4 ms·
(working in the field and away from my computer so using a throaway) Basically you have two different laws that apply here. Eprivacy and the GDPR: * Eprivacy
by temp_account75 7y ago
(working in the field and away from my computer so using a throaway)
Basically you have two different laws that apply here. Eprivacy and the GDPR:
* Eprivacy has been updated in 2009 and says that you need consent of the user for any read/write operation in the user terminal, unless it has been specifically requested by the user. The wording is strange, but it has been interpreted mostly as being about cookies and any other sorts of tracers. That includes fingerprinting. The thing is, it is a directive, so each European country transcribed it slightly differently! Sometimes, the national DPA (data protection agency) does not even have the authority to apply this law. This is the infamous "cookie banner" law. Note that all login cookies, cart cookies, consent cookies are generally regarded as exempted since they are needed to provide the service asked for by the user.
* The GDPR that everybody knows.
The thing is, since the GDPR, the consensus among DPAs has been that the consent used in Eprivacy is in fact the "GDPR consent" (freely given, no negative consequence, easy to withdraw, requires a positive act, and so on). This is a major change, because most cookie banners used now don't have those characteristics. Keep on scrolling to consent won't fly. "I consent"/"more option" buttons won't fly. "Use you browser settings to block cookie if you don't like it" won't fly. Cookie walls won't fly.
This is the current interpretation of the law among most DPAs. And yes, most website are violating it, but in the sense of Eprivacy, not the GDPR. The non harmonization on the European level makes it harder to engage in repressive action but I have faith that this will soon change.
In the case described by the article, you would need a GDPR consent to carry on fingerprinting, so TikTok is in violation of EPrivacy. When DPAs will start repression, they could be targeted for that.
My two cents!
- Wowfunhappy 7y agoThank you, but I'm a bit confused. You lost me here: > And yes, most website are violating it, but in the sense of Eprivacy, not the GDPR. From what I understand of your post, GDPR has basically superseded the old Eprivacy law, because it requires the same things and then more on top.
- temp_account75 7y agoSorry about that. They are violating Eprivacy, not the GDPR, because they are dropping tracers without proper consent. But they are violating it because the consent they are collecting is not valid in the definition given in the GDPR. The previous understanding of Eprivacy (before the GPDR) admitted a "soft consent", ie "keep reading and you consent". That is not longer the case because of GDPR. What they do with the data they collect is subject to the GPDR, but the use of tracers without consent is subject to Eprivacy. Hope it's more understandable!
- Wowfunhappy 7y agoThat makes more sense, thanks!