How digital marketing companies should act in light of the privacy protection regulation (GDPR)

By: Yoram Lichtenstein, Adv. CIPP/E certified in European Privacy and Data Protection.

A relatively new decision (from November 9, 2018) by the French Data Protection Authority (the CNIL) should draw the attention of every agency and digital marketing company. This is a move intended to serve as a deterrent to digital advertising agencies. The decision gives “teeth” and validity to the GDPR regulations (General Data Protection Regulation in Europe). This does not involve a substantial fine imposed on an advertising agency in France due to non-compliance with the regulations.

General Data Protection Regulation symbol highlighting privacy compliance for digital marketers

Before I continue, I would like to draw your attention to the fact that the European Data Protection Board (EDPB) has very recently issued guidelines (not yet finalized) that broaden our understanding of how the–GDPR also applies to non-European companies and/or activities. It is important that we get to know them.

The French agency Vectaury purchased online advertising media for its clients. The agency offered clients the option to integrate an SDK into their applications to help collect various data from their users—the clients’ users. The SDK collected data from users’ devices even when the app was not active. The collected data included device identifiers, browser identifiers, geolocation data, and behavioral data from specific devices. It is important to note that the applications (in which the SDK was embedded) were operated by the agency’s clients, not by the agency itself.

The data was transmitted back to the agency, which analyzed it. Based on it, it created unique profiles for each device based on its behavior and various locations. The profile included a lot of private information. For example: what type of device it is (advanced or simple), which specific stores each device visited, when it visited the stores, how long it stayed there, and more. In this way, the company created profiles that mapped customer habits. Based on these, the SDK provided information to targeted advertising platforms.

The CNIL did not like the company’s mode of operation. Following an examination of the matter, it issued a formal warning requiring the company to correct its conduct or face significant fines. In its defense, the company argued before the French Data Protection Authority that the data was collected with the data subjects’ consent. This was not in dispute. However, the CNIL ruled that the manner in which consent was obtained for data collection did not meet the requirements of the GDPR. From this, we learn how European privacy protection authorities view the way users should be notified that data is being collected about them and how their consent should be requested.

Marketing professional reviewing GDPR legal guidelines on a laptop screen
Digital security lock protecting online customer information and marketing data

First and foremost, when a user downloads the mobile app, if they do not receive a clear and unambiguous notice that the app collects location data, this is a violation of GDPR regulations. Furthermore, if the user does not receive proper notice regarding the purposes of data use, who the entity collecting the data is, and to whom the data will be transferred—this is also a violation of the regulations. Although these details were presented in the terms of use document, it was determined that this was not sufficient. This is because the details are disclosed to the user only after the data has already been stored and processed, and not beforehand (as required by European regulations), and not in a sufficiently clear and transparent manner as required.

In addition, it is not possible to use the app without granting permission for data collection, and furthermore—the user cannot withdraw their permission for data collection. Any use of the app automatically transfers data to the company without the option to cancel. This deprives the user of the right of choice and refusal, which must be granted under the GDPR.

Furthermore, it became clear to the European Data Protection Authority that users were not presented with an explanation that the data about them would be used by the system for “real-time bidding and business profiling purposes.” The app used more general phrasing. Therefore, the description of data use was also not clear and granular enough, as required by the regulation.

Another point that arises is the automatic collection of location data by default. This is a step that contradicts the GDPR’s Privacy by Default principle, and therefore this element was also deemed invalid.

The SDK was installed in more than 32,000 applications, and the data collection involved over 42 million device identifiers and geographic data. It was determined that such processing is on a large scale and the risk involved is relatively severe.

In light of the very initial enforcement stages of the GDPR in Europe, a fine was not yet imposed on the agency, but rather it was given a warning and a requirement to remedy the situation within three months.

In addition, the agency was required to delete all data currently in its possession, in light of the flaws in the manner of its collection. It was also required to bring its practices into compliance within three months from the date of the decision; otherwise, fines will be imposed on it.

Business team analyzing privacy regulation compliance strategies in a meeting

This decision is a warning sign and an important milestone for everyone engaged in digital marketing. The decision helps us understand how digital advertising companies and agencies are expected to act regarding notifying users about data collection concerning them, and the method of obtaining their consent for data collection.

It is also important to understand that the digital field and marketing within it are under specific scrutiny by European authorities, and it is recommended not to take this lightly. I would be happy to answer your questions.

A bit about the author: Yoram Lichtenstein, Adv.

Yoram Lichtenstein Law Firm, certified in European Data Protection and Privacy (CIPP-E), is an innovative and professional boutique firm. It prides itself on its ability to find optimal solutions, while maintaining close, personal service, professionalism, and innovation in the fields of Internet law, technology, high-tech, computers, and diverse intellectual property (such as copyright, trademarks, domain names, and e-commerce).

For more information about Yoram Lichtenstein Law Firm

Portrait of internet law expert and blog author Yoram Lichtenstein