- Embedding social plugins (e.g. Facebook Like) makes the website operator jointly responsible with the plugin provider for data collection and transmission.
- Joint controllers must conclude an Art. 26 GDPR agreement; transfer requires an independent legal basis or, if applicable, consent.
In the present case, the ECJ has Judgment C‑40/17 of July 29, 2019 i.S. Fashion ID again expressed its opinion on joint responsibility. This is already the third ruling on joint responsibility in the past year:
- Judgment C‑210/16 dated June 5, 2018 i.S. Facebook Fanpages/Wirtschaftsakademie Schleswig-Holstein GmbH (we have reports);
- Judgment C‑25/17 of July 10, 2018 i.S. Jehovah’s Witnesses.
In the present decision upon submission of the Higher Regional Court (OLG) Düsseldorf was about the integration of the “Like” button of Facebook on the website of Fashion ID. The Consumer Center NRW had against Fashion ID sued. Facebook was a party to the proceedings before the OLG joined as an intervening party (Nebenintervenientin).
In a nutshell:
- Anyone who integrates a social plugin into their website that transmits visitors’ personal data to the provider of the plugin is jointly responsible for this collection and transmission of data with the provider. Both must enter into an agreement within the meaning of Art. 26 GDPR close
- Both, the operator of the website and the provider of the plugin, need a legal basis for the joint processing.
- If consent is required, it is the responsibility of the website operator to obtain it.
- The operator of the website is also obliged to inform about the process of collection and transmission in the sense of Art. 12 ff. GDPR to inform.
- The ECJ reinforces its pro-data protection stance. The concept of shared responsibility takes on even greater significance. At the same time, it becomes more difficult and costly to handle due to its strong reference to individual cases.
- The question of whether the transfer of data to a joint controller is privileged – i.e., permitted without a special legal basis – is not conclusively clarified. However, the risk that a separate legal basis is required has increased significantly.
Facts
The ECJ based its decision on the following facts:
- Fashion ID had its website the Social plugin “Like integrated by Facebook. When visiting the website, the visitor’s browser loads, among other things, the plugin and thus content from the Facebook server. Through this process, the visitor’s browser transmits certain information, including the IP address of the end device, the visit to the website in question, technical information and information about the requested content. Facebook itself says the following about this, by the way – but the ECJ did not refer to this source:
“If a person has visited Facebook and then visits your website with a social plug-in, the browser sends this information to usto load Facebook content on this page. The data we receive includes information such as the person’s user ID, the web page visited, the date and time, and other browser-related information. We record some of this information and may use it to, improve our products and services, and show users more interesting and relevant ads.”
- The operator of the website cannot influence the scope of the data transmitted to Facebook.
- In this specific case, at least, the data was transmitted even if the visitor neither has a Facebook account nor clicks on the Like button.
Concept of shared responsibility
Against this background, the OLG the question,
(2) In a case such as the present, in which someone embeds a program code in his website which causes the user’s browser to request content from a third party and, for that purpose, to transmit personal data to the third party, is the embedder the ‘controller’ within the meaning of Article 2(d) of Directive 95/46 if he cannot himself influence that data processing operation?
The legal definition of “responsible person” differs according to the here relevant Directive and Art. 4 No. 7 GDPR not relevant. In this respect, this ruling – like the earlier rulings mentioned at the beginning – is relevant for the GDPR directly relevant, which is also the case, for example, with the Hamburg data protection authority held.
The ECJ answered the question in the affirmative:
[…] the operator of a website […] that embeds a social plugin in this website that causes the browser […] to request content from the provider of this plugin and for this purpose to transmit personal data of the visitor to this provider, [can] be considered as for processing Responsible […] be considered […]. However, this responsibility is limited to the operation or operations of data processingfor which it actually decides on the purposes and means, i.e. the collection of the data in question and their disclosure by transmission.
