Schrems strikes again, filing GDPR complaints against Facebook and Google

Just days into GDPR, tech giants already face legal tussle over consent

Facebook keyboard

Privacy campaigner Max Schrems has filed complaints against Google, Facebook, Instagram and WhatsApp, alleging that they are forcing users to consent to data collection in order to use their services.

It marks the first real test for regulators since the introduction of the GDPR, which states that consent to data collection must be freely given, and cannot be a prerequisite of using a service.

Advertisement - Article continues below

The four tech giants are pushing "forced consent" on users via pop-up boxes that require users to agree to data collection in order to access the sites and apps, according to Schrems' newly-founded data privacy rights organisation, noyb.eu (the European Center for Digital Rights, or None of Your Business).

The non-profit filed the claims in four countries on 25 May, the day GDPR applied to all organisations using EU residents' data.

Filing its complaint against Google Android in France, against Facebook in Austria and against the social network's two subsidiaries, Instagram and WhatsApp, in Belgium and Hamburg respectively, noyb.eu hopes to enable "European coordination" between countries' data protection authorities over the complaints.

The Irish data protection commissioner is also likely to get involved, the organisation believes, because Facebook, Instagram and WhatsApp are all headquartered in Dublin.

Advertisement
Advertisement - Article continues below

Schrems, who serves as chair of noyb.eu, said: "Many users do not know yet that this annoying way of pushing people to consent is actually forbidden under GDPR in most cases.

Advertisement - Article continues below

"Facebook has even blocked accounts of users who have not given consent. In the end, users only had the choice to delete the account or hit the 'agree' button that's not a free choice, it more reminds [us] of a North Korean election process."

IT Pro has contacted Google and Facebook about the complaints.

A Google spokesperson said: "We build privacy and security into our products from the very earliest stages and are committed to complying with the EU General Data Protection Regulation. Over the last 18 months, we have taken steps to update our products, policies and processes to provide users with meaningful data transparency and control across all the services that we provide in the EU."

Schrems' and noyb.eu's argument is that GDPR only allows organisations to process data that is strictly necessary for the service; everything else they wish to collect to sell onto third parties or to target users with advertising - requires active opt-in consent from users.

Advertisement - Article continues below

If noyb.eu's complaints are upheld, it believes it can bring an end to the "digital plague" of "annoying pop-ups" that companies rely on to get users' consent, and put smaller businesses, which cannot withhold services until users consent to their terms and conditions, on a more level playing field with the tech giants.

Schrems' last legal case against Facebook led to the scrapping of the Safe Harbour agreement, which underpinned data transfers from the EU to the US but was found to be inadequate at protecting European citizens' rights.

His latest privacy complaints are likely to make waves too they are the first real test of GDPR and its enforcement.

Organisations that fail to comply with the data protection regulation face fines of up to 4% of their annual turnover or 20 million, whichever is higher, leaving these tech giants with huge penalties if they are found to have failed to comply.

Advertisement - Article continues below

"We probably will not immediately have billions of penalty payments, but the corporations have intentionally violated the GDPR, so we expect a corresponding penalty under GDPR," said Schrems.

Noyb.eu is planning more complaints under GDPR, too, focusing on illegal use of users' data for advertising, which it has dubbed "fictitious consent".

Image: Shutterstock

Advertisement
Advertisement

Recommended

Visit/policy-legislation/data-protection/355184/supreme-court-finds-morrisons-was-not-liable-for-2014
data protection

Supreme Court rules Morrisons was not liable for 2014 data breach

1 Apr 2020
Visit/security/privacy/355048/government-may-trace-covid-19-patients-using-mobile-phone-data
privacy

UK government may trace COVID-19 patients using mobile phone data

20 Mar 2020
Visit/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up
General Data Protection Regulation (GDPR)

Irish data regulator racks up GDPR cases against Big Tech

24 Feb 2020
Visit/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal
data management

EU-US data transfer tools used by Facebook ruled legal

19 Dec 2019

Most Popular

Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020
Visit/business-strategy/flexible-working/355186/why-were-lucky-covid-19-has-come-now
flexible working

Why we’re lucky COVID-19 has come now

3 Apr 2020