Wednesday

4th Oct 2023

Opinion

'Consent' - the good, the bad and the ugly in e-privacy regulation

  • Rules are now tighter in the EU and beyond, businesses and public authorities are sweating to be compliant.

Trying to link a spaghetti western with digital privacy might seem as a stretch: but in Europe, we are reaching the climactic showdown of how to efficiently protect privacy online, without hampering innovation and our continent's global competitiveness.

Just two weeks ago, the EU's famous General Data Protection Regulation (GDPR) entered into application.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

Rules are now tighter in the EU and beyond, businesses and public authorities are sweating to be compliant.

But GDPR is not enough for the EU legislator: a new ePrivacy Regulation is on its way and will impact the European digital economy even more.

Telecoms ministers have a choice: either they can decide to reinvent the wheel of GDPR, and fall prey to a supposed silver bullet – consent. Or they decide to go for common sense, and move the discussion in a sensible realistic direction. We are not there yet.

According to some, the silver bullet that will save our privacy is consent.

I agree that consent is important to empower citizens when their personal data are used. I need to know and agree that my personal data are processed to receive promotional offers from my favourite shop for example.

But similarly as in the famous face-off in Sergio Leone's film, what is crucial is not the plain action itself but the way in which the scene unfolds.

Consent has to resonate to be meaningful and to be valid. And it should be used where the risks for the individual are high, where the protection is most at stake. This is good.

But if consent is used for everything and excessively, it devalues consent. This is bad.

I lost count of the number of emails and messages I received in the past weeks asking me to re-consent in view of GDPR.

How many times have you actually read the entire 17,000-word privacy notice before agreeing to share your data? Do you feel more or less protected by clicking 'yes'?

Will the connected car only drive if the owner is constantly pressing buttons on their dashboard to consent to various data-based operations, like communicating with the road infrastructure or the car ahead?

In the EU, we aimed at creating a true culture and awareness of privacy protection through the GDPR. It will protect citizens from data scandals like the recent Facebook/Cambridge Analytica case – ePrivacy is not relevant here as we have all the protection and sanction tools we need with GDPR.

Proper enforcement of existing rules is needed – not always new laws. GDPR is an important step forward, it is being copied world-wide and is a real improvement for EU citizens and companies.

We should be proud of that achievement even if I would have wished for less constraints on our economic actors.

The GDPR insists on the fact that consent is only one way of protecting an individual's data. It recognises that it is not appropriate in all situations. Yet in the currently negotiated ePrivacy Regulation, we risk undermining that pragmatic approach. This is ugly.

Where the GDPR puts consent in a broader context tied to a risk-assessment, the new ePrivacy Regulation elevates consent into an "all or nothing" approach. This is all the more surprising as EU regulators seemed to have recognised that clicking endless cookie-banners online does not lead to more privacy.

Cost/benefit analysis

Instead we should orient the ePrivacy Regulation along the real question: what is the true risk or potential harm for the individual when using innovative services?

The GDPR gives us many tools that should be part of ePrivacy, as they sit more comfortably with new technologies: concepts such as transparency, data sovereignty, opt-out solutions, right to object and innovative privacy-protective measures like pseudonymisation or encryption. These ensure that companies are held accountable – together with the fines – depending on the data-intensity of their business operations.

Let's focus again on the assessment of the risks and potential harms: this is what we want to prevent. Consent can be a silver bullet – so let's not overshoot but use it wisely.

EU ministers in Council have a chance to make the text future-proof.

I call on them to ensure we are not deceiving our citizens and stakeholders. We are dishonest if we promise our citizens that consent always gives them control over their personal data and their privacy.

If badly implemented – as seen in the Facebook/Cambridge Analytica case - it does the opposite: consent leaves little for the individual to remedy. As a user, I have effectively given away my control rather than to retain it.

It can become a boomerang bullet.

Axel Voss is a German MEP with the CDU, part of the European People's Party

Disclaimer

The views expressed in this opinion piece are the author's, not those of EUobserver.

GDPR - a global 'gold standard'?

The new EU privacy rules are touted as a global 'gold standard' - but Mexico's former data commissioner warns some nations are far from ready.

New GDPR enforcer says complaints imminent

The European Data Protection Board is a new EU body tasked with enforcing the EU's privacy laws with powers to impose massive fines. Its head Andrea Jelinek told reporters complaints against companies are expected to be immediate.

Analysis

GDPR does not (yet) give right to global oblivion

The 'right to be forgotten' will become enshrined in EU law on Friday, but it is not yet clear to what extent it will apply. Will the EU's law determine how the internet looks globally?

Are EU data watchdogs staffed for GDPR?

The success of the new general data protection regulation (GDPR) will depend on whether data protection authorities enforce the new rules - which, in turn, will be at least partly determined by how many people they employ.

France 'got its way' as Portugal ends e-Privacy deadlock

EU ambassadors reached a compromise on the e-Privacy reform after four years of deadlock, paving the way for trialogue negotiations. But the text was slammed for allowing "mass surveillance" under national data-retention laws, a crucial win for France.

Brussels Bytes

The EU cannot shape the future of AI with regulation

If the EU continues to over-regulate AI, its AI systems will fail to compete on a global scale and the technology's long-term future, for better or worse, will be shaped by the United States and China.

Column

Northern Europe — the new Nato/Russia frontline

The world has changed, not least in northern Europe, which is rapidly becoming one of the new frontlines between Nato and Russia. It is sometimes said that even the largest avalanche is caused by something small. Watch Northern Europe

Latest News

  1. Migration: Let us put the 'pull factor' myth finally to rest
  2. EU demands 'full clarity' from Warsaw on visa-scandal
  3. EU reveals 10 'critical tech' in bid to de-risk from China
  4. EU Commission at a loss over latest snub from Tunisia
  5. Northern Europe — the new Nato/Russia frontline
  6. The EU-Kenya free trade deal shows a waning 'Brussels effect'
  7. Hoekstra pledges to phase-out fossil fuel subsidies
  8. 10 years on from the Lampedusa shipwreck — what's changed?

Stakeholders' Highlights

  1. Nordic Council of MinistersThe Nordic Region is stepping up its efforts to reduce food waste
  2. International Medical Devices Regulators Forum (IMDRF)Join regulators, industry & healthcare experts at the 24th IMDRF session, September 25-26, Berlin. Register by 20 Sept to join in person or online.
  3. UNOPSUNOPS begins works under EU-funded project to repair schools in Ukraine
  4. Georgia Ministry of Foreign AffairsGeorgia effectively prevents sanctions evasion against Russia – confirm EU, UK, USA
  5. International Medical Devices Regulators Forum (IMDRF)Join regulators & industry experts at the 24th IMDRF session- Berlin September 25-26. Register early for discounted hotel rates
  6. Nordic Council of MinistersGlobal interest in the new Nordic Nutrition Recommendations – here are the speakers for the launch

Stakeholders' Highlights

  1. Nordic Council of Ministers20 June: Launch of the new Nordic Nutrition Recommendations
  2. International Sustainable Finance CentreJoin CEE Sustainable Finance Summit, 15 – 19 May 2023, high-level event for finance & business
  3. ICLEISeven actionable measures to make food procurement in Europe more sustainable
  4. World BankWorld Bank Report Highlights Role of Human Development for a Successful Green Transition in Europe
  5. Nordic Council of MinistersNordic summit to step up the fight against food loss and waste
  6. Nordic Council of MinistersThink-tank: Strengthen co-operation around tech giants’ influence in the Nordics

Join EUobserver

Support quality EU news

Join us