. Such event would generate around 492 million euros in local economic spin-offs, as well as more than 14,000 jobs. The same happened to the Formula 1 Chinese Grand Prix. Originally scheduled for April 19 2020 in Shanghai, they decided to postpone it.

A list of all the episodes in this series can be found on the publications page of this blog or on the dedicated page on datalex.ch.

_______________________________

FEDERAL vs CANTONAL COMPETENCES

On 28 February 2020, the Federal Council decided by means of a federal ordinance to ban large scale events involving more than 1,000 people. This decision resulted from the outbreak of the “Covid-19”. This is a measure that is normally under the responsibility of the cantons. However, in special emergency situations, the government must protect the population against communicable diseases.  In those case, the Swiss Confederation may enact measures by means of a federal ordinance. It has used such power to limit the gathering of people. Furthermore, the Federal Office of Public Health (‘FOPH’) explained, in a press release dated 28 February 2020, the different situations that can arise when dealing with a contagious disease that endangers public health.

(1) In normal situations

The cantons are competent to put in place the necessary measures to protect the population. These consist of quarantine and isolation measures.

(2) In special situations

The Federal Council may encroach on the autonomy of the cantons. This may be the case where: (a) the cantons can no longer exercise their prerogatives or take appropriate measures, should there be a (i) high risk of infection and spread to the population, a (ii) risk to public health or (iii) to the economy. This may also be the case if (b) the World Health Organization (WHO) declares an international health emergency threatening Switzerland.

(3) Extraordinary situations

They arise in the event of an “extraordinary threat to public health“. In such circumstances, the Federal Council may issue federal ordinances without the need for a legal basis in order to take rapid and targeted actions applicable to all Switzerland. The cantons may still have some room to implement them or to issue stricter rules. Pandemic situations may be considered as extraordinary situations, which the Federal Council may invoke to use its overriding powers.

By Gabriel Avigdor | NTIC.ch

street-ads-ntic

Out of Control: a deep dive into the digital advertising and data sharing practices

An expected, but scary report on digital advertising through dating mobile applications run under Google Android OS.

On 14 January 2020, Forbrukerradet, the Norwegian Consumer Council (“NCC”) released on its designated web page a 186 pages study report called “OUT OF CONTROL: How consumers are exploited by the online advertising industry“. Supported by a 93 pages technical report, it explains how the industry of digital advertising (“AdTech” industry) is exploiting personal data of consumers through dating mobile applications to use and monetize such data for their business interest and the ones of “shadow companies”, giving no choice to consumers other than not using the App to avoid profiling and use of their information.

The AdTech players usually conduct tracking and profiling activities, such as behavioral targeted advertising, while sharing and transmitting and communicating electronic information to a wide range of third parties. Nothing new under the sun with this report. Except that the reading provides a lot more clarity about the transmission mechanisms between App providers and third parties active in the advertising industry and real-time bidding (defined below). Some of those mobile application editors use anonymized or aggregate data to conduct segmentation for specific targeted audiences, whereas others just collect personal data “in clear”, without the end-user knowing it, nor agreeing to such practices.

The Norwegian Consumer Council filed three complaints to the Data Protection Authority for breach of the GDPR. And because this report shows that it affects people globally, it is likely that we will hear more actions around the world (even class actions). To read more on the complaints filed against Grindr & Cie, click below:

_______________________________

ICO UK WARNS ADTECH COMPANIES TO EXPECT ENFORCEMENT ACTIONS

In the meanwhile, further to the report, Simon MacDougall, Executive Director for Technology and Innovation at the ICO (UK Information Commissioner’s Office), issued a clear message to the AdTech industry on its blog on 17 January 2020:

“There is a significant lack of transparency due to the nature of the supply chain and the role different actors play. Our June 2019 report identified a range of issues. We are confident that any organisation that has not properly addressed these issues risks operating in breach of data protection law. […]We gave industry six months to work on the points we raised, and offered to continue to engage with stakeholders. If these measures are fully implemented they will result in real improvements to the handling of personal data within the adtech industry. […] We will continue to engage with industry where we think engagement will deliver the most effective outcome for data subjects. […] Those who have ignored the window of opportunity to engage and transform [the ICO gave 6 months from september 2019] must now prepare for the ICO to utilise its wider powers.”

A very good timing for issuing this warning to the industry. In march 2020, once the given 6 month period expires, we should expect further guidance and more enforcement actions if the industry has not convinced the authority to change its doubtful practices.

The ICO UK is one the most active and productive data protection authority in the EU. Together with the CNIL, it issued guidance for this adtech industry, which you can find at the end of this article for more information and references.

_______________________________

UNDERSTANDING THE HARM TO INDIVIDUALS

The study offers a deep dive analysis into the data-sharing practices of AdTech companies communicating via mobile applications. In such cases, unless manufacturers includes built-in easily understandable opt-in consent or opt-out mechanisms associated with clear information about the use of personal data and what it means for them, consumers are unlikely to understand anything of what is going on through the App. This is even more true, when those Apps are used by teenagers or kids.

Out-of-control describes, with examples, how tracking and profiling activities can be used for data-driven persuasion, in particular with the collection of sensitive information. Data-driven models may not only serve dark patterns for commercial purposes aiming at influencing consumers so that they can decide to buy stuff that they initially didn’t want to. According to the report, persuasion based on personal data and profiling may lead to (among others):

  • discrimination
  • harassment
  • manipulation of information and influences of opinions
  • can impair freedom of expression through the “chilling effect” (the effect of not being free to express herself or himself due to the perception of being spied or under surveillance)
  • fraud

which can create other serious harm to individuals if the data goes into the wrong hands. To summarize, when in the wrong hands:

Companies can use tracking and profiling activities for data-driven persuasion, which can lead to serious harm to consumers, whose personal data are collected, including discrimination, fraud, manipulation, same as observed in the Cambridge Analytica’s case.

