• Skip to primary navigation
  • Skip to main content
  • Skip to footer
  • Home
  • About us
  • Contact Us
  • Our Team

Blockchain Consultants

Blockchain Transformations Done Here

  • News
  • Subscribe
  • Cryptocurrency Exchange

Adtech

GDPR adtech complaints keep stacking up in Europe

May 25, 2019 by Blockchain Consultants

It’s a year since Europe’s General Data Protection Regulation (GDPR) came into force and leaky adtech is now facing privacy complaints in four more European Union markets. This ups the tally to seven markets where data protection authorities have been urged to investigate a core function of behavioral advertising.

The latest clutch of GDPR complaints aimed at the real-time bidding (RTB) system have been filed in Belgium, Luxembourg, the Netherlands and Spain.

All the complaints argue that RTB entails “wide-scale and systemic” breaches of Europe’s data protection regime, as personal date harvested to profile Internet users for ad-targeting purposes is broadcast widely to bidders in the adtech chain. The complaints have implications for key adtech players, Google and the Internet Advertising Bureau, which set RTB standards used by other in the online adverting pipeline.

We’ve reached out to Google and IAB Europe for comment on the latest complaints. (The latter’s original response statement to the complaint can be found here, behind its cookie wall.)

The first RTB complaints were filed in the UK and Ireland, last fall, by Dr Johnny Ryan of private browser Brave; Jim Killock, director of the Open Rights Group; and Michael Veale, a data and policy researcher at University College London.

A third complaint went in to Poland’s DPA in January, filed by anti-surveillance NGO, the Panoptykon Foundation.

The latest four complaints have been lodged in Spain by Gemma Galdon Clavell (Eticas Foundation) and Diego Fanjul (Finch); David Korteweg (Bits of Freedom) in the Netherlands; Jef Ausloos (University of Amsterdam) and Pierre Dewitte (University of Leuven) in Belgium; and Jose Belo (Exigo Luxembourg).

Earlier this year a lawyer working with the complainants said they’re expecting “a cascade of complaints” across Europe — and “fully expect an EU-wide regulatory response” give that the adtech in question is applied region-wide.

Commenting in a statement, Galdon Cavell, the CEO of Eticas, said: “We hope that this complaint sends a strong message to Google and those using Ad Tech solutions in their websites and products. Data protection is a legal requirement must be translated into practices and technical specifications.”

A ‘bug’ disclosed last week by Twitter illustrates the potential privacy risks around adtech, with the social networking platform revealing it had inadvertently shared some iOS users’ location data with an ad partner during the RTB process. (Less clear is who else might Twitter’s “trusted advertising partner” have passed people’s information to?)

The core argument underpinning the complaints is that RTB’s data processing is not secure — given the design of the system entails the broadcasting of (what can be sensitive and intimate) personal data of Internet users to all sorts of third parties in order to generate bids for ad space.

Whereas GDPR bakes in a requirement for personal data to be processed “in a manner that ensures appropriate security of the personal data”. So, uh, spot the disconnect.

The latest RTB complaints assert personal data is broadcast via bid requests “hundreds of billions of times” per day — which it describes as “the most massive leakage of personal data recorded so far”.

While the complaints focus on security risks attached by default to leaky adtech, such a long chain of third parties being passed people’s data also raises plenty of questions over the validity of any claimed ‘consents’ for passing Internet users’ data down the adtech chain. (Related: A decision by the French CNIL last fall against a small local adtech player which it decided was unlawfully processing personal data obtained via RTB.)

This week will mark a year since GDPR came into force across the EU. And it’s fair to say that privacy complaints have been piling up, while enforcement actions — such as a $57M fine for Google from the French CNIL related to Android consent — remain far rarer.

One complexity with the RTB complaints is that the technology systems in question are both applied across EU borders and involve multiple entities (Google and the IAB). This means multiple privacy watchdogs need to work together to determine which of them is legally competent to address linked complaints that touch EU citizens in multiple countries.

Who leads can depend on where an entity has its main establishment in the EU and/or who is the data controller. If this is not clearly established it’s possible that various national actions could flow from the complaints, given the cross-border nature of the adtech — as in the CNIL decision against Android, for example. (Though Google made a policy change as of January 22, shifting its legal base for EU law enforcement to Google Ireland which looks intended to funnel all GDPR risk via the Irish DPC.)

The IAB Europe, meanwhile, has an office in Belgium but it’s not clear whether that’s the data controller in this case. Ausloos tells us that the Belgian DPA has already declared itself competent regarding the complaint filed against the IAB by the Panoptykon Foundation, while noting another possibility — that the IAB claims the data controller is IAB Tech Lab, based in New York — “in which case any and all DPAs across the EU would be competent”.

