window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('js', new Date()); gtag('config', 'G-G54KGC74HV');

Personal data: the storm rumbles

2025-03-19T11:24:44+01:00

Part two: Services funded by targeted advertising

A powerful search engine, an email service with generous storage space, a social network that allows instant interaction with photos and videos from around the world: these are all kinds of services that Internet users have grown accustomed to enjoying without spending a cent. Behind the sleek interfaces offered by the Silicon Valley giants are hidden batteries of servers, lined up as far as the eye can see, and armies of engineers: consumers are confusedly aware of that. Someone has to pay for all this, and they know it. « There ain’t no such thing as a free lunch, » and « if it’s free, you’re the product, » they’ve heard it said. But after all, radio stations and most television channels have been financed by advertising for a long time. It’s easy to imagine that online, the same supposedly harmless mechanisms are at work, in a version that is just a little more modern, a little more efficient.

But traditional media have only been using « contextual » advertising: advertisers take into account the program in which their promotional content takes place. The Saturday night soccer audience is not the same as the Sunday morning cartoon audience, and the products that can be expected to sell to them must be tailored accordingly. The same mechanism does exist online, but it is in the minority. The dominant advertising model is, by far, personalized advertising, which is based on an intimate knowledge of each and every Internet user: their age, their socio-professional category, their family situation, their interests. This type of advertising is more effective and much more lucrative. In France, the television industry is in the process of converting to it: Internet boxes and connected screens now offer the technical means to do so. A new window will open on the enchanted world of personalized marketing.

The « free service vs. targeted advertising » business model thus appears at the height of its glory. However, it is possible that this is only an illusion. The very powerful processing of personal data that this business model requires is in conflict with the General Data Protection Regulations and the Electronic Communications Directive (e-privacy). Simple setback or real threat? The question must be asked.

In January 2019, in the « Android » case, the French National Commission on Informatics and Liberty (CNIL) imposed on Google an administrative fine of 50 million euros (our comment here). Two reproaches were mainly addressed to the company. The first was the insufficient clarity of its privacy policy. For Google, the injury was superficial: such a document can always be improved. The second criticism was that it had based its data processing for targeted advertising on the « consent » of users. When an Internet user would create an account, Google would postulate that the user had accepted the advertising tracking through a pre-ticked box, and it was the user’s responsibility to indicate his or her possible refusal with a click: this was an opt-out system. Heavily relying on the notion of consent defined in the GDPR as « a clear positive act », the CNIL required an opt-in system be put in place. The giant of Moutain View was now supposed to leave the box empty. Therefore, if the Internet user, out of disinterest or out of genuine choice, would scroll through the phases of the registration process without asking to be watched, goodbye revenue from targeted advertising. This was a terrible blow. In this case, the company escaped further condemnation only because it managed to take refuge in Ireland, like many other large American corporations, as explained here.

In December 2020, the CNIL went back at it again. In the specific field of cookies, the CNIL mostly relied on the e-privacy directive rather than the GDPR. In this case, the CNIL did not need to cooperate with the Irish authorities and was able to act as a maverick. It imposed a fine of 100 million euros on Google. During a visit to Google Search, several shortcomings had been observed: the cookie banner was obscure, and one would search in vain for a button that would simply refuse to download files on the terminal. Even before the user had expressed his or her choice, some cookies had already been downloaded. Even if the user had managed to opt for refusal, it was not properly taken into account. This behavior probably owed nothing to chance: here again, the company did not seek to sincerely collect the opinion of Internet users, but to defend its business model.

At this point, a morally comfortable posture is to describe these decisions as a victory of good over evil. But is it really consistent to have allowed the « free service vs. targeted advertising » business model to develop, and then to suddenly assert that exposure to advertising must be a matter for the individual free will of each user? It is absurd to propose to customers to pay the price of a commercial service only if « this is their choice ». Whoever asks the question « will you pay me? » will inevitably cover their ears if someone tries to say « no »: hence the convoluted interfaces, the labyrinthine cookie strips, and the « dark patterns ».

Some then imagined basing the treatment not on the « consent » of the person but on the « necessity for the performance of the contract« . The idea, while controversial, is the following: a web user is indeed bound by a synallagmatic contract. The service is provided to the user in exchange for his or her exposure to targeted advertisements. The argument seems to have been raised by Facebook in its case against Max Schrems’ association None of Your Business.

Readers interested in this argument, and more generally in the issues discussed in this post, may wish to refer to the open access article « Free online service versus targeted advertising: the business model with feet of clay » (only in French for the time being).

Suggested citation: Netter Emmanuel, Personal data: the storm rumbles, Blog of the LexTech Institute, 1st March 2021

Données personnelles : l’orage gronde

2021-06-03T10:13:50+02:00

Première partie : les transferts internationaux de données personnelles

L’autrichien Max Schrems n’est encore qu’un étudiant en droit lorsque débute son long combat pour obtenir de l’entreprise Facebook qu’elle applique correctement la législation européenne en matière de protection des données personnelles. Alerté par les révélations d’Edward Snowden sur les pratiques de surveillance de la NSA, il va notamment contester en 2013 la possibilité pour le réseau social d’exporter des données vers les États-Unis.