This is where the real danger is.

Such collection by shadow companies can contribute to the absence of trust about information, opinions, and impair how we all perceive today’s society based on information quickly consumed through information pushed to anyone’s eyes and mind unconsciously storing and memorizing information through data-driven persuasion. Reality becomes the one others want us to believe. According to an Amnesty International report (p. 43 of the out-of-control report), the technology used can dramatically impair fundamental human rights of people and it says:

These capabilities mean there is a high risk that the companies could directly harm the rights to freedom of thought, conscience and religion and freedom of opinion and expression through their use of algorithmic systems.

The study shows that some mobile applications (such as Perfect 365) can even communicate and exchange data with more than 70 external third parties and vendors, including social media platforms, such as Facebook and Twitter, which demonstrates how broad this can be.

Looking at the data flow and the complexity of this ecosystem, it becomes clear that consumers have no more control over their personal data.

_______________________________

EXAMINED MOBILE APPLICATIONS

The study was conducted by the NCC together with 10 other non-profit organizations, including the FRC, the French speaking division of the Swiss Consumer Federation, outlining the width and scope of data-sharing practices through selected mobile applications on Google Android mobile OS operating system. This study focuses on online dating platforms, such as Grindr (subject to 3 formal complaint to the Norwegian data protection authority), OkCupid and Tinder). A lot of information is processed through those applications, including location data, e-mail addresses, and other sensitive personal data such as sexual preferences, health-related information, such as HIV status.

Other mobile applications are included in the study.

For example, it analyses MakeUp Apps (such as Perfect365, based on augmented reality), allowing live photo editing before sharing on social media, Ovulation Calendar & Period Tracker, such as MyDays (which may be considered as a medical device as standalone medical software), Religious Apps, which can be used to receive reminders of events tied to religious matters (Muslim) and Apps for children (My Talking Tom 2) among others. For most of those applications, users have downloaded them million times, with a huge community of consumers, including minors. The study observes how publishers (software editor of the App – see below) share personal data with a range of third parties in the AdTech ecosystem built to monetize personal data.

_______________________________

GETTING INTO MORE DETAILS: PLAYERS OF THE ADTECH INDUSTRY

The online advertising industry uses different ways for marketers to publish their content online.

A company can either pay (alone or through a third party broker) for a space on an internet page or display an add in a mobile App with a fixed price. When a company displays its ad, it will either pay a fixed fee or a variable amount, based on the value of placing an advertisement at a certain period of time (lunch time, night) or to a certain segmented audience (type of audience, territory, etc.). It can decide to place its ads up for the value of the key word. The value of such keyword is constantly evolving based based on an algorithm. For example, such algorithms are used by Google on search engines to display advertisements. The costs can go up to a certain price if it is popular or lower if few people want to search this keyword. After this, online users can see sponsored content (content pushed to the public at a certain place on the website) in relation to the keyword entered into the search engine, where the marketer will pay Google on a per-click basis.

A company can also use real-time bidding (RTB), consisting of an instantaneous online auction. Real-time bidding means that advertising buyers bid on an impression (= number of times a content appears in someone’s feed; A viewer doesn’t have to engage with the post in order for it to count as an impression). If the bid is won, the content of the person buying the ad will instantly display on the publisher’s site, page, network or App. This is one of the standard business models for companies sponsoring their content online.  The ad will display and the marketer shall pay an amount subject to value of the won bid and the allocated budget. See the ICO UK’s guidance for more information or privacy in RTB (link at the end of the article).

The different stakeholders of the AdTech market usually are:

  • Publishers provide information and interactive services to users. The publisher is the editor of the mobile application and offers locations in the App, for advertisers to display their ads. Publishers are paid by the number of clicks on an ads, but often, publishers cannot know which ads will display because as it out of their control.–> App providers (publishers) are data controllers.
  • Marketers are entities that want to acquire and retain valuable customers, find and influence users across the digital world. This can include retailers, grocery stores, consumer goods brands, device makers, car vendors, the travel and hospitality industry, telecom and financial services providers, and many other providers of products and services.–> Marketers involved in the purchase of targeted advertising can be considered joint controllers, even if they do not actually process personal data themselves, as long as they define the means purposes of the processing.
  • Advertising networksanalytics vendors, and data brokers. These other third party vendors is another category that includes a number of actors in the digital marketing and AdTech industry, which is normally hidden from consumers. Unlike publishers and marketers, third party vendors mostly do not have any direct relationships with users.–> Those third party vendors, which are receiving personal data from the apps are either processors, separate controllers, or joint controllers, depending on how and under what terms they use the personal data;
  • Major platforms such as Google and Facebook are involved, for the large part, in the AdTech industry. They offer services and play an important role to either: (a) sell digital advertising based on user data (YouTube as a publisher of ads on video content); or (b) sell sponsored posts on their platforms (Facebook, Twitter, LinkedIn). Those major platforms also act as third party vendors to provide digital advertising services through their other entities and other divisions with other brand names.–> Major platforms can either be data controllers, processors or joint controllers depending on the types of services that they offer.
  • Consumers are the last players of this economy, called data subjects under the GDPR.

_______________________________

WHAT DATA IS SHARED AND WITH WHOM

The technical report is a supporting document for the complaints filed to the Norwegian data protection authority. It shows data flows, where third parties are involved in this massive data-sharing ecosystem. We read what categories of personal data are constantly collected by the publishers and communicated to, or accessible by their, business partners. The parameters analyzed in the technical report include: Advertising ID, IP address, MAC address, GPS location, device information, device configuration, Wifi networks, App name making the requests, account information, and user data, such as age and gender. It can also include e-mail addresses and sensitive personal data.

