Take-Aways (AI)
  • Embed­ding social plug­ins (e.g. Face­book Like) makes the web­site ope­ra­tor joint­ly respon­si­ble with the plug­in pro­vi­der for data coll­ec­tion and transmission.
  • Joint con­trol­lers must con­clude an Art. 26 GDPR agree­ment; trans­fer requi­res an inde­pen­dent legal basis or, if appli­ca­ble, consent.

In the pre­sent case, the ECJ has Judgment C‑40/17 of July 29, 2019 i.S. Fashion ID again expres­sed its opi­ni­on on joint respon­si­bi­li­ty. This is alre­a­dy the third ruling on joint respon­si­bi­li­ty in the past year:

In the pre­sent decis­i­on upon sub­mis­si­on of the Hig­her Regio­nal Court (OLG) Düs­sel­dorf was about the inte­gra­ti­on of the “Like” but­ton of Face­book on the web­site of Fashion ID. The Con­su­mer Cen­ter NRW had against Fashion ID sued. Face­book was a par­ty to the pro­ce­e­dings befo­re the OLG joi­n­ed as an inter­vening par­ty (Neben­in­ter­ve­ni­en­tin).

In a nuts­hell:

  • Anyo­ne who inte­gra­tes a social plug­in into their web­site that trans­mits visi­tors’ per­so­nal data to the pro­vi­der of the plug­in is joint­ly respon­si­ble for this coll­ec­tion and trans­mis­si­on of data with the pro­vi­der. Both must enter into an agree­ment within the mea­ning of Art. 26 GDPR close
  • Both, the ope­ra­tor of the web­site and the pro­vi­der of the plug­in, need a legal basis for the joint processing.
  • If con­sent is requi­red, it is the respon­si­bi­li­ty of the web­site ope­ra­tor to obtain it.
  • The ope­ra­tor of the web­site is also obli­ged to inform about the pro­cess of coll­ec­tion and trans­mis­si­on in the sen­se of Art. 12 ff. GDPR to inform.
  • The ECJ rein­forces its pro-data pro­tec­tion stance. The con­cept of shared respon­si­bi­li­ty takes on even grea­ter signi­fi­can­ce. At the same time, it beco­mes more dif­fi­cult and cost­ly to hand­le due to its strong refe­rence to indi­vi­du­al cases.
  • The que­sti­on of whe­ther the trans­fer of data to a joint con­trol­ler is pri­vi­le­ged – i.e., per­mit­ted wit­hout a spe­cial legal basis – is not con­clu­si­ve­ly cla­ri­fi­ed. Howe­ver, the risk that a sepa­ra­te legal basis is requi­red has increa­sed significantly.

Facts

The ECJ based its decis­i­on on the fol­lo­wing facts:

  • Fashion ID had its web­site the Social plug­in “Like inte­gra­ted by Face­book. When visi­ting the web­site, the visitor’s brow­ser loads, among other things, the plug­in and thus con­tent from the Face­book ser­ver. Through this pro­cess, the visitor’s brow­ser trans­mits cer­tain infor­ma­ti­on, inclu­ding the IP address of the end device, the visit to the web­site in que­sti­on, tech­ni­cal infor­ma­ti­on and infor­ma­ti­on about the reque­sted con­tent. Face­book its­elf says the fol­lo­wing about this, by the way – but the ECJ did not refer to this source:

    If a per­son has visi­ted Face­book and then visits your web­site with a social plug-in, the brow­ser sends this infor­ma­ti­on to usto load Face­book con­tent on this page. The data we recei­ve inclu­des infor­ma­ti­on such as the person’s user ID, the web page visi­ted, the date and time, and other brow­ser-rela­ted infor­ma­ti­on. We record some of this infor­ma­ti­on and may use it to, impro­ve our pro­ducts and ser­vices, and show users more inte­re­st­ing and rele­vant ads.”

