behavioral targeting & european la · behavioral targeting & european law w3c workshop: do...

17
Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information Law, University of Amsterdam New York University

Upload: others

Post on 29-May-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

Behavioral targeting & European law

W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012

Frederik Borgesius Institute for Information Law, University of Amsterdam

New York University

Page 2: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

2

Contents

1. Consent for tracking technologies

2. Data protection law and behavioral targeting

3. W3C?

Page 3: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

3

1. Consent tracking technologies

Consent for storing and reading information in device.

Exceptions: necessary for communication / requested service.

Art 5.3 e-Privacy Directive

Page 4: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

4

Contents

1. Consent for tracking technologies

2. Data protection law and behavioral targeting

3. W3C?

Page 5: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

5

2. Right to Data Protection Charter of Fundamental Rights EU

Page 6: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

6

2. EU data protection law & behavioral targeting

Data protection law generally applies to nameless profiles for behavioral targeting.

Page 7: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

7

‘Personal data’ in EU

Any information relating to an identified or identifiable person.

Art. 2(a) Data Protection Directive

Page 8: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

8

Personal data

Page 9: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

9

Personal data

W3C Team, © R. Ishida 2008

Page 10: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

10

Court of Justice EU

IP addresses: personal data

(case concerned ISP)

CJEU, Scarlet/Sabam, 24 Nov 2011

Page 11: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

11

EU Data Protection Authorities

Nameless profiles for behavioral targeting: personal data.

Can be used to ‘single out’ a person.

WP29, behavioural advertising opinion 2010

Page 12: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

12

EU Personal data

EU Personal data

Personally identifiable information ‘PII’

Page 13: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

13

Data protection law: Fair information principles (FIPs)

- Consent (or other legitimate basis)

- Transparency - Right to access data - Data minimization - Security - ...

Overview FIPs: Gellman, ‘FIPs: a basic history’

Page 14: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

14

Contents

1. Consent for tracking technologies

2. Data protection law and behavioral targeting

3. W3C?

Page 15: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

15

W3C & Fair information principles (FIPs)?

- Consent (or other legitimate basis)

- Transparency - Right to access data - Data minimization - Security - ...

Overview FIPs: Gellman, ‘FIPs: a basic history’

Page 16: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

16

Contents

1. Consent for tracking technologies

2. Data protection law and behavioral targeting

3. W3C?

Page 17: Behavioral targeting & European la · Behavioral targeting & European law W3C Workshop: Do Not Track and Beyond Berkeley 26-27 November 2012 Frederik Borgesius Institute for Information

Thank you!

Frederik Borgesius

@FBorgesius