Android Advertising ID’s example

Out of control report and its supporting technical document underline what identifiers are used to track users information, especially the Android Advertising ID (“AAID”).

The AAID provides a user-specific, unique, resettable ID to be used for advertising and provides linkability, in the sense that it gives advertisers an easy way to connect the dots between multiple apps or multiple sources.

This AAID is embeded is any device. As a so-called “anonymous” ID, it provides advertising companies a unique device identifier for advertising and tracking, which can be used to correlate data from multiple sources (technical report p 12) and services. Although Android smartphones users may reset their Android Advertising ID, the report shows that combined with other unique identifiers, resetting the Android Ads ID may become useless, because third parties will often be able to re-identify users. Finally, the interesting part linking to privacy settings is the following (p. 13):

“There is an option in the Android system settings to opt out of targeted advertising based on the advertising ID, but this mechanism appears to be largely trust-based, as it requires the app developers to actively check for and honour an opt-out, rather than supporting the opt-out natively in the platform. At the same time, end users have no way to evaluate whether a given app is respecting Android’s privacy controls, and may believe that the control is effective even if they are not”.

The conclusion is clear: there is no way for an Android user to have the guarantee from Google’Android that even when deactivating the AAID, other companies will not use the ID to target them with online content!

Wide range of personal data shared with a wide range of third parties

Usually, most of the data that is communicated to third parties, relate to GPS location, names and surnames, contact details, and preferences. However, in other cases, the report shows that very intrusive personal data is collected and shared with third parties, such as questions, where the company shall have no valid purpose to hold such data. Questions asked in the OkCupid App shared the answers with Braze (an marketing agency), included information from:

  • Do you have student debt?
  • Do you prefer hardcore or softcore when it comes to your porn?
  • Are you jewish?
  • How does the idea of being slapped hard in the face during sex make you feel?
  • Is it easy for you to achieve orgasm?
  • Do you enjoy exercise?
  • Generally, do you enjoy being drunk?
  • Is climate change real?
  • Is the US educational system designed to benefit the rich?
  • Would you ever date someone that is hiv positive?

Such data is extremely sensitive and can lead to a serious harm for persons whose personal data may come in the wrong hands. In another scandal arose in 2018, where Grindr was found to share HIV status data with 2 other Apps being Apptimize and Localytics (p. 23 of the technical report).

_______________________________

INTRUSIVE AND NON-INTRUSIVE BUSINESS MODELS 

Although some sectors are regulated and prohibit publicity to protect consumers (doctors, alcool, tobacco, pharma and other sectors), advertising companies can conduct their business legally to the extent they follow relevant legislation, including at least: data privacy and consumer protection rules. In this regard, data protection laws (including ePrivacy Directive) and consumer protection laws mean the laws of each country, where users are residing (except that the GDPR applies everywhere, when in-scope), which can become a challenge to implement. In the AdTech sector, given the intrusiveness of the processing activity, Codes of conducts (IAB codes of conduct) and principles of ethics are emerging (see the Principles and practices for advertising ethics). Although those texts are not considered as law, they help companies using advertising practices that are fair and ethical. This is a growing area that any company, not only the AdTech sector, should have a look at to embed those principles in their culture. In a world, where data collection and sharing practices are commonly performed without transparency, ethics can help build trust of consumers again.

An interesting part of the study explains that several business models are available, which can involve or not the processing of personal data of consumers using an App. In reality, the more personal the profile is, the more companies can accurately target users, with content that may interest them. And there is still a large number of companies operating in the shadow of users taking advantage of the data business tracking and profiling  with debatable legitimate purpose to hold such information (report p. 5 and 45).

The consequences for a company to use personal data or not are massive. Let’s use an example for the use of personal data:

Does a third party, used by the data controller to backup information on hosting servers, really need to access political views, sexual preferences and orientations or religious believes? Using a subcontractor to store personal data on its server is perfectly okay, even if it leaves the EU. The cloud vendor should however, as data processor (subcontractor), follow all instructions of the data controller and comply at least with all art. 28 (data processing agreement) and art. 32 (appropriate security measures in place) requirements of the GDPR. If this backup company uses personal data for its own purpose, and let’s say it will make profit from it, this cloud provider becomes a data controller – i.e: responsible for handling personal data – and will have to comply all data protection laws, including the all GDPR requirements.

This means that any third party holding personal data of consumers through the App, deciding about what to do with the data (“for its own purpose”), such as making money of it, should inform the user about the processing, explaining why it holds the data, base such processing activity on a valid legal justification, such as consent or a legitimate interest, and comply with all other obligations under data privacy laws.

This is unlikely to be the case for shadow companies using personal data that is not anonymized, in order to take their own decisions.

Alternative business models vs the sad reality

The reports reminds that companies can use non-intrusive business models to conduct advertising on mobile applications.

This is the case for Subscription services. Subscription-based models, often used by online media and newspapers, require users to pay for the work done by journalists. Also, donation – which is the Wikipedia and TheGuardian business models, can also work. As opposed to behavioral targeted advertising, which requires to create user profiles, companies can chose contextual advertising as business model, where targeting ads can be based on the content that the consumer is looking at, rather than on the profile of the consumer her- or himself.

The problem for players of the AdTech industry, is that using less intrusive technologies may lead to a “race to the bottom” with the side-effect of “depressing the value of data, which may fuel further extensive sharing of personal data, leading to market inefficiencies from a competition point of view” (p. 53 and 54 of the report).

