Privacy activist Max Schrems has filed complaints against Google, Facebook, Instagram and WhatsApp, alleging that they are forcing users to consent to data collection in order to use their services.
It marks the first real test for regulators since the introduction of the GDPR, which states that consent to data collection must be freely given, and cannot be a prerequisite of using a service.
The four tech giants are pushing “forced consent” on users via pop-up boxes that require users to agree to data collection in order to access the sites and apps, according to Schrems’ newly-founded data privacy rights organisation, noyb.eu (the European Center for Digital Rights, or None of Your Business).
The non-profit filed the claims in four countries on 25 May, the day GDPR applied to all organisations using EU residents’ data.
Filing its complaint against Google Android in France, against Facebook in Austria and against the social network’s two subsidiaries, Instagram and WhatsApp, in Belgium and Hamburg respectively, noyb.eu hopes to enable “European coordination” between countries’ data protection authorities over the complaints. The Irish data protection commissioner is also likely to get involved, the organisation believes, because Facebook, Instagram and WhatsApp are all headquartered in Dublin.
Schrems, who serves as chair of noyb.eu, said: “Many users do not know yet that this annoying way of pushing people to consent is actually forbidden under GDPR in most cases. “Facebook has even blocked accounts of users who have not given consent. In the end, users only had the choice to delete the account or hit the ‘agree’ button – that’s not a free choice, it more reminds [us] of a North Korean election process.”
IT Pro said it has contacted Google and Facebook about the complaints.
A Google spokesperson said: “We build privacy and security into our products from the very earliest stages and are committed to complying with the EU General Data Protection Regulation. Over the last 18 months, we have taken steps to update our products, policies and processes to provide users with meaningful data transparency and control across all the services that we provide in the EU.”
Schrems’ and noyb.eu’s argument is that GDPR only allows organisations to process data that is strictly necessary for the service; everything else they wish to collect – to sell onto third parties or to target users with advertising – requires active opt-in consent from users.
If noyb.eu’s complaints are upheld, it believes it can bring an end to the “digital plague” of “annoying pop-ups” that companies rely on to get users’ consent, and put smaller businesses, which cannot withhold services until users consent to their terms and conditions, on a more level playing field with the tech giants.
Schrems’ last legal case against Facebook led to the scrapping of the Safe Harbour agreement, which underpinned data transfers from the EU to the US but was found to be inadequate at protecting European citizens’ rights. His latest privacy complaints are likely to make waves too – they are the first real test of GDPR and its enforcement.
Organisations that fail to comply with the data protection regulation face fines of up to 4% of their annual turnover or €20 million, whichever is higher, leaving these tech giants with huge penalties if they are found to have failed to comply.
“We probably will not immediately have billions of penalty payments, but the corporations have intentionally violated the GDPR, so we expect a corresponding penalty under GDPR,” said Schrems.
Noyb.eu is planning more complaints under GDPR, too, focusing on illegal use of users’ data for advertising, which it has dubbed “fictitious consent”.