  • The ope­ra­tor of the web­site can­not influence the scope of the data trans­mit­ted to Facebook.
  • In this spe­ci­fic case, at least, the data was trans­mit­ted even if the visi­tor neither has a Face­book account nor clicks on the Like button.

Con­cept of shared responsibility

Against this back­ground, the OLG the question,

(2) In a case such as the pre­sent, in which someone embeds a pro­gram code in his web­site which cau­ses the user’s brow­ser to request con­tent from a third par­ty and, for that pur­po­se, to trans­mit per­so­nal data to the third par­ty, is the embedder the ‘con­trol­ler’ within the mea­ning of Artic­le 2(d) of Direc­ti­ve 95/46 if he can­not hims­elf influence that data pro­ce­s­sing operation?

The legal defi­ni­ti­on of “respon­si­ble per­son” dif­fers accor­ding to the here rele­vant Direc­ti­ve and Art. 4 No. 7 GDPR not rele­vant. In this respect, this ruling – like the ear­lier rulings men­tio­ned at the begin­ning – is rele­vant for the GDPR direct­ly rele­vant, which is also the case, for exam­p­le, with the Ham­burg data pro­tec­tion aut­ho­ri­ty held.

The ECJ ans­we­red the que­sti­on in the affirmative:

[…] the ope­ra­tor of a web­site […] that embeds a social plug­in in this web­site that cau­ses the brow­ser […] to request con­tent from the pro­vi­der of this plug­in and for this pur­po­se to trans­mit per­so­nal data of the visi­tor to this pro­vi­der, [can] be con­side­red as for pro­ce­s­sing Respon­si­ble […] be con­side­red […]. Howe­ver, this respon­si­bi­li­ty is limi­t­ed to the ope­ra­ti­on or ope­ra­ti­ons of data pro­ce­s­singfor which it actual­ly deci­des on the pur­po­ses and means, i.e. the coll­ec­tion of the data in que­sti­on and their dis­clo­sure by transmission. 

In doing so, the ECJ takes its judgments regar­ding Face­book fan pages and Jehovah’s Wit­nesses as a start­ing point:

  • The aim of the legal defi­ni­ti­on is, among other things, to ensu­re “effec­ti­ve and com­pre­hen­si­ve pro­tec­tion” of the per­sons con­cer­ned, which requi­res a broad interpretation.
  • Anyo­ne who “exer­cis­es an influence over the pro­ce­s­sing of per­so­nal data on grounds of his or her own inte­rests” and thus “takes part in the decis­i­on regar­ding the pur­po­ses and means of such pro­ce­s­sing” is a con­trol­ler (Jehovah’s Wit­nesses, para. 68).
  • Joint respon­si­bi­li­ty does not requi­re that each per­son respon­si­ble has access to the data in que­sti­on (Face­book Fan­pages, para. 69).
  • Joint” accoun­ta­bi­li­ty does not mean “equal” accoun­ta­bi­li­ty. At the same time, a “pro­ce­s­sing” may invol­ve seve­ral ope­ra­ti­ons. Data con­trol­lers may the­r­e­fo­re be invol­ved in a data pro­ce­s­sing ope­ra­ti­on “at dif­fe­rent stages and to dif­fe­rent ext­ents.” The scope of accoun­ta­bi­li­ty can the­r­e­fo­re only be deter­mi­ned on a case-by-case basis (Jehovah’s Wit­nesses, para. 66):

    74 It fol­lows […] that a […] per­son […] can only be joint­ly respon­si­ble with others for pro­ce­s­sing ope­ra­ti­ons […] the pur­po­ses and means of which he deci­des – joint­ly with others. By con­trast,[…] that […] per­son can­not be con­side­red respon­si­ble within the mea­ning of this pro­vi­si­on for ope­ra­ti­ons upstream or down­stream in the pro­ce­s­sing chain for which he deter­mi­nes neither the pur­po­ses nor the means.”

