{"id":18238,"date":"2023-01-18T12:29:39","date_gmt":"2023-01-18T11:29:39","guid":{"rendered":"https:\/\/www.rosello-mallol.com\/?p=18238"},"modified":"2023-01-18T12:29:43","modified_gmt":"2023-01-18T11:29:43","slug":"meta-sanction","status":"publish","type":"post","link":"https:\/\/www.rosello-mallol.com\/en\/meta-sanction\/","title":{"rendered":"Meta Sanction: how does it affect my company?"},"content":{"rendered":"\n
2023 is starting strong as far as GDPR sanctions are concerned, due to the 390M euros META sanction<\/a><\/strong> imposed by the Irish Authority because of the manner in which it processes its users\u2019 data from<\/strong> Facebook and Instagram<\/strong>.<\/p>\n\n\n\n The sanction, which occurred after the involvement of the European Data Protection Council<\/strong>, has forced the Irish Authority to change its initial criteria and multiply its sanction by 10.<\/p>\n\n\n\n In short, the terms and conditions of META included the fact that data from Facebook and Instagram users<\/strong> could be used for custom advertising purposes and, more importantly, it did not request any specific consent for this purpose, considering this data processing necessary to fulfil the contract (the terms and conditions) accepted by users.<\/p>\n\n\n\n Essentially, they say that receiving custom advertising does not fall within the expectations of users when they register on one of the two social networks, and that their expectation or the service they expect to receive is none other than to communicate with others or to remain informed.<\/p>\n\n\n\n In conclusion, the processing of data for advertising purposes is not part of the service that users expect to receive, so the use of their data for this purpose requires their express and prior consent<\/strong>.<\/p>\n\n\n\n Well, this decision deals with the core of the GDPR<\/strong>, which is none other than what is known as the lawful basis of processing<\/strong>. This is what justifies a company or public authority to process someone’s personal data.<\/p>\n\n\n\n Regarding the lawful bases, some important considerations:<\/p>\n\n\n\n This is how Art 6.1 of the GDPR<\/strong> includes them:<\/p>\n\n\n\n a) the data subject has given consent <\/strong>to the processing of his or her personal data for one or more specific purposes;<\/em><\/p>\n\n\n\n b) processing is necessary for the performance of a contract<\/strong> to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;<\/em><\/p>\n\n\n\n c) processing is necessary for compliance with a legal obligation<\/strong> to which the controller is subject;<\/em><\/p>\n\n\n\n d) processing is necessary in order to protect the vital interests<\/strong> of the data subject or of another natural person;<\/em><\/p>\n\n\n\n e) processing is necessary for the performance of a task carried out in the public interest<\/strong> or in the exercise of official authority vested in the controller;<\/em><\/p>\n\n\n\n f) processing is necessary for the purposes of the legitimate interests<\/strong> pursued by the controller or by a third party, except where such interests are overridden by said interests.<\/em><\/p>\n\n\n\n As indicated, the basis for the META sanction is the use of one lawful basis<\/strong> (compliance with a contract) over another (consent). Undoubtedly, deciding that data processing is justified by the fulfilment of a contract or, in other words, providing a service selected by the user, makes things easier for the company, as express and independent acceptance will not be necessary beyond the terms and conditions.<\/p>\n\n\n\n On the other hand, if we decide that consent is required, the process is complicated because we will have to find a way for the user to accept, regardless of the terms and conditions, the use of their personal data.<\/p>\n\n\n\n Unfortunately the answer is, it depends<\/strong>.<\/p>\n\n\n\n Indeed, we must analyse what is contracted or what expectations the user has<\/strong> when they accept some terms and conditions to decide, from there, what we can do with the data without additional consent. For example: purposes such as receiving the product or providing the service, administrative tasks or guarantee management might imply processing typical of the contract between the company and the user.<\/p>\n\n\n\n From there, apply the criterion of caution: what is not included in the contract or in case of doubt, always request consent. In addition, we must analyse whether any other lawful basis applies, such as legitimate interests<\/strong>, which is analysed in this post<\/a><\/strong>.<\/p>\n\n\n\n As always, use caution and analyse what we want to do with someone’s data before it is collected in order to later avoid problems arising from data collected with insufficient information or without the necessary consent for its use.<\/p>\n\n\n\n If you want or need more information on this topic, contact us!<\/p>\n\n\n\n <\/p> Meta Sanction:<\/strong> Why has been penalised?<\/strong><\/h2>\n\n\n\n
What do the data protection authorities say?<\/strong><\/h2>\n\n\n\n
META Sanction:<\/strong> OK, but how does it affect my company?<\/strong><\/h2>\n\n\n\n
\n
\n
The two conflicting lawful bases: consent and contractual compliance<\/strong><\/h2>\n\n\n\n
What use of data is included in the fulfilment of a contract and what is not?<\/strong><\/h2>\n\n\n\n
<\/ul><\/div>\n