7 ms·
Recital 43 is a fair objection -- I should rephrase what I said in light of it. I should have said: > "The GDPR requires many things, but there's nothing in th
by methodover 8y ago
Recital 43 is a fair objection -- I should rephrase what I said in light of it. I should have said:
> "The GDPR requires many things, but there's nothing in there that says you can't reject the customer if they don't opt-in to the things you need them to opt-in to in order to provide the service."
The last sentence of recital 43 says that consent can only be given to those personal data processing operations that are necessary for the performance of a contract/provision of the service.
In Google and Facebook's case, collection of personal data for the purpose of targeted ads is necessary for the service because targeted ads provides the source of revenue for the service's operation.
- taysic 8y agoThis is not the interpretation I've seen everywhere. GDPR says 'accordingly, consent will not be considered to be free if the data subject is unable to refuse or withdraw his or her consent without detriment.' The user needs to be able to use the service in the way they expect to, without needing to give their personal data for targeted advertising. Another way of putting it is personal data can no longer be used to pay for a service.
- azernik 8y agoYour business model's success is not "providing the service". EDIT: Quoth the British agency responsible for implementation: "The processing must be necessary to deliver your side of the contract with this particular person. If the processing is only necessary to maintain your business model more generally, this lawful basis will not apply and you should consider another lawful basis, such as legitimate interests." https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/contract/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- methodover 8y agoThank you for the citation; this is an interesting and useful discussion. The contract that Facebook has with its users is not merely to serve as their social media platform. The contract includes personalized advertising. Facebook, in the terms of their contract with you, give you X in exchange for Y. X is the social media platform. Y is personalized advertising. This is the contract. AFAICT from the GDPR, they don't specify boundaries for the terms of the contract itself, do they? The ICO talks at length about what it means for processing to be "necessary" for the purpose of fulfilling a contract. But it doesn't state what the boundaries are as far as what constitute legitimate contracts. For example, this would be a valid contract under the GDPR, AFAICT: I offer to make you free sandwiches in exchange for you telling me some personal information about you and targeting you with advertisements while you're my sandwich shop or elsewhere; and I provide you an ability to revoke this contract at any time (and whereupon I will delete the data I've collected). Of course, this means you don't get free sandwiches anymore. This would not be an illegal contract under the GDPR, AFAICT. Now, if my contract were just "I'm going to give you free sandwiches." Then yes, collecting data and advertising would not be necessary for that contract. But that isn't the contract.
- azernik 8y agoFrom same source: "The processing must be necessary to deliver your side of the contract with this particular person." That is - these regulations refer to the performance of a contract by the service provider. If the data isn't necessary for creating the sandwich, you're not allowed to deny use of the service based on the user not giving you the data. GDPR was specifically written by smart lawyers and regulators to prohibit the specific kind of contract you're describing. The whole point of regulations like this (also minimum wage, regulation of arbitration agreements, etc.) is to limit the kinds of contracts people can enter into. Specifically, they're allowed to consent to give you that data, but that's not allowed to be a condition for the use of the service. EDIT: More specific sourcing on the way that GDPR regulates contracts, in Article 7(2): "Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding." EDIT 2: And in fact, we've gone in a circle. Again, as Recital 43 states: "Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance." This is all super crystal clear, by design.
- methodover 8y ago> Specifically, they're allowed to consent to give you that data, but that's not allowed to be a condition for the use of the service. You seem to be trying to say that Recital 43 rules out certain types of items as being part of the terms of a contract between a person and a service provider. Namely, the term `you will be shown targeted ads` is an invalid term in a contract. (If this is a misunderstanding of your position, please let me know.) But this is not what Recital 43 actually says. Recital 43 talks about the performance of a contract. It does not speak to the terms of a contract. The phrase "performance of a contract" is, I believe, a specific thing in contract law: it refers only to the execution of some established contract. If Recital 43 or some other part of the GDPR wanted to limit the terms of legal contracts to exclude targeted advertising, they could have done that. But they did not, AFAICT.