In practice of mobile Apps and social networks, sharing personal data is often the counterpart of using the free version of an App. In the mobile gaming industry, the use of a free game almost always includes other ways to monetize the App: just think about Candy Crush. It can include: (a) forcing the user to watch a video, (b) to share with friends the results of a game; or (c) share its personal data with third parties, or (d) offer direct purchase of items, which will make you progress in your game journey. A free version of an App usually forces the consumer to give something in return to its free use, therefore making this App not really “free” anymore. Many initiatives are emerging to monetize personal data, but in a transparent manner. In the case of companies doing market researches or surveys, the publishers remunerates consumers in exchanges of answers to certain questions. It can also be based on the physical performance displayed in the App owned by a insurance provider which the consumer is already a client of.

Often, even with paid Apps, subscription-based models or other less intrusive business models still use tracking and profiling activities of users. Those practices are very often done without the knowledge of the users; with very low transparency and consent-based mechanism to the users.

_______________________________

FREE VS PAID: REASONABLE EXPECTATIONS OR DATA HOLD-UP?

Should the out-of-control report be a surprise to the general public? Absolutely not! The subject is not new and those business models are already dated. However, the technology is evolving and with machine learning and other more clever algorithms, it will become less easy to understand the consequences for one’s privacy when using an online service through a mobile application.

Consumers can expect ads in free or even paid versions.

Users of mobile Apps, in particular social networks, should expect a difference in the business models between free and paid Apps. To run mobile applications consisting in any kind of social networks, it requires a connection. Thus, by design, it is not possible to use a social network without opening your phone to the external world, for games this might be different, but the publisher will often deny the game if the internet connection is not active. Now, when a user decides to use a free version, compared to a paid version, users can assume and expect that, with no money, the App will not be maintained or will just disappear from the market and App stores. Remember old times when using video games decades ago; a one-off payment would allow anyone to own the game and play ad eternam without any connection.

When we think of the current business models, Facebook is the best example of the next generation business models. According to a study, Facebook’s revenues in 2018 were almost only based on advertising (98%). This means how lucrative it is when the publisher offers a platform with millions of consumers, earning money with a pay-per-click model. In the case of Grindr, the App has been downloaded more than 100 million times. In this sense, consumers can expect to see ads when using free versions of a platform or a service, because this model has become mainstream. Compared to premium, subscription-based or paid versions, free versions almost always use advertisements. Advertising business models can be based on personal data or not, but it almost always requires a connection to the Internet or the transmission of information via the App.

Learning from the cookie wall debate?

The next question is: does consumer has to accept to be targeted with ads to use a free (or even paid) service? The answer is not  clear from a legal point of view.

Although this is a different situation, one may compare free Apps and choice, to the cookies and tracking technologies’ discussion in the EU (i.e:  article 5(3) of the ePrivacy Directive). As a reminder, the cookie wall debate relate to granting or denying access to an internet user depending whether she or he decides to accept to place cookies on its device or not. If the user says yes, which allows online tracking and potentially creating profiles, users can pass the wall and access the site. If the user says no, I don’t want to be tracked on your site, then the user cannot access the website. In my opinion, the situation is similar with free mobile Apps and social networks.

The cookie wall debate is still on and a court has not judged yet, whether a website can ban users if they don’t agree to be tracked. In the context of cookies at least, we know now that, further to most data protection authority’s recent guidance and approach (CNIL and ICO UK), there is no exception to consent, other than when the tracking technology is necessary for the performance of the services. Therefore, consent is almost always required. Cookies are regulated by the ePrivacy Directive principles, but consent and transparency obligations rules have to follow the GDPR (as seen in the recent CJUE Planet49 case).

The out-of-control report explains that Grindr and its third parties, go far beyond such practices. It involves tracking, profiling and transmission of sensitive personal data to external companies that may not have any valid ground to hold the data and do not inform individuals properly. Also there is almost not valid legal justification as consent and explicit consent are not properly included in the App.

When a user knows in advance what company is going to do what, with what data, and if the user can easily choose what to do and decide to continue to use the service or not, this could be fine (subject to the view that a cookie wall may not be lawful). This could be fine if you follow the argument of pro cookie walls, who argue that nobody is forced to use an App or a service. It is always possible to choose to use another one if the user is not happy. This apply as long as the choice for the user to leave the website or the App comes before the cookie is placed on the device. On the contrary, people not supporting the cookie wall concept, claim that such mechanism does not give the user a real choice, because it should be possible to use the service without detriment to the user and allow them to use read the content by refusing the placement of cookies as a counterpart of entering the website.

Although both arguments are arguable and valid, banning cookie walls means that it requires to find other ways to monetize the use of online services, especially in an data-driven economy.

In any case, if a user has no information and no choice, and uses a service that collects such amount of data, sharing with them with so many other companies, this is not just unethical anymore, it constitutes a sneaky and severe violation of someone’s privacy.

_______________________________

COMPLAINTS TO AUTHORITIES: NORWAY VS SWITZERLAND APPROACH

NORWAY – A GDPR COUNTRY

Norway is a GDPR country. As an EU country, it has implemented a sanction mechanism based on Regulation 2016/679, better known as the GDPR. This action includes appointing a data protection authority capable of taking enforcement actions for violations of data protection laws, which is the case of all EU countries. The fines can go up to 2% or 4% of the annual worldwide turnover for private companies. As a reminder, the GDPR applies regardless of the location of the data controller, if it uses personal data of individuals located in the EU. The controller is the company deciding about the purpose and the means for the processing of personal data. In this sense, the GDPR is very powerful to most companies (compared to tech giants that can easily survive to fines) because companies cannot exit the EU to escape the application of this law. Also, due to its sanction mechanisms, it can be used as a preventive and dissuasive tool.