From this, the ECJ con­clu­des that Fashion ID

  • is respon­si­ble for coll­ec­ting the visi­tors’ data and trans­mit­ting it to Facebook,
  • but not for down­stream pro­ce­s­sing ope­ra­ti­ons by Facebook.

For the coll­ec­tion and trans­mis­si­on is Fashion ID then joint­ly respon­si­ble with Face­book, becau­se both deci­de joint­ly on the means and pur­po­ses of the­se pro­ce­s­sing operations:

  • Medi­um: Fashion ID binds the but­ton in know­ledge that this ser­ves for the coll­ec­tion and trans­mis­si­on. In addi­ti­on, Fashion ID ther­eby “decisi­ve­ly the coll­ec­tion and trans­mis­si­on of per­so­nal data of the visi­tors of this site” to Face­book “.Influen­ces”.
  • Pur­po­ses: Face­book uses the data coll­ec­ted to opti­mi­ze the adver­ti­sing of Fashion ID. In return, Face­book can use the coll­ec­ted data “for their own com­mer­cial pur­po­ses.” This Exch­an­ge ratio of eco­no­mic inte­rests means that both par­ties “joint­ly deci­de on the pur­po­ses of the ope­ra­ti­ons of coll­ec­tion of the per­so­nal data at issue in the main pro­ce­e­dings and dis­clo­sure by transmission”.

As a result, the joint respon­si­bi­li­ty in this regard was to be affirm­ed. That Fashion ID can­not access the coll­ec­ted data its­elf does not pre­clude this accor­ding to Face­book Fan­pages case law, which the ECJ con­firms again here.

Inte­rim result

The ruling initi­al­ly has the fol­lo­wing implications:

  • Anyo­ne who embeds a Face­book Like but­ton is joint­ly respon­si­ble with Face­book. The same applies to all other social plug­ins whe­re the pro­vi­der of the plug­in recei­ves per­so­nal data when they are inte­gra­ted or triggered.
  • The ope­ra­tor of the web­site and the pro­vi­der of the plug-in must the­r­e­fo­re enter into an agree­ment within the mea­ning of Art. 26 GDPR close
  • The rele­vant data pro­tec­tion state­ments must be sup­ple­men­ted accor­din­gly, in par­ti­cu­lar to include the fact of joint respon­si­bi­li­ty and the essence of the agreement.

The fol­lo­wing also fol­lows from the ECJ’s decision:

  • Shared respon­si­bi­li­ty is about the com­mon deter­mi­na­ti­on of the pur­po­ses and means of a pro­ce­s­sing ope­ra­ti­on or parts the­reofi.e., of indi­vi­du­al pro­ce­s­sing ope­ra­ti­ons. No role is play­ed (unfort­u­n­a­te­ly; they would be exci­ting) by the que­sti­ons of how an indi­vi­du­al ope­ra­ti­on is to be distin­gu­is­hed from a pro­ce­s­sing ope­ra­ti­on, what a “pur­po­se” is in the first place, and whe­ther an ope­ra­ti­on – in the sen­se of a part of a pro­ce­s­sing ope­ra­ti­on – can have its own purpose.
  • To under­stand what “Influen­cing the means of pro­ce­s­sing” in con­cre­te terms, the judgment con­tri­bu­tes litt­le. In the pre­sent case, the means of pro­ce­s­sing (coll­ec­tion and trans­mis­si­on) was the inte­gra­ti­on of the plug­in, and here the ECJ is satis­fied with the state­ment that Fashion ID has inte­gra­ted the plug­in in the know­ledge that data will be trans­mit­ted to Face­book as a result. What con­sti­tu­tes a “means of pro­ce­s­sing” and a rele­vant “influen­cing” of the means in other con­stel­la­ti­ons is not clear from this. At least, howe­ver, it beco­mes clear that Know­ledge about the pro­ce­s­sing is requi­red, i.e. know­ledge of the rele­vant tran­sac­tion. What the ECJ impli­ci­t­ly assu­mes is the invol­vement of Face­book in this means. The invol­vement pro­ba­b­ly lies in the fact that Face­book makes the plug­in available and, when it is used, allo­ws the data con­nec­tion with its ser­ver and obta­ins per­so­nal data in the process.
  • Inte­re­st­ing are the exe­cu­ti­on to the com­mon pur­po­se. Fashion ID wants its adver­ti­sing on Face­book to be play­ed out to spe­ci­fic tar­get groups, which is also in Facebook’s inte­rest, and at the same time Face­book wants to use the data for fur­ther pur­po­ses (not ela­bo­ra­ted here). The ECJ the­r­e­fo­re assu­mes the eco­no­mic con­nec­tion of the pur­po­ses from and sub­se­quent­ly tre­ats both pur­po­ses as one sin­gle but com­mon pur­po­se.

