When I pointed out issues with the DMA-GDPR Guidelines & resulting risks for *all* controllers (not just gatekeepers), the EDPB’s Gwendal Le Grand said something to the effect of “Don’t just post about it, submit a response”. So here we go, a copy of the response submitted yesterday to the public consultation by the Commission and the EDPB!
I have had discussions with companies of all sizes over the past couple of months on the topic, and the level of worry regarding various topics meant that it made sense to contribute more formally than my summary post of a few weeks ago ( https://lnkd.in/ex7Gvirv ).
This goes beyond the Digital Markets Act, as the Guidelines contain considerations on the interpretation of GDPR concepts that are not always identical to those from other EDPB guidance. This in turn creates a risk of inconsistency (where a same GDPR concept might be applied differently to gatekeepers or non-gatekeepers) or legal uncertainty (if these novel interpretations are intended for all yet are only present in guidance that is less widely read).
We’ll see what comes of the public consultation and whether it leads to any changes to the proposed Guidelines, but this contribution should be interesting reading for data protection professionals, gatekeepers & non-gatekeepers alike.
Here are my main conclusions:
1. The DMA-GDPR Guidelines should be revised, in particular as regards the taking of any positions regarding GDPR concepts and their interpretation that go beyond the text of the GDPR itself as well as any interpretations already published by the EDPB in other, broader guidance on the GDPR.
2. The Guidelines should be amended to apply a flexible standard of consent granularity, in accordance with the GDPR and existing guidance of the EDPB.
3. The Guidelines should make it clear that the requirement for an “equivalent” service is *not* misconstrued a requirement for an “identical” service, thus allowing inherent differences to be taken into account.
4. The Guidelines should be amended to avoid contradictions or inconsistencies with other statutory frameworks, such as the provisions of the ePrivacy Directive.
5. On “dark patterns” and the assessment of freely given consent, the Guidelines should focus on potentially deceptive practices rather than mere nudging, which does not rob a data subject of his/her freedom.
6. The interpretation of the DMA provisions on data combination and cross-use remains consistent and proportionate (the analysis to which I refer in the submission is available here: https://lnkd.in/eDxHcpwY ).
7. The Guidelines should make it clear that the DMA provisions on data portability and access are to be interpreted in a manner that permits compliance with the GDPR’s data minimisation principle as well as with the actual obligations under the DMA.
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