The NCC filed 3 complaints to the Norwegian Data Protection Agency against Grindr and companies accessing personal data of consumers through the App. The content of the 3 complaints is very similar to each other. The main focus is on the absence of valid consent as the legal justification to use the data. It also mentions the Dominant Market Position of Grindr. This is interesting, because we start to see an interplay between privacy and anti-trust laws, where data controllers may abuse from their dominant positions.

In this article, I previously discussed Google’s €50M fine by the CNIL. I also analyzed the first GDPR enforcement cases to understand the level of fines under this EU data privacy law, where in this other article, I compared the legal regime in force before the GDPR, mentionning Equifax and Cambridge Analytica’s cases.

SWITZERLAND – A NON GDPR COUNTRY

The situation is slightly different in Switzerland.

The Swiss French speaking division of the Consumer Federation (FRC) also requested the Swiss Federal Data Protection Commissioner (Swiss Commissioner) to take further actions. This request will be very limited given the Swiss Commissioner can only issue non-binding recommendation, go in front of the federal administrative court to have a conceptual judgement. As such, the there is still no direct enforcement, nor sanction power for the Commissioner.  Therefore the Swiss complaint will lead to a statement or recommendation, under the means available under the Swiss Data Protection Act.

Further to a massive data breach to Swisscom, I commented (in French) the weakness of the Swiss Data Protection Act (“Swiss DPA”) in terms of enforcement. Although Switzerland benefits from an adequacy decision from the EU Commission and its law is comprehensive and solid, it lacks from enforcement and direct sanction mechanism compared to EU legislation to dissuade bad players exploiting data with no further consequences. Currently, the Swiss DPA only allows someone to initiate a criminal trial with a maximum criminal fine of CHF 10K. The currently revised text of the Swiss DPA will not grant anymore sanction powers for the Commissioner in case of infringement of the Swiss Federal Data Protection Act, but will increase the individual responsibility criminal offences up to CHF 250K.

Data protection is a balance between the fundamental rights of individuals against the rights of others to use such information for their own purpose.

Swiss politicians have chosen their side. To date, the legislator clearly gives more importance to the rights of companies to process personal data instead of protecting the fundamental rights and freedoms of Swiss citizen. AS a result, claiming more control in Switzerland, will always remain weak if companies decides not to apply privacy rules to Swiss citizen so that they can claim more control over their personal data. This remains a political choice.

_______________________________

TOP 5 PRIVACY RECOMMENDATIONS FOR THE ADTECH INDUSTRY

The following recommendations can apply to Adtech players, including manufacturers of mobile applications, but also to other industries.

1. DETERMINE YOUR ROLE

You should first understand whether your company acts as data controller, data processor or as joint controller. Your role is based on each processing activity. This first step is absolutely key and will determine the level of responsibility of your company and regulate how to act with your business partners, especially fulfilling other compliance obligations, having the right contracts in place (art. 28 GDPR), limiting your liability and indemnity obligations, and determine the roles and responsibilities of your counterparts for the processing of personal data in each situation.

2. KNOW WHAT DATA YOU HOLD, WHY AND WITH WHOM YOU SHARE IT

WHAT. Consumer data (B2C) requires the same care as B2B information. However, when is comes to involve children’s privacy or with sensitive data, it requires due care. On social networks, is will very often if not always involve sensitive personal data. Except where other rules may apply, such as consumer protection, age verification and authorization from parents may be of importance. When you determine what information your company collects, you can then apply data minimization principle (don’t collect more than what you need for what you want to achieve = only collect what is strictly necessary). Once you know the categories of data you have about whom, you can apply the appropriate security measures, assessing the risk associated to such data in case you suffer a breach, and data minimisation.

WHY. You need a purpose to process personal data and inform people about it. If you just collect personal data to hold it, sell it or for a future use, this might be against the GDPR and generally a lot of other data privacy laws around the world. The purpose needs to be explained to the data subjects (users/consumers) though privacy notices for each processing activities and with the right justifications and for each purpose.

WITH WHOM. Ensure you have all appropriate safeguards and legal mechanisms to share personal data with others, including knowing if the other party acts as your data processor or another controller. Collecting and sharing data with other vendors is part of the connected world. Nowadays, data and personal data are transferred to many third parties, including to countries with less data protection standard as in the EU or Switzerland, such as India or the USA. When transferring data that is personal, your company must ensure to have the right to pass it to third parties If you have to rely on consent, you cannot pass and transfer the consent to your third party if the third party becomes a controller. In this case, the other party will have to inform consumers and collect the consent or explicit consent. If not, any such practice will infringe data privacy laws.

3. USE THE RIGHT LEGAL BASIS AND COMPLY WITH IT

Still check whether you can rely on any exemption or exception to consent under art. 6 GDPR (among the 6 other legal bases) and/or under art. 9 GDPR (explicit consent if you hold sensitive personal data). The ICO UK stated in June 2019 that, in the case of marketers, it is unlikely that another legal basis than consent can be used. Also, tracking technologies are subject to the ePrivacy Directive, which now is clear to require consent each time the placement of a tracking technology on a device is not necessary for the performance of the service. The ICO states for sensitive data: “market participants must modify existing consent mechanisms to collect explicit consent, or they should not process this data at all” (guidance June 2019 p. 16). Therefore, you’d better use the appropriate consent mechanism (not bundled, freely-given, informed, unambiguous, etc.) if you do not want to hear from authorities or data subjects lodging a complaint.

