a legal analysis of facebook privacy practices - eema · 2018-11-27 · a legal analysis of...

18
A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for IT & IP Law iMinds EEMA/TrustCore/iMinds, 17 March 2016

Upload: others

Post on 18-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

A legal analysis of

Facebook privacy practices

Brendan Van Alsenoy

Prof. Peggy ValckeKU Leuven Centre for IT & IP Law – iMinds

EEMA/TrustCore/iMinds, 17 March 2016

Page 2: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Privacy is …

“espoused as the most fundamental of rights,

marketed as the most desirable of commodities,

and pronounced dead twice a week.”

Jonathan Franzen, ‘Imperial bedroom’ (1998)

2

Page 3: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Agenda

• Main findings

• Tracking through social plug-ins

• Actions by CBPL

• Impact GDPR

3

Page 4: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Main findings

Page 5: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Main findings

• How Facebook combines and shares data

• Privacy settings

• Unfair contract terms

• Location data

• User-generated content

• Data subject rights

• Tracking of (non-)users5

Page 6: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Combining data “cross-everything”

6

Page 7: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Privacy settings

7

Page 8: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Unfair contract terms

8

Page 9: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Tracking through social

plug-ins

Page 10: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Tracking through social plug-ins

“What’s not to ?”

10

Page 11: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Information received

• Cookies

© Güneş Acar

• URLs of visited webpages

• Other information (IP, browser, OS, …)

11

Page 12: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

“Opt-out”

12

Page 13: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Article 5(3) ePrivacy Directive

• Prior consent unless necessary for

– network communication

– service explicitly requested by user

• WP29 Opinion 4/2012

– OBA requires opt-in, opt-out insufficient

– no exemption for tracking non-users

(“not of any use for non-members”)

13

Page 14: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Actions by CBPL

Page 15: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

CBPL actions

• Recommendation 04/2015

– Facebook

– Website operators

– Internet users

• Litigation

– Trib. Brussels 9 Nov 2015 (injunction)

– Ordinary procedure (users & non-users)

• Common Statement

• Blocking by Facebook 15

Page 16: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Impact of the GDPR

Page 17: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

GDPR

• Consent

– opt-in

– provision of a service dependent on the

consent

• Privacy by design & by default

– increased emphasis on role of

technology

17

Page 18: A legal analysis of Facebook privacy practices - EEMA · 2018-11-27 · A legal analysis of Facebook privacy practices Brendan Van Alsenoy Prof. Peggy Valcke KU Leuven Centre for

Thank you for your attention!

Questions?

[email protected]

www.citip.be