4 ms·
I'm the author and even if I know GDPR quite well as professional journalist I know I can't interprete a law on my own, so I additionally asked an legal expert
by rufposten 7y ago
I'm the author and even if I know GDPR quite well as professional journalist I know I can't interprete a law on my own, so I additionally asked an legal expert in this field. So this is what he explained:
1. Sending data to Appsflyer is OK in general, but you have to declare to which parties the data will be sent afterwards. As most of the partners will be joint controllers of the data you have to lay open the arrangements with ALL joint controllers: "The arrangement may designate a contact point for data subjects. The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject."
Tiktok just denied to show any arrangements.
2. Sending data to Facebook is ok in general, but here it's without consent, so it must be covered by legitimate interests. This has to be balanced with the interests of the user and two crucial points are how invasive and how transparent a data procesing is. Sending your search terms to a company you don't even know it's involved and de-anonymising you in the same time (in case you have a app of facebook inc. on your smartphone) hardly can be legitimate interest.
3. Sending data to a non-EU country is OK, but only if the country is secure. This is indeed complex, but: ECJ ruled, that if public authorities have access on a generalised basis to the content of electronic communications, it's not ok, it's even a FUNDAMENTAL violation of the privacy of the users.
4. Browser/Device-Fingerprinting is legally ok. But I doubt that it is used for anti-fraud/security. If it's used for tracking, they probably need consent.
- singularity2001 7y agoConsider adding this highly relevant extra information to the main post.