Skip to main content

Facebook Faces Fines Of $268K Per Day For Tracking Non-Users In Belgium


Facebook is facing fines of €250,000 per day unless it alters the operation of tracking cookies in Belgium after a data protection court ruling. Facebook has said it will be appealing.
The court action dates back to June when the country’s data protection watchdog filed a civil suit against Facebook, following a highly critical report of Facebook’s data protection practices which the Belgian DPA commissioned following updates to Facebook’s privacy policy at the start of this year.
At specific issue in this court case: how Facebook deploys tracking cookies and social plug-ins on third party websites to track the Internet activity of users and non-Facebook users. At the time of filing the suit, the Belgian DPA said Facebook had failed to answer questions about how it tracks non-users and what it does with the data it gleans — hence the watchdog’s decision to challenge the company in court. It also said it wanted to seek legal clarity on whether it had jurisdiction.
In seeking to combat the suit, Facebook had argued the Belgian privacy commission had no jurisdiction over its European business, given it is headquartered in Ireland. However the court slapped this down, ruling that Belgian data protection law does indeed apply and that Belgian courts have jurisdiction.
On this point it’s worth noting the Brussels’ court ruling aligns with recent landmark rulings by Europe’s top court, the ECJ, also relating to jurisdiction and data protection — including the so-called right to be forgotten ruling involving Google Spain, and a more recent judgement where the ECJ ruled that the Hungarian data protection authority is able to impose data protection-related fines on a Slovakian website which was offering services in Hungary — because it judged the latter to have some establishment in the country.
Returning to the Belgian data protection case, Facebook has since sought to argue its tracking cookies are an important security measure for users of the site — albeit it has not provided any public comment on how it is proportionate for an online service to systematically track non-users even for, ostensibly, security purposes.
Writing a blog post on the case last month, Facebook’s CSO Alex Stamo claimed: “We use the datr cookie to help differentiate legitimate visits to our website from illegitimate ones.”
“If the court blocks us from using the datr cookie in Belgium, we would lose one of our best signals to demonstrate that someone is coming to our site legitimately. In practice, that means we would have to treat any visit to our service from Belgium as an untrusted login and deploy a range of other verification methods for people to prove that they are the legitimate owners of their accounts. It would also make Belgian devices more attractive to spammers and others who traffic in compromised accounts on underground forums,” he added.
However again the court was again unimpressed by this line of argument. The Belgian DPA says the court found it “not credible” that systematic collection of a tracking cookie each time a social plug-in is loaded on a website should be necessary for the security of Facebook’s services — ergo it dubbed Facebook’s processing of personal data of people who do not have a Facebook account as “disproportionate”.
Facebook had also sought to argue that the data it collected via the datr tracking cookie was not personal data — but rather a means for it to identify a computer — with Stamo claiming “the datr cookie is only associated with browsers, not individual people” and saying: “It doesn’t contain any information that identifies or is tied to a particular person.”
“At a technical level, we use the datr cookie to collect statistical information on the behavior of a browser on sites with social plugins, such as the Like button, to help us distinguish patterns that look like an attacker from patterns that look like a real person,” he added.
Again the court evidently disagreed with this depiction, determining that the info being gathered and processed by Facebook via this cookie is indeed personal data. And — given the lack of consent for Facebook to gather and process the personal data of non-users — the court also judged this to be a “manifest” violation of Belgian data protection, according to the Belgian DPA.

Comments

Popular posts from this blog

Smart savings app Clinc is a new fintech startup from ex-CEO and founder of Numbrs

Last April, Julien Arnold quietly left his role as CEO of Numbrs, the mobile-first banking app he co-founded with Swiss company builder Centralway. Now, almost a year on, he’s on the verge of launching his next project:  Clinc , a mobile app to make it easier to save money for a future purchase or financial rainy day. Using what Arnold describes as a “dynamic intelligence algorithm,” Clinc promises to track your current account spending and analyse the results to find the optimum amount to save each month, which is then automatically deposited into your Clinc savings account underpinned by the startup’s partner bank. The secret sauce, which he won’t go much into detail on, is that the app is dynamic, able to make on-the-fly adjustments to how much you transfer to your savings account based on how your spending has changed or are predicted to change. In other words, Clinc’s central proposition is to help you achieve your financial goals faster. “This is the bigges...

The EHang 184 Is A Human-Sized Drone Taking Off At CES

We’ve seen some pretty cool stuff on day 1 of CES 2016, but probably nothing more eye-catching than the EHang 184, a human-sized drone built by the Chinese UAV company  EHang . Yes you heard right — a giant autonomous drone that fits a human. It’s basically what you would expect to see if someone shrunk you down to the size of a LEGO and stuck you next to a DJI Inspire. Except no one was shrunk, and the giant flying machine was sitting smack in the middle of the CES drone section. EHang, which was founded in 2014 and has raised about $50M in venture fundingto date, was pretty gung-ho about telling everyone at CES that the 184 was the future of personal transport. And for the most part, people were too in awe to question them. But the reality is that the company probably was using the 184 as more of a marketing tool for their standard-sized drones like the  Ghost . Not that we’re saying that the 184 will never be a real thing, just that it probably isn’t co...

Iron Man Galaxy S6 Edge Arrives With An Arc Reactor Charger

Samsung’s  Iron Man-branded Galaxy S6 Edge  arrives tomorrow, with a custom paint job, 64GB of on-board storage and a limited edition wireless charger accessory with an appropriate arc reactor graphic included on top. It ships with a clear cover, too, so you can protect your precious “armor” when ticketing around in the real world. The box it comes in is also red and gold, and there’s a big ol’ Iron Man helmet stencil graphic on the back of the device, too, as well as a software theme to match. I probably would’ve left off the face personally, letting the colors speak for themselves, but this was a partnership with Marvel with the intent of promoting the new Avengers film oversees, so they probably could’ve been a lot less tasteful with the branding overall. The sad news for those of you who were hoping to advertise their Stark fandom on their phones is that availability is listed as only Korea as of tomorrow, with sales beginning in China and Hong Kong...

NVBOTS Wants To Make 3D Printers As Easy As Toasters

Right now 3D printing curriculums, if they exist, are fairly sparse. Putting a two thousand dollar machine in front of a grade schooler usually ends up in a lot of 3D printed Yoda heads and not much education while the learning curve for most 3D design tools is steep. That’s what the founders of NVBOTS, AJ Perez, Forrest Pieper, Christopher Haid, and Mateo Peña Doll, are looking to solve. Their product, the  NVPRO , is a 3D printer with a few interesting features. The two most interesting are the automatic removal system which pops parts off of the build plate when they are done and a built-in print server that allows you to print from any device. This means you can run large batches of prints from different users with each part popping off as its printed. This means a class of students can send jobs to a printer and then pick them up just as they would a laser printer. The printer also supports a central “admin” who can check jobs before they are printed as and offers a ...