4. USE TRANSPARENT PRACTICES TO BUILD TRUST

Privacy notices, not only support consent compliance, but allows to inform people about what exactly you hold about them. It explains what you will do with the data, how you protect it and with whom you share it (among others). Adtech companies operating as data controllers, need to find creative ways to draft (concisely, clearly, etc.) and display their privacy notices in a easily understandable way which will not discourage the user from reading, nor understanding, nor … using the App! Hiring pragmatic, business-oriented and creative privacy lawyers might be worth the price, as privacy on mobile applications is more difficult to achieve given the smaller screen of the devices. Demonstrating a valid consent is still, and will remain, a challenge.

5. APPLY PRIVACY BY DESIGN AND BY DEFAULT 

The architecture and the data flows in mobile applications and social networks can become extremely complex. Building and maintaining software, taking into account data lifecycle (data retention and data minimization) with built-in opt-in consent, privacy notices, appropriate security measures, features and technology to give the control to users and always apply the less intrusive parameter (turned off if not strictly necessary) to start using the service.

AND … FOLLOW INDUSTRY-SPECIFIC GUIDANCE (IBA, ISBA, ICO UK), DON’T FORGET EPRIVACY AND THINK ABOUT DATA ETHICS!

Future will tell if privacy laws will influence business models in the field of digital advertising…

To go further with authorities guidance:

By Gabriel Avigdor | NTIC.ch | datalex.ch | penalex.ch

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine

Google fined €50M by the CNIL under the GDPR

This 21 January 2019, the French data protection supervisory authority (Commission Nationale de l’Informatique et des Libertés – the “CNIL“) fined Google LLC 50 million Euros for breach of the General Data Protection Regulation (the “GDPR“).

In today’s communication (in French), the French authority issued the highest fine against Google LLC since 25 May 2018 considering severe infringements of the GDPR by Google for failing to inform properly the users and collecting valid consent for targeted advertising services.

SCOPE OF THIS DECISION. It is worth noting that this decision is solely based on investigations of the CNIL related to configuration of new Android device for the first time by a user. This particular infringement of the GDPR only relates to the privacy notice displayed to users when they create an account and when logging into their new Android phone. However, the full complaint has not yet been examined by the CNIL and goes far beyond that. The complete case is much broader and related to targeted advertising on Youtube, Gmail and Google Search platforms. The CNIL will have to examine how Google may have or not “forced” users to consent to sharing their personal data via Google targeted ads services. So we can expect to hear more from the CNIL in the upcoming months in this case. This is probably only the beginning of a long series for 2019. The two organizations also filed (as explained below) similar complaints against other GAFAM in several jurisdictions.

________________________________

FINDINGS OF THE CNIL

The CNIL considered that Google did not comply with the GDPR for three main reasons: (1) lack of transparency (art. 5 GDPR); (2) insufficient information (art. 12 and 13 GDPR); and (3) invalid consent collection (art. 7 GDPR).  The two complaints were brought by Max Schrems’ non-profit organization called “None Of Your Business” (NOYB) and the association La Quadrature du Net, a French association that regrouped complaints from 9’974 individuals. Those two organizations claimed that Google’ services, including the targeted advertising services on Android OS, did not comply with its obligation to process personal data with the proper legal basis (art. 6 GDPR), forcing users to share massive amount of personal data and therefore compromising their privacy without their consent.

Those complaints have just been confirmed by the CNIL in today’s findings. After that, it is interesting to read on the blog of NOYB, that Google will move its EU headquarters to Ireland with effect to 22 January 2019, with the Irish DPA (Data Protection Authority) as the lead authority.

The French authority adds some interesting considerations to its findings. The CNIL explains that with Google current services, due to the way the data are collected, the volume that can be processed and the type of data collected through those services, it can result in revealing entire parts of someone’s life, which becomes very intrusive. The CNIL also considered the fact that Google’s business model is partially based on those intrusive services.

Finally, the CNIL explains that, essentially, despite Google’s efforts to change its processes, Google is still not compliant. This also means that as long as Google remains non compliant, it may face other complaints and, potentially other fines unless the way Google processes data about individuals changes drastically.

________________________________

HISTORY OF THE CASE

Two massive complaints on 25 and 28 May 2018 for € 7,6 bn

25 May 2018. Max Schrems – the Austrian privacy advocate who provoked the cancellation of the Safe Harbor framework by the European Court of Justice (see judgement here) – founded a not profit organization called “None Of Your Business” (NOYB) to support consumers and data subjects in filing complaints against companies and to authorities to enforce and protect their privacy. Just the day the GDPR became enforceable on 25 May 2018,  Max Schrems sued Instagram (Belgium), WhatsApp (Hamburg, Facebook (Austria) and Android (France) with a massive complaint amounting to € 7,6 bn via its NGO for infringement of the GDPR. Find more details on NOYB’s website here.

28 May 2018. The French Digital Rights Group “La Quadrature du Net” lodged a complaint on 28 May 2018 against Google, Apple, Facebook, Amazon and LinkedIn in front of the CNIL on the behalf of 12,000 individuals for illegal processing of personal data.

The CNIL’s sanction of € 50 millions issued today is only one sanction against one company – Google LLC – and in one juridiction. There is most likely other sanctions to come if other authorities follow the CNIL’s argumentations and considerations.

In terms of procedure, Google can appeal to this sanction and contest the fine (edit 24-janv-2019), which the company announced publicly. Even if the fine remains low compared to the €4bn it can incur in the event of a maximum fine, the amount is high for this case. In its public statement, Google said:

We´ve worked hard to create a GDPR consent process for personalised ads that is as transparent and straightforward as possible, based on regulatory guidance and user experience testing

By appealing against this decision, Google wants initiates the process of a precedent in interpreting the GDPR’s requirements on information, transparency and how to validly obtain consent, particularly in the area of targeted advertising.

Google’s appeal is therefore highly strategic. Not contesting this fine would create room for potential more severe sanctions, especially as the scope of the case is limited. In addition, it could be seen as an indirect acknowledgment of responsibility for using non-compliant practices.

Finally, Google defends itself by arguing that it has worked hard to set up data collection in order to respect transparency, but also said:

We´re also concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond

We will see if his work has been sufficient or not and how strong this EU Regulation can effectively be in practice.

________________________________

THE CASE IN MORE DETAILS

To get into more details, the CNIL provides the following explanations to justify the sanction against Google:

  • Breach of transparency: the transparency principle refers to how you inform individuals about the processing activities. This usually takes the form of privacy notices. This information is supposed to remain concise, clear, accessible, unambiguous and intelligible by any person.

This was not really the case. Google spread all that information in many separate places through links and buttons which made it very difficult to access, understand and takes ages. At the end, all that information was only accessible after 5 or 6 actions, in any case after several steps to know what data are collected about the individual. The information was not clear enough, vague and described in a too generic way. That means that if nobody takes the time to read that information (why would Google collect your data for what purpose, for how long, what categories of data are used for the targeted advertising, etc.), the obligation of having a clear and easily accessible notice is not achieved. Also, Google failed to inform about the retention period of certain personal data (for how long will Google keep that data).

  • Invalid consent: Google requested the consent of the users to collect the personal data. However, the CNIL considered that this legal basis was not valid for the options of customized advertising for the two following main reasons:

The consent was not informed. This means that users do not understand the scope of use of the data. For example, in the “customized publicity” section, it is not possible to see how many services, sites and applications are related to the processing and there is no information about the volume of personal data that those services will process and combine.

The consent was not specific, nor unambiguous despite the fact that users may have the ability to select several parameters. According to article 7 of the GDPR:

request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

With Google targeted advertising services and options, the users could only access those parameters by clicking “more options”. Also, the option to use “targeted advertising” was already pre-ticked, which forces the user to turn it off. So the option will remain active, if the user does nothing, unless there is an active action from the user to disable the option. Therefore, using pre-ticked boxes is contrary to the principle of privacy by default (art. 25 GDPR), which requires to turn off any settings or parameters by default to apply a maximum protection of privacy to the user. It is only up to the user to decide whether he or she wishes to increase the level of intrusiveness to his or her privacy and agree to share any personal data. Finally, Google only provided one box for the users to click which appeared like this:

“I accept Google’s terms and conditions” and “I accept that my data are used as described above and as detailed in the privacy policy”

Such bundled consent, which is not specific and do not provide any details for each purpose is not compliant with the requirements as set out in the GDPR.  Where several purposes for processing personal data exist, users must have the ability to only consent to those purposes that they wish. Having all the purposes all-in-one, does not work under the GDPR.

________________________________

ARE THOSE REQUIREMENTS NEW UNDER THE GDPR?

Yes and no.

Yes, the requirements to collect a valid consent has been extensively strengthened. It not as easy as before to collect a valid consent and as this case demonstrates, there are individuals and authorities out there that can have a word and ultimately impose fines to your organization.

No,  the principles of consent, collecting personal data with a valid legal basis and informing the individuals via privacy notice, are not new from an EU data protection legislation. The obligation to process personal data with a lawful ground already existed under Directive 95/46/EC and also applies under the Swiss Federal Data Protection Act (DPA), as probably in most of the jurisdiction that have adopted comprehensive data protection framework. A company responsible for collecting and processing personal data has to justify a valid legal reason. As a reminder, the GDPR offers 6 different legal bases to justify the processing of personal data (article 6 GDPR), which are:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protect the vital interests of natural persons;
  • performance of a task carried out in the public interest or in the exercise of official authority; and
  • legitimate interest.

Each of those legal bases have their pros and cons, but where you use the consent, you should remain careful to collect it lawfully, unless the processing becomes illegal. With the GDPR, the consent has become much more difficult to obtain. In particular, you need to inform and explain who shall consent, what you will do with that data, for what reasons and based on what legal basis you process the data, with whom you will share them. And this shall apply for each purpose. If those conditions are not, the consent is not valid illicit and you cannot process the personal data.

And this is what happened to Google LLC in the case of targeted advertising, for this first part of the story.

________________________________

By Gabriel Avigdor | ICT.ch 

Digital Lawyer

Conference on telemedicine

On 4 October 2018, I was invited by Planète santé to speak at the assises de la médecine romande on the topic of telemedicine. The title of my conference was:

Telemedicine : legal framework for physicians

The Swiss health forum 2018, including the “assises de la médecine romande”, is global conference and Forum where more thatn 1’000 healthcare professionals and doctors meet and participate during a few days. This forum held a practical conference on the ‘digitalisation of the medical profession‘. I had the pleasure to speak along with Dr Jean-Gabriel Jeannot and other healthcare experts, including lawyers and physicians on digital in the context of healthcare.

Dr Jean-Gabriel Jeannot and I had the pleasure to develop thoughts and highlights challenges with this specialized audience in the context of telemedicine. For those who do not know him, Dr Jeannot is a Swiss physician specialized in internal medicine known for his digital initiatives to medical care, his numerous websites Medicalinfo, Medplus.ch, cabinetmedical.ch and his large amount of articles on his blog hosted by the local newspaper “Le Temps”. He spoke about the practical aspects of telemedicine for physicians, while I tackled the legal part of the topic. I mainly oriented my presentation for global awareness to healthcare professionals and doctors about legal issues which they may not find obvious, while offering practical recommendations.