Veale also says different DPAs could argue that different parts of the IAB are in their jurisdiction. “We don’t know how the IAB structure really works, it’s very opaque,” he tells us.

The Irish DPC, which Google has sought to designate the lead watchdog for its European business, has said it will prioritize scrutiny of the adtech sector in 2019, referencing the RTB complaints in its annual report earlier this year — where it warned the industry: “the protection of personal data is a prerequisite to the processing of any personal data within this ecosystem and ultimately the sector must comply with the standards set down by the GDPR”.

There’s no update on how the UK’s ICO is tackling the RTB complaint filed in the UK as yet — but Veale notes they have a call today. (And we’ve reached out to the ICO for comment.)

So far the same RTB complaints have not been filed in France and Germany — jurisdictions with privacy watchdogs that can have a reputation for some of the most muscular action enforcing data protection in Europe.

Although the Belgian DPA’s recently elected new president is making muscular noises about GDPR enforcement, according to Ausloos — who cites a speech he made, post-election, saying the ‘time of sit back and relax’ is over. They made sure to reference these comments in the RTB complaint, he adds.

Veale suggests the biggest blocker to resolving the RTB complaints is that all the various EU watchdogs “need a vision of what the world looks like after they take a given action”.

In the meanwhile, the adtech complaints keep stacking up.

Read more: https://techcrunch.com/2019/05/20/gdpr-adtech-complaints-keep-stacking-up-in-europe/

Filed Under: blockchain Tagged With: ad tech, Adtech, Android, behavioral advertising, belgium, data controller, data processing, data protection, data security, digital rights, Europe, european union, France, GDPR, General Data Protection Regulation, google, ireland, Johnny Ryan, Netherlands, online advertising, poland, Privacy, Real-time bidding, RTB complaints, spain, United Kingdom

Googles lead EU regulator opens formal privacy probe of its adtech

May 24, 2019 by Blockchain Consultants

Google’s lead data regulator in Europe has opened a formal investigation into its processing of personal data in the context of its online Ad Exchange, TechCrunch has learnt.

This follows a privacy complaint pertaining to adtech’s real-timing bidding (RTB) system filed under Europe’s GDPR framework last year.

The statutory inquiry into Google’s adtech that’s being opened by the Irish Data Protection Commission (DPC), cites section 110 of Ireland’s Data Protection Act 2018, which means that the watchdog suspects infringement — and will now investigate its suspicions.

The DPC writes that the inquiry is “to establish whether processing of personal data carried out at each stage of an advertising transaction is in compliance with the relevant provisions of the General Data Protection Regulation, including the lawful basis for processing, the principles of transparency and data minimisation, as well as Google’s retention practices”.

We’ve reached out to Google for comment. Update: A Google spokesperson said: “We will engage fully with the DPC’s investigation and welcome the opportunity for further clarification of Europe’s data protection rules for real-time bidding. Authorised buyers using our systems are subject to stringent policies and standards.”

As we reported earlier this week complaints about the RTB system used by online advertisers have been stacking up across Europe.

The relevant complaint in this instance was lodged last fall by Dr Johnny Ryan of private browser Brave, and alleges “wide-scale and systemic breaches of the data protection regime” by Google and others in the behavioral advertising industry.

Where Google is concerned the complaint focuses on its DoubleClick/Authorized Buyers ad system.

In a nutshell, the RTB complaints argue the system is inherently insecure — and that’s incompatible with GDPR’s requirement that personal data is processed “in a manner that ensures appropriate security”.

Commenting on the Irish DPC opening an inquiry in a statement, Ryan said: “Surveillance capitalism is about to become obsolete. The Irish Data Protection Commission’s action signals that now — nearly one year after the GDPR was introduced — a change is coming that goes beyond just Google. We need to reform online advertising to protect privacy, and to protect advertisers and publishers from legal risk under the GDPR”.

Similar complaints against RTB have been filed in the UK, Poland, Spain, Belgium, Luxembourg and the Netherlands.

Ireland is leading the investigation of Google’s adtech as the company designates Google Ireland as the data controller for EU users.

Google and IAB ad category lists show ‘massive leakage of highly intimate data,’ GDPR complaint claims

Read more: https://techcrunch.com/2019/05/22/googles-lead-eu-regulator-opens-formal-privacy-probe-of-its-adtech/

Filed Under: blockchain Tagged With: Adtech, GDPR, google, Privacy, rtb

Footer

Get the latest news delivered weekly. Simple as that.

  • Cryptocurrency Exchange
  • About us
  • ANTI-SPAM POLICY
  • Cookies Policy
  • Digital Millennium Copyright Act (DMCA) Notice
  • Earnings Disclaimer
  • Exchanges
  • Our Team
  • Terms of Use

Copyright © 2021 · Blockchain Consultants LLC · WordPress · Log in