Showing posts with label Facebook Ireland. Show all posts
Showing posts with label Facebook Ireland. Show all posts

Sunday, 5 December 2021

Consumer law and the GDPR: Case C-319/20 Facebook Ireland - Opinion of the Advocate General


 


 

Lorna Woods, Professor of Internet Law, University of Essex

 

Facts

 

The Bundesverband der Verbraucherzentralen und Verbraucherverbände – Verbraucherzentrale Bundesverband e.V. (Federation of German Consumer Organisations) sought to bring an action before the German courts arguing that Facebook, in the context of making free, third party games available on its platform, contravened data protection rules by not giving adequate information about the data collected and this also constituted a violation of rules on unfair competition and on consumer protection. It brought this action before the Bundesgerischtshof, which court had doubts as to whether the federation had standing given the entry into force of the GDPR. It referred questions on this issue to the CJEU.

 

As the Advocate General phrased the question, the issue was whether Article 80(2) GDPR

 

precludes consumer protection associations from retaining, following the entry into force of that regulation, the standing to bring proceedings that national law confers on them in order to obtain injunctions against conduct that constitutes both an infringement of the rights conferred by that regulation and an infringement of the rules designed to protect consumer rights and to combat unfair commercial practices [para 4]

 

In Germany, the standing of the federation would not have been in doubt prior to the introduction of the GDPR; the question is whether it has been altered by the GDPR and, specifically, whether the GDPR exhaustively provides for the mechanisms by which its provisions are enforced so that it precludes national legislation which allows consumer protection bodies to bring actions against those allegedly responsible for an infringement of personal data, relying on other causes of action.

 

Opinion

 

The Advocate General’s opinion commenced by noting that, since the Federation had not been mandated by a data subject to bring the action, the relevant provision was Article 80(2) GDPR. The Court has considered a similar question in relation to the data Protection Directive in Fashion ID. It found that Articles 22-24 of the Data Protection Directive “must be interpreted as not precluding national legislation which allows consumer-protection associations to bring … legal proceedings against a person allegedly responsible for an infringement of the protection of personal data” [para 63 Fashion ID, cited para 44]. The Directive neither required Member States to give such organisations standing to bring a data protection action, but nor did it expressly preclude it. Indeed, the provision of such a possibility contributed to the objectives of the Data Protection Directive.  So, the question is – has anything changed?

 

The Advocate General considered the characteristics of the GDPR. The fact that it is in the form of a regulation (by contrast to the previous directive) suggests a tendency towards full harmonisation rather than the minimum standards found in the Data Protection Directive. However, as the Advocate General pointed out, “[t]he truth is more complex” [para 51]. He pointed to the legal base for the GDPR: Art 16 TFEU which

 

“precludes the view that in adopting [the GDPR] the European Union would have pre-empted all the ramifications which the protection of personal data may have in other areas relating, in particular, to employment law, competition law or even consumer law, by depriving Member States of the possibility of adopting specific rules in those areas ….” [para 51]

 

Data protection has a cross-sectoral impact but the harmonisation does not cover all of these areas. Moreover, the intensity of the harmonisation is not uniform across the GDPR. The use of a regulation does not necessarily mean that Member States have no scope for action [para 53].

 

Against this background we seen that Article 80(2) is “optional” – it uses the word ‘may’ [para 54]. Interpreting the scope of Article 80(2) the Advocate General considered that the entities listed there could not be limited  to those entities whose sole and exclusive object is data protection, but “extends to all entities which pursue an objective in the public interest that is connected with the protection of personal data” [para 61]. He also argued that other aspects of Article 80(2) should not be interpreted restrictively, so that the entity should not be required to show specific existing cases of persons affected by the processing.

 

Rather, all that is required is an allegation of an infringement of the provisions designed to protect individual rights. The objective of the provision is to give the bodies the ability to have a competent body check whether the rights-granting provisions of the GDPR are being complied with; the emphasis is on the protection of the collective interests of consumers. This viewpoint is supported also by the approach in Directive 2020/1828 on consumer injunctions (see especially recital 15). This is the position in this case, in which the federation seeks an injunction against Facebook Ireland [para 70].

 

More generally, he argued that

 

“[i]t would be contrary to the objective of ensuring a high level of protection of personal data if the Member States were precluded from putting in place actions which, while pursuing an objective of protecting consumers, also help to achieve the objective of protecting personal data” [para 75].

 

The defence of collective interests of consumers is, in the view of the Advocate general, particularly suited to the establishment of a high level of data protection and a narrow interpretation of Article 80(2) would interfere with the preventative function of actions brought by such bodies. An injunction, as in issue here, contributes to the effective protection of rights.

 

While the laws pertaining to data protection and consumer law have developed separately, there are interactions between the two areas; a similar point can be made in relation also to competition law: the same conduct can simultaneously be covered by all three regimes. While consumers are different from data subjects, these also overlap. This leads to ‘complementarity and convergence’ between these different areas of law and these may mutually strengthen protection.

 

In sum, Article 80(2) did not preclude legislation that allowed these entities to bring an action in the interest of enforcement of data protection rights.

 

Comment

 

The end point in this, especially given Fashion ID, is not so surprising, though we will – of course – need to wait for the Court’s judgment on this. It is noticeable that the Advocate General goes to some lengths to emphasise that although the GDPR is a regulation, it is not closed, and especially not where the higher levels of protection for data are concerned.  The implication of the Advocate General’s reasoning is of course that each clause will need to be considered on its own terms, but always in the light of the objectives of the GDPR and the need to ensure a high level of protection. Here, the impact of the regulation’s legal base should be noted; the reference to high levels of protection is not just verbiage but has been used as a motivating force in the reasoning of the Advocate General.

 

Another point of interest is the recognition of the interplay between the different types of law: data protection, consumer and even competition law. The Advocate General has used this interplay to strengthen protection, rather than assigning types of law to silos, and potentially thereby undermining protection. The approach of the Advocate General seems right – as he notes, the same conduct may fall within each of these rules. There is overlap, but it raises the question more broadly of the need for cooperation between at least the regulators in each of the fields.  This approach is also noteworthy as it illustrates support for attempts to deal – using a range of different legal mechanisms -with problems relating to the super-dominant ICT business built on user data. This is particularly significant given the perceived weakness in effective data protection regulation in some Member States.

 

Photo credit: Johnscotaus, via Wikimedia Commons



Wednesday, 16 June 2021

Who has jurisdiction over Facebook Ireland? The CJEU rules on the GDPR 'one stop shop'

 



 

Lorna Woods, Professor of Internet Law, University of Essex

 

Introduction

 

This recent CJEU judgment concerns the one stop shop in the GDPR and the way that very large corporations that have operations in most if not all Member States are regulated.  Facebook has its European headquarters in Ireland so that the Irish Data Protection Commissioner (DPC) is ‘lead authority’ – that is, the DPC has primary responsibility for regulating Facebook under the GDPR.  There have been some concerns about how this one stop shop has been working, especially since some of the larger companies have tended to establish themselves in the same, small Member State. The one stop shop mechanism relies on trust between the Member States, but different Member States have varying degrees of enthusiasm for the enforcement of data protection and also have different levels of money to throw at the issue. As is the case with other one-stop shop mechanisms in other legislation, there are exceptions or ways for other affected regulators to be involved. This case is about the space left to those other regulators.

 

Facts

 

In 2015 the Belgian Privacy Commissioner (subsequently the Data Protection Authority) sought an injunction in the Belgian courts against Facebook Belgium with the objective of ending alleged infringements of data protection laws by Facebook through the collection and use of information on the browsing behaviour of Belgian internet users, whether or not  they  were  Facebook  account  holders,  by  means  of  various  technologies,  such  as  cookies, plug-ins (like or share buttons) or pixels. The matter ended up in the Hof van beroep te Brussel (an appeal court) which was uncertain as to the effect of the one stop shop in the GDPR on the competence to the Belgian Data Protection Authority to bring action against Facebook Belgium. So while Article 55(1) GDPR establishes the principle that each national regulatory authority is competent to carry out its role as regards its own national territory, Article 56(1) states:

 

the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor.

 

Judgment

 

The central question concerned the circumstances in which, given the one stop shop established by Article 56(1) GDPR, a supervisory authority could take action in relation to specific instances of processing. In this, the Court emphasised two underpinning considerations: that the high level of data protection applied across the EU; and that the one stop shop depended on the process for cooperation laid down in Article 60.

 

While Article 60 envisages that it is the responsibility of the lead authority to adopt decisions in relation to cross-border processing, and that position is the general rule, there are exceptions found in Articles 56(2) (matter only affecting its own territory) and Article 66 (urgency procedure). The Court noted, however, that the exercise of these provisions “must be compatible with the need for sincere and effective cooperation with the lead supervisory authority” as set [para 60] – but this obligation applies also to the lead authority - so that it cannot eschew dialogue with those other authorities [para 63]. Specifically, any  relevant  and  reasoned  objection  made  by  one  of  the  other  supervisory  authorities has the effect of blocking, at least temporarily, the adoption of the draft decision of the lead supervisory authority.

 

In terms of the protection of fundamental rights, the Court noted this allocation of responsibilities is compatible with the Charter. It noted that:

 

the use of the ‘one-stop shop’ mechanism cannot under any circumstances have the consequence that a national supervisory authority, in particular the lead supervisory authority, does not assume the responsibility incumbent on it under Regulation 2016/679 to contribute to providing effective protection of natural persons from infringements of their fundamental rights as recalled in the preceding paragraph of the present judgment, as otherwise that consequence might encourage the practice of forum shopping, particularly by data controllers, designed to circumvent those fundamental rights and the practical application of the provisions of that regulation that give effect to those rights [para 68].

 

The Court noted that legal action by a regulatory authority could not be completely excluded- for example when the lead supervisory authority has not responded to a request for information (see Article 61(8) GDPR), where there is an urgent need for the adoption of final measures (Article 66(2) GDPR), or where the matter is referred for consideration by the European Data Protection Board (EDPB) (Article 64(2) GDPR). In this instance, the Belgian DPA asked the DPC to respond to its request for mutual assistance as expeditiously as possible, but no response was given.

 

The Court also addressed the question of whether the data controller must have a ‘main establishment’ in the territory of that other regulator, concluding that there was no such prerequisite [para 84]. A third question asked whether the non-lead supervisory would be limited as to which body to sue – that is, whether it can take action against the main establishment of the controller or against the establishment that is located in its own Member State. In the national proceedings in this case, the litigation was brought against Facebook Belgium although the headquarters of the Facebook group is situated in Ireland and Facebook Ireland is the sole controller with respect to the collection and processing of personal data throughout the European Union. Facebook Belgium was set up to sell advertising in Belgium but also to lobby the EU institutions. The Court determined that the non-lead regulatory authority may take action with respect to the main establishment of the controller located in that authority’s own Member State but also with respect to another establishment of that controller, provided that the object of the legal proceedings is data processing  carried out in the context of the activities of that establishment and that that authority is competent to exercise that power [para 96].

 

A fourth question addressed the impact of the change in regime from the Data Protection Directive (which did not have a one stop shop) and the GDPR. The Court distinguished between actions brought before the date the GDPR became applicable and actions after that date. As regards the first situation, such legal action may be continued (on the basis of the Directive); for other actions the GDPR rules apply – and this allows such a regulatory authority to take action where one of the exceptions applies.

 

The Court held that Article 58(5) GDPR (on the power of data protection authorities to bring legal proceedings) has direct effect, so that the relevant authorities may rely on the provision even when it has not been specifically implemented in the national legal system.

 

Comment

 

This seems to be a balanced judgment in which the Court aims to reconcile competing pressures.  It has re-emphasised the one stop shop, but is aware of the unevenness of resources and alive to the risk of forum shopping against that background.  One of the key elements of this judgment is the Court’s emphasis on the obligation to cooperate, which applies to lead authority and other authorities alike. Nonetheless, while the lead regulator must be given the chance to act, lead regulators cannot choose to ignore the importunate demands of other national regulators – whether for lack of resources, or other reasons (eg a different assessment as to what’s important).  The significance of this comes down to the concerns about the effectiveness of the DPC (especially bearing in mind the size of the companies under the DPC’s jurisdiction).  Against this background, the judgment will probably be welcomed by privacy advocates. Whether it is equally good from the perspective of data controllers, at least those based in Ireland, seems far less likely. What is potentially problematic from the perspective of the data controller is the greater unpredictability of the data protection regime. This may be less about fragmenting standards (especially if the decision is referred to the EDPB) but about where enforcement actions may start; this agenda may not rest entirely in the hands of the lead authority.

 

Photo credit: Niamfrifruli, via Wikimedia Commons