Schrems strikes again, filing GDPR complaints against Facebook and Google

Just days into GDPR, tech giants already face legal tussle over consent

Facebook keyboard

Privacy campaigner Max Schrems has filed complaints against Google, Facebook, Instagram and WhatsApp, alleging that they are forcing users to consent to data collection in order to use their services.

It marks the first real test for regulators since the introduction of the GDPR, which states that consent to data collection must be freely given, and cannot be a prerequisite of using a service.

The four tech giants are pushing "forced consent" on users via pop-up boxes that require users to agree to data collection in order to access the sites and apps, according to Schrems' newly-founded data privacy rights organisation, noyb.eu (the European Center for Digital Rights, or None of Your Business).

The non-profit filed the claims in four countries on 25 May, the day GDPR applied to all organisations using EU residents' data.

Filing its complaint against Google Android in France, against Facebook in Austria and against the social network's two subsidiaries, Instagram and WhatsApp, in Belgium and Hamburg respectively, noyb.eu hopes to enable "European coordination" between countries' data protection authorities over the complaints.

The Irish data protection commissioner is also likely to get involved, the organisation believes, because Facebook, Instagram and WhatsApp are all headquartered in Dublin.

Schrems, who serves as chair of noyb.eu, said: "Many users do not know yet that this annoying way of pushing people to consent is actually forbidden under GDPR in most cases.

"Facebook has even blocked accounts of users who have not given consent. In the end, users only had the choice to delete the account or hit the 'agree' button that's not a free choice, it more reminds [us] of a North Korean election process."

IT Pro has contacted Google and Facebook about the complaints.

A Google spokesperson said: "We build privacy and security into our products from the very earliest stages and are committed to complying with the EU General Data Protection Regulation. Over the last 18 months, we have taken steps to update our products, policies and processes to provide users with meaningful data transparency and control across all the services that we provide in the EU."

Schrems' and noyb.eu's argument is that GDPR only allows organisations to process data that is strictly necessary for the service; everything else they wish to collect to sell onto third parties or to target users with advertising - requires active opt-in consent from users.

If noyb.eu's complaints are upheld, it believes it can bring an end to the "digital plague" of "annoying pop-ups" that companies rely on to get users' consent, and put smaller businesses, which cannot withhold services until users consent to their terms and conditions, on a more level playing field with the tech giants.

Schrems' last legal case against Facebook led to the scrapping of the Safe Harbour agreement, which underpinned data transfers from the EU to the US but was found to be inadequate at protecting European citizens' rights.

His latest privacy complaints are likely to make waves too they are the first real test of GDPR and its enforcement.

Organisations that fail to comply with the data protection regulation face fines of up to 4% of their annual turnover or 20 million, whichever is higher, leaving these tech giants with huge penalties if they are found to have failed to comply.

"We probably will not immediately have billions of penalty payments, but the corporations have intentionally violated the GDPR, so we expect a corresponding penalty under GDPR," said Schrems.

Noyb.eu is planning more complaints under GDPR, too, focusing on illegal use of users' data for advertising, which it has dubbed "fictitious consent".

Image: Shutterstock

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Parler suffers data leak before being taken offline
social media

Parler suffers data leak before being taken offline

12 Jan 2021
Misconfigured Git servers lead to Nissan data leak
hacking

Misconfigured Git servers lead to Nissan data leak

7 Jan 2021
BackupAssist teams with Wasabi to offer cheaper backup for businesses
backup

BackupAssist teams with Wasabi to offer cheaper backup for businesses

6 Jan 2021
Trump's TikTok ban hits another roadblock
social media

Trump's TikTok ban hits another roadblock

9 Dec 2020

Most Popular

SolarWinds hackers hit Malwarebytes through Microsoft exploit
hacking

SolarWinds hackers hit Malwarebytes through Microsoft exploit

20 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

12 Jan 2021