En 2015, il obtient une victoire au retentissement mondial devant la Cour de justice de l’Union européenne (CJUE). Les États-Unis étaient jusqu’alors considérés comme un pays présentant un « niveau de protection des données adéquat » à chaque fois que l’entité américaine importatrice d’informations s’était pliée aux exigences d’un programme du Département du commerce américain appelé le « Safe Harbour ». La CJUE estime que la Commission a sous-estimé les risques que la législation antiterroriste américaine fait courir aux données des européens. Elle annule la « décision d’adéquation », remettant en cause la possibilité pour des milliers d’entreprises d’envoyer des informations personnelles outre-Atlantique.

Toutefois, les USA mettent sur pied un remplaçant au Safe Harbour, le « Privacy Shield », supposé garantir de manière plus efficace les droits des citoyens de l’Union. Max Shrems, qui a entre-temps fondé la très active association None of Your Business (NOYB) forme un nouveau recours. La CJUE se prononce à l’été 2020, dans un arrêt « Schrems 2 ». Elle constate que le Foreign Intelligence Service Act et l’Executive Order 12333 n’encadrent pas de manière suffisamment étroite les programmes de surveillance américains (§184), et annule une nouvelle fois la décision d’adéquation de la Commission.

En Suisse, le Préposé fédéral à la protection des données et à la transparence procède en septembre 2020 à son examen annuel de l’accord Swiss – US Privacy Shield et estime à son tour que le « bouclier » n’offre pas une protection adéquate. Il rappelle toutefois que « il n’existe en Suisse aucune jurisprudence comparable à celle de l’arrêt précité de la CJUE. Les tribunaux suisses, en se fondant sur l’art. 6 de la LPD suisse, pourraient arriver aux mêmes conclusions concernant l’accès aux données par les autorités américaines que la CJUE en application du RGPD, mais cette question reste à ce jour ouverte ».

L’Europe, en revanche, bascule dans l’inconnu. Certes, le Règlement général sur la protection des données prévoit qu’en l’absence de décisions d’adéquation, les transferts vers un pays tiers sont néanmoins possibles sur la base de « garanties appropriées » (article 46). En particulier, il reste théoriquement possible de recourir aux « clauses contractuelles types de la Commission européenne » (CCT), un ensemble de stipulations qu’il faut insérer dans une convention conclue entre l’entité européenne exportatrice de données et l’entité étrangère importatrice. Mais que peut faire un simple « RGPD miniature » de nature purement contractuelle, placé bien bas dans la hiérarchie des normes, contre une législation antiterroriste trop puissante ? « Rien », est-on tenté de répondre. La CJUE explique plus sobrement que c’est au duo exportateur-importateur de données qu’il convient d’étudier, ensemble, si la protection conférée aux données par l’instrument contractuel est suffisante (§141). Un tel audit global des législations en cause apparaît hors de portée de beaucoup de responsables de traitement, supposés réussir là où les puissants services de la Commission européenne ont échoué. Si la protection apportée par les CCT apparaît trop faible, il leur faudra alors recourir à « mesures supplémentaires » dont on peine à apercevoir la nature et, si cela n’est toujours pas suffisant, il sera obligatoire de suspendre le traitement (§113).

Il faut bien comprendre que les transferts de l’UE vers les USA ne sont pas les seuls menacés, au terme de ce raisonnement. L’arrêt rappelle une nouvelle fois que les décisions d’adéquation de la Commission sont susceptibles d’être annulées par le juge européen : il pourrait en aller ainsi, demain, pour l’Argentine, la Nouvelle-Zélande ou le Japon. Mais l’essentiel des pays tiers n’a bénéficié à aucun moment d’une décision d’adéquation. Pour eux, l’essentiel des transferts a lieu sur la base de CCT, qui ressortent incroyablement fragilisées de la décision Schrems 2. C’est donc la capacité de l’Europe (et peut-être de la Suisse) à faire circuler des données personnelles à l’échelle mondiale qui est potentiellement compromise. Or, de nombreux flux internationaux économiques, sociaux et culturels requièrent la circulation d’informations personnelles.

Cette situation en apparence ubuesque est en réalité logique. La CJUE est suffisamment indépendante pour obliger l’Union à tirer toutes les conséquences des règles de protection des données dont elle s’est dotée. Des dossiers dans lesquels la Commission européenne adopte une attitude teintée de réalisme politique, de volonté de préserver les intérêts économiques des États-membres et de diplomatie sont approchés par le juge européen sous le seul angle du droit. Il est vrai qu’il y avait peu de sens à fixer un niveau élevé de protection des données dans l’ordre interne, si la vie privée des européens pouvait ensuite être compromise sitôt franchies les frontières de l’Union : de là viennent les règles sévères encadrant les exports. Mais surgit alors une réalité crue : tous les pays du monde n’entendent pas suivre le modèle européen de protection des données, ni même veiller suffisamment au respect des informations des européens. La suite du dossier apparaît alors au moins aussi politique que juridique. Des négociations difficiles s’annoncent, avec les USA et bien d’autres.

En attendant, l’heure va bientôt sonner pour les autorités de protection des données d’ordonner les premiers arrêts de transferts transatlantiques, dans le dossier Facebook et ailleurs. Si elles reculent, elles risquent leur crédibilité. Si elles agissent, le grand public découvrira, médusé, un dossier dont il semble n’avoir pour l’heure aucun écho. L’orage gronde, et la foudre pourrait bientôt tomber.

Aller en haut