6 ms·
Legitimate interest is one of the six legal bases for processing personal data under the GDPR, alongside: consent, performance of a contract, a vital interest,
by tcldr 5y ago
Legitimate interest is one of the six legal bases for processing personal data under the GDPR, alongside: consent, performance of a contract, a vital interest, a legal requirement, and a public interest.
I don’t think we’ve seen much in the way of precedent being set here, but theoretically if you can demonstrate and document a measured approach to the way you collect and process data it should be fine. (Objection not withstanding.)
On the other hand, a drag net approach to collecting and sharing data won’t stand up to legitimate interest claims no matter how many toggles you put on your cookie banners.
- zibzab 5y agoMy personal take is that there is no real legitimate interest here and these companies are just testing to see how far they can push this.
- xg15 5y agoIn the dialogs I have seen so far, the "legitimate interest" page was always a perfect carbon-copy of the "consent" page - with the only difference that the "consent" options were off by default while the "legimate interest" options were on by default. I understand that, legally, the buttons represent different actions (not giving consent vs objecting a legitimate interest claim) but practically, the only purpose the "legitimate interest" page seems to serve is as a way to have on-by-default options that are still borderline legal. I can't imagine this is in the spirit of the law.
- pieno 5y agoI think a lot of sites are conflating cookie consent and GDPR consent. You only need GDPR consent when processing personal data, so you don’t need consent just for storing settings in a cookie (as long as those settings do not contain personal data or identifiers linked to personal data). But many sites will ask “GDPR consent” or claim “GDPR legitimate interest” for those settings cookies in any case (in my view that’s a dark pattern in itself because you’re actually making the side harder or impossible to use and thereby inducing visitors to just click the big green “accept all” button to get it over with already…)
- M2Ys4U 5y ago>I think a lot of sites are conflating cookie consent and GDPR consent. They are doing that, however the the legal standard of consent under the ePrivacy Directive is the same as the GDPR. The ePD initially referenced the definition in the Data Protection Directive, but that was replaced by the GDPR.
- tcldr 5y agoAs I understand, there's currently an update to the ePD working its way through which aims to clarify some of these points and unify it with the GDPR. Here's what they say about analytics for example: > Audience measurement shall be limited to non-intrusive practices that are not likely to create a privacy risk for users > The Council’s position creates a new exception for audience measurement as suggested by the Article 29 Working Party6. However, the derogation for audience measurement as proposed by the Council is worded too broadly and could lead to an overly broad interpretation of what could fall under the scope of the derogation and consequently lower the level of protection of end users’ terminals. > Therefore, the EDPB stresses that the derogation for audience measurement should be limited to low level analytics necessary for the analysis of the performance of the service requested by the user and should be solely limited to providing statistics to the service operator, and must be put in place by the operator or their processors. Therefore, this processing operation cannot give rise, by itself or in combination with other tracking solutions, to any singling-out or any profiling of users by the provider or other data controllers. Moreover, the audience measurement service should not allow to collect navigation information related to users across distinct websites/applications and should include a user-friendly mechanism to opt-out from any data collection. https://edpb.europa.eu/system/files/2021-03/edpb_statement_032021_eprivacy_regulation_en_0.pdf https://edpb.europa.eu/system/files/2021-03/edpb_statement_0...
- M2Ys4U 5y agoYeah, the ePrivacy Regulation has been in development for years now, being held up by the Council. It was supposed to be adopted soon after the GDPR, but 5 years later and we're still waiting...
- g_p 5y agoWhat most websites don't realise is that cookies aren't only covered by GDPR, but also the ePrivacy directive (or more specifically its national implementation, since it is a directive). The ePD says consent is the only legal basis permitted for placing non essential cookies. Essential has a very narrow meaning that effectively covers a shopping basket or login cookie for features you elect to use. It doesn't cover analytics etc. No presumed consent, no opt-out, etc. The combination of GDPR and ePD means that your ePD cookie consent must meet GDPR standard levels of consent, which require clear, unambiguous opt-in, informed consent. And that rules out many dark patterns we see everywhere. The German "Planet 49" ruling confirms that consent is required for cookies. Therefore every time I see "legitimate interest" on a cookie banner, I know it's an ill-informed attempt at a dark pattern by someone who wants a second bite at the cherry, and doesn't understand they: 1. Require consent 2. Need this consent to be actively given (opt in, not opt out). 3. Can't just ask the question again with a pre-ticked box and hide it behind a tab or fold...
- tcldr 5y ago> The ePD says consent is the only legal basis permitted for placing non essential cookies. Essential has a very narrow meaning that effectively covers a shopping basket or login cookie for features you elect to use. It doesn't cover analytics etc. No presumed consent, no opt-out, etc. I think this area has always been a bit murky, actually. There's currently a review of the ePD taking place to unify it with the GDPR and clarify on points such as these. This is in the working group's memo from March 2021 > Audience measurement shall be limited to non-intrusive practices that are not likely to create a privacy risk for users > The Council’s position creates a new exception for audience measurement as suggested by the Article 29 Working Party6. However, the derogation for audience measurement as proposed by the Council is worded too broadly and could lead to an overly broad interpretation of what could fall under the scope of the derogation and consequently lower the level of protection of end users’ terminals. > Therefore, the EDPB stresses that the derogation for audience measurement should be limited to low level analytics necessary for the analysis of the performance of the service requested by the user and should be solely limited to providing statistics to the service operator, and must be put in place by the operator or their processors. Therefore, this processing operation cannot give rise, by itself or in combination with other tracking solutions, to any singling-out or any profiling of users by the provider or other data controllers. Moreover, the audience measurement service should not allow to collect navigation information related to users across distinct websites/applications and should include a user-friendly mechanism to opt-out from any data collection. Source: https://edpb.europa.eu/system/files/2021-03/edpb_statement_032021_eprivacy_regulation_en_0.pdf https://edpb.europa.eu/system/files/2021-03/edpb_statement_0... This seems a reasoned approach.