The Belgian DPA’s newest decision – about a shared customer loyalty scheme allowing participating retailers to have up-to-date data regarding a customer, some of the data coming from national identity cards – is worth a read. [Skip pages 8-35 if not a Belgian data protection lawyer, though]
Q1: (Joint) controllership? [paras. 215-232]
The Belgian DPA considers that *all* participating retailers and the provider of the shared loyalty scheme are joint controllers, because the purpose of “collection and sharing of personal data […] is shared by [the provider] and the retailers”: it is “necessary to enable [the provider] to enrich its database to attract retailers interested in reliable and up-to-date identification of their consumers” and that also helps retailers “avoid any confusion between their consumers”.
Does this mean lots of separate joint controllerships between the provider and each retailer individually, or one major joint controllership between everyone? The decision is unclear – probably because it’s a tricky situation with significant implications for the pooling of data.
The Belgian DPA also considers the means of processing to be determined jointly:
“data is collected mainly by retailers using devices supplied by [the provider] […] [the provider] centralises the data in a technical infrastructure that it has developed, but the pooling itself is made possible by ongoing contributions from retailers, who regularly transfer identity data to keep the information up to date.
Part of the reasoning underlying this conclusion is that some of the data is collected via paper forms by the retailer and then submitted to the provider’s platform.
Conclusion? “[I]f the collection is primarily the responsibility of the retailers, while the pooling is carried out by [the provider], these operations are inseparable and inextricably linked […] pooling by [the provider] is only possible through the collaboration of retailers in the process of collecting identity data.
Q2: Legal ground?
Based on Belgian legislation on ID cards, the Belgian DPA rapidly says that consent is required for loyalty schemes, something the provider does not appear to have challenged.
Instead, the discussion was focussed on whether the conditions for valid consent are met.
One point seems in my view particularly interesting here:
“the services offered require acceptance of [the provider’s T&Cs] by way of consent […] The fact that the data subject must accept [the provider’s T&Cs] in order to benefit from the commercial advantages offered by [a retailer] demonstrates a lack of freedom offered to data subjects” [para. 249(A)].
But is that really so? I love to point out the “a contrario” reading of Art. 7(4) GDPR, and I think that is relevant here. If the law requires consent for ID-based loyalty schemes (= contracts), why can’t T&C acceptance & GDPR consent be linked?
More later – the decision covers a lot!
Decision (in French): https://lnkd.in/ezf73KzW
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