Global Privacy Control is great, why can’t that solve cookie fatigue in the EU? Could it be part of the Digital Omnibus 88b proposal?” A recent study examines the GPC in context of EU-level discussions on possible changes to the GDPR and ePrivacy rules.
It’s an important question, as the idea of browser-level settings needs a proper debate – yet right now, few are actually looking at their practical implications.
Notably:
1. It’s all very nice to say browsers must provide “the technical means to allow data subjects to give their consent” (proposed Article 88b(6) GDPR), but how can browser-level consent meet the requirement to show the controllers’ identity? (= informed consent, Recital 42 of the GDPR)
There is no way for all possible website/app publishers and their partners etc. to be listed within a browser setting.
So it won’t be a means of giving consent (= positive action) but only a means of objecting/indicating a refusal of consent (= negative action).
2. Where a user makes a general “refusal” choice in the browser, can a publisher or partner still make the case for acceptance? Or are users who say “no” never reachable to even explain the value of certain processing activities? I have seen such concerns coming from a wide range of sectors.
Ultimately, if a consent refusal is based on an incomplete view of the consent request itself, is it “uninformed”?
3. The issue of conflicting signals (between a browser signal/GPC and a website-specific signal) is mentioned in the study as unclear:
If a data subject consents to tracking-based advertising through a banner while the GPC signal is active, […] If we consider GPC as an indication of the data subject’s wishes, then the consent that the data subject gives by clicking yes on the banner could be considered invalid due to the conflict between the automated GPC signal and the data subject’s click.
=> This is incorrect. Timing matters, as does specificity. If a user says “no” yesterday and “yes” today, the “yes” prevails – even more so if the “yes” is specific to a given website. But yes, this needs to be made clear in the law too.
4. The “media” exemption isn’t a solution, as it doesn’t apply to e.g. community/e-commerce/… sections (often present).
So what should we be doing?
In my view, we need a real discussion about what 88b is intended to achieve.
Is it a general objection right to certain kinds of processing? If so, there *has* to be an override anyway in case of compelling legitimate grounds (which the study rightly references in relation to fraud-related processing).
Is it a means of giving consent? If so, it may be better to focus on making consent choices last longer (e.g. by allowing their storage in a “secure” part of browser storage).
Is it a universal refusal of consent? If so, we need to permit the provision of explanations to show consent can be useful.
After all, data protection law isn’t about banning all processing but laying down rules for it to be lawful.
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