In doing so, the ECJ takes its judgments regarding Facebook fan pages and Jehovah’s Witnesses as a starting point:
- The aim of the legal definition is, among other things, to ensure “effective and comprehensive protection” of the persons concerned, which requires a broad interpretation.
- Anyone who “exercises an influence over the processing of personal data on grounds of his or her own interests” and thus “takes part in the decision regarding the purposes and means of such processing” is a controller (Jehovah’s Witnesses, para. 68).
- Joint responsibility does not require that each person responsible has access to the data in question (Facebook Fanpages, para. 69).
- “Joint” accountability does not mean “equal” accountability. At the same time, a “processing” may involve several operations. Data controllers may therefore be involved in a data processing operation “at different stages and to different extents.” The scope of accountability can therefore only be determined on a case-by-case basis (Jehovah’s Witnesses, para. 66):
“74 It follows […] that a […] person […] can only be jointly responsible with others for processing operations […] the purposes and means of which he decides – jointly with others. By contrast,[…] that […] person cannot be considered responsible within the meaning of this provision for operations upstream or downstream in the processing chain for which he determines neither the purposes nor the means.”
From this, the ECJ concludes that Fashion ID
- is responsible for collecting the visitors’ data and transmitting it to Facebook,
- but not for downstream processing operations by Facebook.
For the collection and transmission is Fashion ID then jointly responsible with Facebook, because both decide jointly on the means and purposes of these processing operations:
- Medium: Fashion ID binds the button in knowledge that this serves for the collection and transmission. In addition, Fashion ID thereby “decisively the collection and transmission of personal data of the visitors of this site” to Facebook “.Influences”.
- Purposes: Facebook uses the data collected to optimize the advertising of Fashion ID. In return, Facebook can use the collected data “for their own commercial purposes.” This Exchange ratio of economic interests means that both parties “jointly decide on the purposes of the operations of collection of the personal data at issue in the main proceedings and disclosure by transmission”.
As a result, the joint responsibility in this regard was to be affirmed. That Fashion ID cannot access the collected data itself does not preclude this according to Facebook Fanpages case law, which the ECJ confirms again here.
Interim result
The ruling initially has the following implications:
- Anyone who embeds a Facebook Like button is jointly responsible with Facebook. The same applies to all other social plugins where the provider of the plugin receives personal data when they are integrated or triggered.
- The operator of the website and the provider of the plug-in must therefore enter into an agreement within the meaning of Art. 26 GDPR close
- The relevant data protection statements must be supplemented accordingly, in particular to include the fact of joint responsibility and the essence of the agreement.
The following also follows from the ECJ’s decision:
- Shared responsibility is about the common determination of the purposes and means of a processing operation or parts thereofi.e., of individual processing operations. No role is played (unfortunately; they would be exciting) by the questions of how an individual operation is to be distinguished from a processing operation, what a “purpose” is in the first place, and whether an operation – in the sense of a part of a processing operation – can have its own purpose.
- To understand what “Influencing the means of processing” in concrete terms, the judgment contributes little. In the present case, the means of processing (collection and transmission) was the integration of the plugin, and here the ECJ is satisfied with the statement that Fashion ID has integrated the plugin in the knowledge that data will be transmitted to Facebook as a result. What constitutes a “means of processing” and a relevant “influencing” of the means in other constellations is not clear from this. At least, however, it becomes clear that Knowledge about the processing is required, i.e. knowledge of the relevant transaction. What the ECJ implicitly assumes is the involvement of Facebook in this means. The involvement probably lies in the fact that Facebook makes the plugin available and, when it is used, allows the data connection with its server and obtains personal data in the process.
- Interesting are the execution to the common purpose. Fashion ID wants its advertising on Facebook to be played out to specific target groups, which is also in Facebook’s interest, and at the same time Facebook wants to use the data for further purposes (not elaborated here). The ECJ therefore assumes the economic connection of the purposes from and subsequently treats both purposes as one single but common purpose.