The fol­lo­wing, more gene­ral, points ari­se from the ruling:

  • The ECJ con­ti­nues its strong pri­va­cy-fri­end­ly case law – unsur­pri­sin­gly – con­tin­ued. Not only in this point the judgment reminds of the decis­i­on i.S. Goog­le Spain (the­re the que­sti­on was dif­fe­rent, but the state­ments of the ECJ (“[…] it is unac­cep­ta­ble that the pro­ce­s­sing of per­so­nal data […] be depri­ved of the obli­ga­ti­ons and safe­guards pro­vi­ded for in Direc­ti­ve 95/46, which would limit the prac­ti­cal effec­ti­ve­ness of the Direc­ti­ve and the effec­ti­ve and full pro­tec­tion of the fun­da­men­tal rights and free­doms of natu­ral per­sons which it seeks to ensu­re […]”). remain valid). The ulti­m­ate­ly eco­no­mic approach was also a decisi­ve fac­tor in the Goog­le Spain case. The ECJ is obvious­ly con­cer­ned with hel­ping data pro­tec­tion to achie­ve a breakth­rough in the con­cre­te eco­no­mic cir­cum­stances, wit­hout dog­ma­tic que­sti­ons play­ing a major role. Con­ver­se­ly, it fol­lows that super­vi­so­ry aut­ho­ri­ties must pay atten­ti­on to effec­ti­ve pro­tec­tion in their acti­vi­ties and should not give much weight to vio­la­ti­ons of for­ma­li­ties, inso­far as the­se do not increa­se the risks for the data subjects.
  • Shared respon­si­bi­li­ty is not an aca­de­mic con­cept, but a Core ele­ment in deter­mi­ning respon­si­bi­li­ty, the in all com­pli­ance mea­su­res (e.g., pro­ce­s­sing direc­to­ry; con­tract design with ser­vice pro­vi­ders and part­ners in the Group and with out­si­ders; com­mu­ni­ca­ti­on with data sub­jects; data sub­ject rights; plan­ning of secu­ri­ty mea­su­res; lia­bi­li­ty regu­la­ti­ons, etc.) must be taken into account.
  • The deter­mi­na­ti­on of joint respon­si­bi­li­ty is Stron­gly case-by-caseand not only the que­sti­on of when such a con­tract exists, but abo­ve all the que­sti­on of how far it extends. In the intra-group rela­ti­on­ship, this leads to the fact that the work with con­tract tem­pla­tes is made more dif­fi­cult and that tem­pla­tes may have to be sup­ple­men­ted with cor­re­spon­ding ins­truc­tions and assi­stance. The gra­nu­la­ri­ty of con­side­ra­ti­on – joint respon­si­bi­li­ty rela­ted to indi­vi­du­al, con­cre­te­ly deter­mi­ned ele­ments – can also lead to two or more par­ties wea­ring mul­ti­ple hats on a sin­gle project.
  • The importance of joint respon­si­bi­li­ty com­bi­ned with the case-by-case approach and with the dif­fe­rent legal con­se­quen­ces depen­ding on the qua­li­fi­ca­ti­on of the par­ty roles has the poten­ti­al, espe­ci­al­ly the The hand­ling of per­so­nal data within the Group is con­sider­a­b­ly more com­plex. to make.

Legal basis: no privilege (?)

The comm­ents on the legal basis are inte­re­st­ing and also point bey­ond the spe­ci­fic case. The OLG Düs­sel­dorf had asked whe­ther a pos­si­ble exami­na­ti­on of the legal basis of the legi­ti­ma­te inte­rests should be based on the legi­ti­ma­te inte­rest of this ope­ra­tor or the legi­ti­ma­te inte­rest of the said pro­vi­der (whe­ther con­sent is requi­red on the basis of the Coo­kie Direc­ti­ve was left open by the ECJ in this con­text; the OLG Düs­sel­dorf have to exami­ne). Here, the ECJ said the following:

As […] the ope­ra­tor of a web­site who embeds a social plug­in in this web­site, which cau­ses the brow­ser of the visi­tor of this web­site to request con­tent from the pro­vi­der of this plug­in and to trans­mit per­so­nal data of the visi­tor to this pro­vi­der for this pur­po­se, tog­e­ther with this sup­plier as […] Respon­si­ble can be con­side­red, it is neces­sa­ry that each of the­se con­trol­lers has a legi­ti­ma­te inte­rest in the­se pro­ce­s­sing ope­ra­ti­ons. […] per­cei­ves, so that the­se pro­ce­s­ses can be justi­fi­ed for each of them are.

Accor­ding to the ECJ, the ope­ra­ti­ons must be the joint respon­si­bi­li­ty of both par­ties – the coll­ec­tion and trans­mis­si­on – i.e. for each indi­vi­du­al be justi­fi­ed. Taking this state­ment at face value, this invol­ves a con­te­sted Que­sti­on deci­ded: the data trans­fer of one con­trol­ler to the other joint con­trol­ler (unli­ke that of a con­trol­ler to its pro­ces­sor) is Not pri­vi­le­gedbut needs a legal basis just like the trans­fer to an inde­pen­dent con­trol­ler.

Whe­ther the ECJ real­ly meant to say this, howe­ver, is an open que­sti­on. The reci­tals do not indi­ca­te that the ECJ was awa­re of the pos­si­ble signi­fi­can­ce of the­se state­ments. On the other hand, the ECJ’s state­ments can hard­ly be read as if it had con­side­red pri­vi­le­ging. After all, it does not speak of Face­book for the fol­lo­wing pro­ce­s­sing in its own respon­si­bi­li­ty need its own legal basis (which is true, of cour­se); rather, it alre­a­dy needs the trans­mis­si­on as such a legal basis. As a result, pri­vi­le­ging is not off the table; rely­ing on it, howe­ver, has beco­me riskier.

What the ECJ not said (con­tra­ry to some Comm­ents to the judgment): that here a Con­sent would have been requi­red. The ECJ only says that it is up to the ope­ra­tor of the web­site to if neces­sa­ry It is the respon­si­bi­li­ty of the data con­trol­ler to obtain con­sent, as this would have to be obtai­ned pri­or to the coll­ec­tion and trans­mis­si­on of the data. It beco­mes the respon­si­bi­li­ty of the OLG Düs­sel­dorf remain to exami­ne a con­sent requirement.

More points

The ECJ noted the fol­lo­wing addi­tio­nal points:

  • The Duty to inform within the mea­ning of Art. 13 f. GDPR must be ful­fil­led imme­dia­te­ly, i.e. at the time of coll­ec­tion, not later (at least this is how paras. 102 f. can be read).
  • A natio­nal regu­la­ti­on that Con­su­mer pro­tec­tion asso­cia­ti­ons a right of action against data pri­va­cy vio­la­tors does not vio­la­te the Directive.