Page 57 - CB12_all pages
P. 57

~ Spotlight on ~





            It is true that the current text of the proposed ePrivacy   ment is not validly constituted by way of a pre-checked
            Regulation appears to be quite restrictive on direct email   checkbox which that user must deselect to refuse his or her
            marketing.                                        consent. That decision is unaffected by whether or not the
                                                              information stored or accessed on the user’s equipment is
            Regarding specific conditions, the GDPR allows traders   personal data. EU law aims to protect the user from any in-
            to carry out direct marketing based on legitimate interest   terference with his or her private life, in particular, from the
            rather than user consent: “…The processing of personal data   risk that hidden identifiers and other similar devices enter
            for direct marketing purposes may be regarded as carried   those users’ terminal equipment without their knowledge”
            out for a legitimate interest” (Recital 47 of the GDPR).  ( Judgment in Case C-673/17).

            On the contrary, the proposed ePrivacy Regulation will only   However, the new version of the e-Privacy Regulation still
            allow data processing based on consent, not on legitimate   places the burden on websites to ensure that consent is
            interest. Such an approach would likely lead to a severe   obtained for tracking cookies and for device fingerprinting.
            restriction on “soft spam”. As observed by E-commerce   So, there is still much uncertainty at this stage.
            Europe, the association of online retailers representing
            over 75,000 EU stores, as the GDPR lays down legitimate   The proposed text also clarifies that cookie walls may not
            interest as a possible legal basis for data processing, an   be used. Making access to a website entirely dependent on
            identical framework should be included in the proposed   consent to cookies deprives the user of a genuine choice and
            ePrivacy Regulation, preferably with the grounds for lawful   may be considered disproportionate. However, recital 20 of
            processing without restrictions on the processing of personal   the proposal also says that: “Making access to the website
            metadata obtained in the course of electronic communica-  content provided without direct monetary payment con-
            tions services.                                   ditional to the consent of the end-user to the storage and
                                                              reading of cookies for additional purposes would normally
            Cookies are another important privacy area addressed by   not be considered disproportionate in particular inter alia if
            proposed ePrivacy Regulation.                     the end-user is able to choose between an offer that includes
                                                              consenting to the use of cookies for additional purposes on
            Many users complaint that navigation on the internet is   the one hand and an equivalent offer by the same provider
            continuously hindered by pop-ups or website banners ask-  that does not involve consenting to data use for additional
            ing for permission to save cookies on the user device. The   purposes on the other hand”.
            ePrivacy Regulation is likely to streamline the process of
            consent acquisition when it comes to cookies.     Another important aspect relates to penalties for those
                                                              breaking the new rules, which will mirror the hefty ones of
            The original drafts of the ePrivacy Regulation proposed   the GDPR. Fines will range from 2% of annual turnover to
            the (mostly welcomed) removal of cookie banners and  put   4% of annual turnover, depending on the seriousness of the
            specific legal obligations on those who place software (i.e.,   breach.
            browsers) on the market: “Software placed on the mar-
            ket permitting electronic communications, including the   The ePrivacy Regulation is unlikely to see the light of day
            retrieval and presentation of information on the internet,   before the second quarter of 2020. Once adopted, a transi-
            shall offer the option to prevent third parties from storing   tion period will allow the industry to implement the new
            information on the terminal equipment of an end-user or   rules, which are likely to become effective no earlier than
            processing information already stored on that equipment”   2022.
            (former article 10 of the proposal). This provision was no
            longer included in the new text on the ePrivacy Regulation
            published by the Finnish presidency in early October 2019.

            Moreover, the proposed ePrivacy Regulation specifies that
            service providers must provide users with clear, precise and
            user-friendly information on the purposes of the cookies
            used.

            This approach is consistent with a recent ruling by the
            European Court of Justice, dated 1 October 2019: the Court
            has stated that the consent “which a website user must give
            to the storage of and access to cookies on his or her equip-


               Alan Rhode is a co-founder at Taxmen, the one-stop-shop for legal and tax services to the e-Commerce industry.






                                                            57
   52   53   54   55   56   57   58   59   60