The following, more general, points arise from the ruling:
- The ECJ continues its strong privacy-friendly case law – unsurprisingly – continued. Not only in this point the judgment reminds of the decision i.S. Google Spain (there the question was different, but the statements of the ECJ (“[…] it is unacceptable that the processing of personal data […] be deprived of the obligations and safeguards provided for in Directive 95/46, which would limit the practical effectiveness of the Directive and the effective and full protection of the fundamental rights and freedoms of natural persons which it seeks to ensure […]”). remain valid). The ultimately economic approach was also a decisive factor in the Google Spain case. The ECJ is obviously concerned with helping data protection to achieve a breakthrough in the concrete economic circumstances, without dogmatic questions playing a major role. Conversely, it follows that supervisory authorities must pay attention to effective protection in their activities and should not give much weight to violations of formalities, insofar as these do not increase the risks for the data subjects.
- Shared responsibility is not an academic concept, but a Core element in determining responsibility, the in all compliance measures (e.g., processing directory; contract design with service providers and partners in the Group and with outsiders; communication with data subjects; data subject rights; planning of security measures; liability regulations, etc.) must be taken into account.
- The determination of joint responsibility is Strongly case-by-caseand not only the question of when such a contract exists, but above all the question of how far it extends. In the intra-group relationship, this leads to the fact that the work with contract templates is made more difficult and that templates may have to be supplemented with corresponding instructions and assistance. The granularity of consideration – joint responsibility related to individual, concretely determined elements – can also lead to two or more parties wearing multiple hats on a single project.
- The importance of joint responsibility combined with the case-by-case approach and with the different legal consequences depending on the qualification of the party roles has the potential, especially the The handling of personal data within the Group is considerably more complex. to make.
Legal basis: no privilege (?)
The comments on the legal basis are interesting and also point beyond the specific case. The OLG Düsseldorf had asked whether a possible examination of the legal basis of the legitimate interests should be based on the legitimate interest of this operator or the legitimate interest of the said provider (whether consent is required on the basis of the Cookie Directive was left open by the ECJ in this context; the OLG Düsseldorf have to examine). Here, the ECJ said the following:
As […] the operator of a website who embeds a social plugin in this website, which causes the browser of the visitor of this website to request content from the provider of this plugin and to transmit personal data of the visitor to this provider for this purpose, together with this supplier as […] Responsible can be considered, it is necessary that each of these controllers has a legitimate interest in these processing operations. […] perceives, so that these processes can be justified for each of them are.
According to the ECJ, the operations must be the joint responsibility of both parties – the collection and transmission – i.e. for each individual be justified. Taking this statement at face value, this involves a contested Question decided: the data transfer of one controller to the other joint controller (unlike that of a controller to its processor) is Not privilegedbut needs a legal basis just like the transfer to an independent controller.
Whether the ECJ really meant to say this, however, is an open question. The recitals do not indicate that the ECJ was aware of the possible significance of these statements. On the other hand, the ECJ’s statements can hardly be read as if it had considered privileging. After all, it does not speak of Facebook for the following processing in its own responsibility need its own legal basis (which is true, of course); rather, it already needs the transmission as such a legal basis. As a result, privileging is not off the table; relying on it, however, has become riskier.
What the ECJ not said (contrary to some Comments to the judgment): that here a Consent would have been required. The ECJ only says that it is up to the operator of the website to if necessary It is the responsibility of the data controller to obtain consent, as this would have to be obtained prior to the collection and transmission of the data. It becomes the responsibility of the OLG Düsseldorf remain to examine a consent requirement.
More points
The ECJ noted the following additional points:
- The Duty to inform within the meaning of Art. 13 f. GDPR must be fulfilled immediately, i.e. at the time of collection, not later (at least this is how paras. 102 f. can be read).
- A national regulation that Consumer protection associations a right of action against data privacy violators does not violate the Directive.