The New Guidelines on Consent as a Legal Ground for the Processing of Personal Data in the Digital Context / 21.05.2020 г.
This month the European Data Protection Board* (EDPB) adopted new Guidelines on consent under the General Data Protection Regulation**, replacing the Guidelines on consent previously adopted by the Article 29 Working Party (WP29) and endorsed by the EDPB***.
The new Guidelines on Consent reaffirm the analysis of the notion of consent given by the WP29 and provide further clarifications with regards to the validity of consent in the digital field especially when it comes to the processing of personal data via cookies and similar technologies on an operator’s website, the interaction of data subjects with the so-called “cookie walls” and the relationship between scrolling and consent. Thus, the paragraphs concerning these issues have been revised and updated, while the rest of the document was left largely unchanged except for editorial redactions.
Tear down this cookie wall!
Unbundling of consent with acceptance of website t&c
It has been commonly understood among privacy specialists that “bundling” consent with acceptance of terms or conditions is considered highly undesirable. The EDPB now reaffirms this understanding, citing that in no way can blanket acceptance of general terms and conditions be seen as a clear affirmative action to consent to the use of personal data. Where tacit consent such as scrolling-as-consent still lives, it is to finally be retired as well.
No opt-out mechanisms and no pre-ticked boxes
In a separate paragraph, the EDPB reaffirms that the GDPR does not allow for data controllers to offer pre-ticked boxes or opt-out constructions such as opt-out boxes that require an intervention from the data subject to prevent the use of non-necessary cookies. This requirement will also not in any way surprise those familiar with the recent case-law of the European Court of Justice on cookies****, however, two years after the GDPR becoming effective pre-ticked boxes are still not a view too rarely seen in the universe of cookie consent management panels.
The e-Elephant in the Room
----------------------------------------------------------------------------------------------------
* The European Data Protection Board is an independent body established under Article 68 of the General Data Protection Regulation. The EDPB is composed of the heads of the supervisory authorities of each Member State and the head of the European Data Protection Supervisor. Among others, the EDPB is given the task to issue guidelines, recommendations and best practices to encourage consistent application of the GDPR.
** REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
*** Guidelines on consent under Regulation 2016/679 (WP259.01) adopted on November 28th, 2017, last revised and adopted on April 10th, 2018 by the Working Party set up under Article 29 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995.
**** See for example Judgment of the Court of 1 October 2019 in Case C 673/17, Bundesverband der Verbraucherzentralen und Verbraucherverbände — Verbraucherzentrale Bundesverband eV v Planet49 GmbH.
***** For information regarding the proposal for the so-called e-Privacy Regulation see Procedure 2017/0003/COD: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications).