This month the European Data Protection Board* (EDPB) adopted new Guidelines on consent under the General Data Protection Regulation**, replacing the Guidelines on consent previously adopted by the Article 29 Working Party (WP29) and endorsed by the EDPB***.

The new Guidelines on Consent reaffirm the analysis of the notion of consent given by the WP29 and provide further clarifications with regards to the validity of consent in the digital field especially when it comes to the processing of personal data via cookies and similar technologies on an operator’s website, the interaction of data subjects with the so-called “cookie walls” and the relationship between scrolling and consent. Thus, the paragraphs concerning these issues have been revised and updated, while the rest of the document was left largely unchanged except for editorial redactions.

 

Tear down this cookie wall!

 

No alt text provided for this imageIn the document, the EDPB finds that when faced with the so-called cookie wall, i.e. a pop-up blocking the access of the user to the rest of the operator’s website until such time as the user consents to the use of non-necessary cookies, the user is not provided with a genuine choice whether to allow such processing or not. Thus, in the opinion of the EDPB, such consent does not fulfill the ‘freely given’ criterion under the GDPR which requires access to services and functionalities to not be made conditional on the consent of the user to the storing of information or gaining of access to information already stored in the device of the user.
 

Unbundling of consent with acceptance of website t&c

 

It has been commonly understood among privacy specialists that “bundling” consent with acceptance of terms or conditions is considered highly undesirable. The EDPB now reaffirms this understanding, citing that in no way can blanket acceptance of general terms and conditions be seen as a clear affirmative action to consent to the use of personal data. Where tacit consent such as scrolling-as-consent still lives, it is to finally be retired as well.

 

No opt-out mechanisms and no pre-ticked boxes

 

In a separate paragraph, the EDPB reaffirms that the GDPR does not allow for data controllers to offer pre-ticked boxes or opt-out constructions such as opt-out boxes that require an intervention from the data subject to prevent the use of non-necessary cookies. This requirement will also not in any way surprise those familiar with the recent case-law of the European Court of Justice on cookies****, however, two years after the GDPR becoming effective pre-ticked boxes are still not a view too rarely seen in the universe of cookie consent management panels.

 

The e-Elephant in the Room

 

No alt text provided for this imageNowadays when more and more companies who have traditionally carried their business are challenged to adapt their business to the economic realities of the COVID-19 pandemic, the role of EDPB guidelines, recommendations, and best practices with regards to the application of the GDPR in the digital field has increased immensely. Not only are companies to catch up with the compliance requirements following the digitalization of their business model, but they also have to catch up fast to match the pace of the ever-evolving regulations in the field of digital trade and electronic communications. However, the elephant in the room remains the upcoming e-Privacy regulation***** replacing the 2002 e-Privacy Directive, which will add a new layer of complexity on top of the already sophisticated consumer law and data protection regulations. Thus, traditional companies transitioning to modern business opportunities are to also seek modern compliance solutions.

----------------------------------------------------------------------------------------------------

* The European Data Protection Board is an independent body established under Article 68 of the General Data Protection Regulation. The EDPB is composed of the heads of the supervisory authorities of each Member State and the head of the European Data Protection Supervisor. Among others, the EDPB is given the task to issue guidelines, recommendations and best practices to encourage consistent application of the GDPR.

** REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

*** Guidelines on consent under Regulation 2016/679 (WP259.01) adopted on November 28th, 2017, last revised and adopted on April 10th, 2018 by the Working Party set up under Article 29 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995.

**** See for example Judgment of the Court of 1 October 2019 in Case C 673/17, Bundesverband der Verbraucherzentralen und Verbraucherverbände — Verbraucherzentrale Bundesverband eV v Planet49 GmbH.

***** For information regarding the proposal for the so-called e-Privacy Regulation see Procedure 2017/0003/COD: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications).