Platforms should not confront users with 'binary choice' over personal data use

The EU’s Data Protection Board (EDPB) has told large online platforms they should not offer users a binary choice between paying for a service and consenting to their personal data being used to provide targeted advertising.

In October last year, the social media giant said it would be possible to pay Meta to stop Instagram or Facebook feeds of personalized ads and prevent it from using personal data for marketing for users in the EU, EEA, or Switzerland. Meta then announced a subscription model of €9.99/month on the web or €12.99/month on iOS and Android for users who did not want their personal data used for targeted advertising.

At the time, Felix Mikolasch, data protection lawyer at noyb, said: “EU law requires that consent is the genuine free will of the user. Contrary to this law, Meta charges a ‘privacy fee’ of up to €250 per year if anyone dares to exercise their fundamental right to data protection.”

@krcr@sh.itjust.works
link
fedilink
English
308M

They can put all the ads they want to finance their services, but if they want to use targeted ones, they have to ask for unbiased users consent.

@bleistift2@feddit.de
link
fedilink
English
2
edit-2
8M

I can’t find the word ‘unbiased’ in the GDPR. All it asks for is consent:

  1. Processing shall be lawful only if and to the extent that at least one of the following applies:

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

In the case of facebook, the user gives consent for the purpose of being served targeted advertising in exchange for the provided service.

[Edit:] Found something:

When assessing whether consent is freely given, utmost account shall be taken of whether, […] the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. Article 7, paragraph 4 GDPR

So the question of whether the pay-or-consent model is legal hinges upon the question of whether payment (in any form) is “necessary for the performance of that contract“.

@krcr@sh.itjust.works
link
fedilink
English
4
edit-2
8M

Yes the term is “freely given consent” indeed, but more importantly: Why would you not trust the EU Data Protection Board if they say themselves that consent-or-pay is not okay?

@bleistift2@feddit.de
link
fedilink
English
28M

Suppose non-targeted ads didn’t generate enough revenue. Would it then be legitimate to require facebook to provide their service at a loss?

I would say no. Just as it’s not legitimate for any other business to break the law even if that means they’re not going to be profitable

Create a post

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more…


Check out our website at privacyguides.org before asking your questions here. We’ve tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the “official” Privacy Guides community on Lemmy, which can be verified here. Other “Privacy Guides” communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don’t ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don’t repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don’t abuse our community’s willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

  • 1 user online
  • 1 user / day
  • 26 users / week
  • 68 users / month
  • 410 users / 6 months
  • 1 subscriber
  • 677 Posts
  • 11.2K Comments
  • Modlog