_____________________

ISSUES RAISED BY TELEMEDICINE

Telemedicine is a wide topic.

Physicians and healthcare professionals have issued a few guidelines. Just to name a few, in the US, the American Telemedicine Association (ATA) and, in Europe, the Standing Committee of European Doctors (CPME) have created a useful documents, containing best practices for telemedicine services and remote healthcare.

Those guidelines are a first step to understand what a telemedicine project requires as a minimum. But a telemedicine project or initiative, may remain very simple (such as online or telephone medical consultations) or become extremely complex. Healthcare remains a heavily regulated environment, where laws are different in each country, with different practices and particularities, especially for cross-border projects. Moreover, there are many other aspects to take into consideration, such as from a regulatory perspective. Other issues relates to how securing contracts with third parties and partners in distant healthcare, how to tackle protection of health data and personal data under local laws, including the GDPR, as well as liability issues and how insurer can recognize distance medical services and reimburse them to  patient and pay doctors.

Structure of my conference

The main points of my talk related to three main pillars:

(1) Acts of telemedicine

The first part consisted in presenting the different acts of telemedicine that healthcare professionals my do. For each act, I have explained the typical contract that needs to be in place, highlighting the problem what issues may arise in each different scenario. A physician may provide four types or acts of telemedicine :

  • teleconsultations, which relate to the distant telephone or videoconferencing to provide a medical evaluation, including e-prescribing;
  • teleexpertise, where one physician instruct another physician that is answering remotely as an expert;
  • teleassistance, which applies in the event a doctor is unable to examine a patient on the site (emergency, distance, etc.) and a third person that is not a doctor assists the patient while communicating with the remote doctor based on his instructions; and
  • telesurveillance, which may involves remote biomonitoring of vital functions of the body, where a doctor is not present, or because there is no need for medical examination directly on the patient.

(2) Legal framework for physicians

The second part of my presentation was about the legal issues of telemedicine for doctors. It consisted in answering to a few questions, such as:

  • does telemedicine require a particular legal framework and how law applies to it?
  • who can practice telemedicine?
  • how to manage protection of health data?
  • telemedicine  and liability: how to minimize the risks?
  • how does the social insurance reimbursement work for telemedicine services?

(3) Recommendations

Finally, the last part had a main goal to provide practical guidelines and checklist for doctors and healthcare professionals, including insurance companies and innovators (start-ups and hospitals).

_____________________

TELEMEDICINE IS NOT A NEW METHOD, BUT A GROWING MARKET

A bit of history. It is not obvious to realize that the practice of medical services remotely is pretty ancient. The system of emergency medical hotline that associations of doctors have set up is a proof of it, as has been working for decades.

We can already find acts of telemedicine provided at the early 20th century.  Since the telephone invention in the late 19th, and television in early 20th century, doctors have provided medical services through different means, such as telephone (ECG and EEG), videoconferences in the context of psychiatry, virtual reality and with more modern tools after the invention of TCP/IP, etc. Four days before 9/11, the famous remote “Lindberg” surgery was a success, which demonstrated that technology could bring promising solutions remotely even to perform extremely sensitive acts of medicine.

In Switzerland, two main centers of telemedicine are in place since early 21st century, created by, and based on the model of, insurance companies such as Medgate and Medi24. These 2 providers mainly offer acts of teleconsultation (medical telephone calls). Other insurer now propose remote medical services, such the software myguide that the CSS insurance company provides to its clients.

Private initiatives, such as “heal-me” ” (“soignez-moi” in French) offer non-synchronized models (compared to synchronized). This online telemedicine platform allow patient to only pay CHF 39.- per consultation, with a assurance to receive a call from a doctor with a timeframe of 60 minutes. If the response takes longer, the medical consultation becomes free of charge, which becomes an incentive for the platform to ensure performance and availability for patients.

With respect to private clinics, the Aevis Victoria Group has massively invested telemedicine with acquisition of 40% of the share in MedGate, the Swiss leader in telemedicine. The Group also increased its participation in “LifeWatch AG” with an IPO in 2017. THis company is specialized in developing tools and devices for distant medicine. The Aevis Victoria Group continues to invest in other institutions or projects in the area.

_____________________

NOW WHAT?

Potential, but a probable slow growth. With such investments, and the potential of telemedicine, this market is likely to grow and complement ordinary medical care. One thing is sure, telemedicine will never replace ordinary physical examinations on patients. But it appears that physicians remain careful with distant medicine, probably for liability matters, or not knowing that most remote medical acts can be reimbursed by social insurances, by not using electronic communications, such as e-mail or text messages, or simply because they do not have the time or the need to change the way the provide healthcare to patient.

There are many ongoing initiatives, but as we saw, regulatory, legal, political barriers and reluctance from doctors. So this market remains full of potential, but is likely to grow slowly before becoming more in the daily practice and complement traditional care.

Some elements to consider. Patients use more electronic communication means. They have few time to go and visit the doctor. Nowadays, it is common that both parents work and struggle to organize to find medical appointments either for themselves or for their kids. They also prefer not to go to the doctor unless it becomes urgent. Sometimes, they even perform medical care on themselves. Now patients change their doctor more easily, or even have not a general physician: therefore telemedicine has all potential to match with a true market.

Now the players arriving with new ideas on the market will have to demonstrate that it is worth it from an economical and quality standpoint, while being able to reduce the costs of healthcare.

But maybe, digital medical office are not so far to come on the market…

To know more:

___________________________________________

You are launching a project in the context of digital health or distant healthcare? If you have questions or want to meet, go and check out our platform and schedule a meeting with us on datalex.

___________________________________________