Executive Summaries Dec 11, 2019

Joint Controllership or the Risks of using Website Plugins

Companies that engage adtech services either to sell their products to or to collect information on Europeans may be considered joint controllers according to the finding of the European Court of Justice (“ECJ”) in the case of Fashion ID GmbH &Co.KG v. Verbraucherzentrale NRW eV (“Fashion ID”) – a finding that creates compliance obligations.

Danielle Miller Olofsson has authored this article.

In this case, Fashion ID GmbH, an online fashion retailer, embedded on its website Facebook’s “Like” social plugin. Personal data belonging to visitors to the Fashion ID website was immediately transmitted to Facebook Ireland without the visitors: i) being aware, ii) having clicked the “Like” button, or iii) having a Facebook account. Although Fashion ID GmbH argued that it could not control what data the browser transmitted or what Facebook did with the data, it was nevertheless held to be a “controller” for the purposes of European data protection legislation. The court held that: “the operator of a website [...] that embeds on that website a social plugin causing the browser of a visitor to that website to request content from the provider of that plugin and, to that end, to transmit to that provider personal data of the visitor can be considered to be a controller”.

The ECJ specifies, however, that the function of controller only applies with respect to the information over which the company exercises some control – that is to say the information its website processes up until the point it transmits it to the adtech provider’s browser.

Practically speaking, this means that organisations using the marketing services of adtech providers such as Google, Amazon or Facebook as well as numerous others, may in fact be deemed joint controllers for the purposes of the European General Data Protection Regulation (“GDPR”) and, as such, obliged to enter into a joint controller agreement with these providers. This agreement requires both controllers to set their respective data processing responsibilities, especially as they pertain to the purpose and means of collection, as well as their respective notification obligations as per articles 13 and 14 of the GDPR. It should be recalled that controllers, by definition, are also required to:

  • process the information lawfully which in most cases means acquiring specific and explicit consent at the time of processing (i.e. prior to transferring the information to the visitor’s browser);
  • inform the data subject clearly of the fact that its information may be transferred to a third party and of the uses that could be made of it;
  • notify affected data subjects of a breach within 72 hours of becoming aware of it;
  • ensure that the information that might be transmitted is protected by adequate safeguards; and
  • in the event the third party site is not located in the European Union, ensuring that appropriate safeguards are in place (adequacy, privacy shield, biding corporate rules, codes of conduct, etc.) so that the transfer is not in violation of the GDPR.

In light of the Fashion ID decision, then, website owners using social plugins to collect information on their clientele should consider:

  • immediately updating their privacy notices to reflect the requirements of the decision especially at they relate to consent and full disclosure; and
  • drafting a model joint-controllership agreement that clearly delineates the scope of their responsibilities.

BCF’s Data Protection Group would be more than happy to assist organisations review their relationships with marketing service providers and implement measures to comply with their new role in light of the Fashion ID decision.

Stay on the lookout!

Subscribe to our communications and benefit from our market knowledge to identify new business opportunities, learn about innovative best practices and receive the latest developments. Discover our exclusive thought leadership and events.

Subscribe

You would also like

Data-Privacy

Bill 82: One Step Closer to a National Digital Identity (and Modifications to Other Provisions!)

Entrepreneurship forum

Entrepreneurship Forum: Vision 2025

Athlete

Protecting Privacy in Sports – Don’t Wait to be Caught Flat-Footed!

data-protection

Obligation to Report Information Security Incidents: The Autorité des Marchés Financiers Catches the Wave and Publishes a New Regulation

Right to Data Portability: Is your Organization Ready?

Tech Forum 360

Tech 360 Forum: Growth and Inflection Points

Prospera: Québec’s Economic Barometer

Canada's Best Managed Companies: BCF Recognized for 17th Consecutive Year

paul et misha

BCF Strengthens its Expertise in Artificial Intelligence

new-partners-2024

BCF Has Appointed Three New Partners

Who’s Who Legal : 5 BCF Professionals Stand Out

BCF extends its Partnership with the Canadian Association of Black Lawyers to a Third Year

Demystifying Privacy Impact Assessments (PIAs)

The Data Processing Agreement: An Essential Resource to Implement

camera-on-a-wall

The Incident Response Plan: the Cornerstone of Effective Crisis Management

forum-privacy-en

Strategic Forum on Enterprise Data Protection

Chambers Canada Ranking: Five of our Lawyers Recognized

Photo of Julie Doré

Julie Doré Takes Over Management of The BCF Business Law Firm

Prospera – Quebec Economic Barometer

Julien Tricart, Member of the Meritas Sports Law Group

Pride Month: Let’s Create an Inclusive Future

Canada’s Best Managed Companies: BCF Recognized for 16th Consecutive Year

New Privacy Requirements: Is Your Business Compliant?

Every Woman Counts

Strategic Forum on the Role Played by Businesses in the Fight Against Climate Change

BCF Partners with the Canadian Association of Black Lawyers to Promote Diversity in Québec Law Faculties

BCF's More Inclusive Approach: Improved Parental Leave

Shaun E. Finn Appointed to the Superior Court of Québec

How to Ensure a Business Succession?

Business black folders on table

Adoption of Bill 78 on Transparency Business: Are You Ready?

Strategic Forum on Market Consolidation and Business Succession

BCF Partners with the Clinique Juridique de Saint-Michel to Promote Access to Legal Studies for Young People from Diverse Communities

What Are the Best Practices for Managing Privacy Incidents?

Shaun E. Finn, Co-Author of In the Public Eye: Privacy, Personal Information, and High Stakes Litigation in the Canadian Public Sector

Should Using Personal Information Obtained Without Consent Be Grounds for Class Action Authorization?

Five of our Lawyers Stand out in the 2023 Edition of the Chambers Canada Ranking

Cybersecurity and Privacy in Canada: What You Need to Know About Bill C-27

Is the Loss of Personal Information Sufficient to Justify the Success of a Class Action on the Merits?

Bill C-26: The Federal Government Takes a Closer Look at Cybersecurity and Privacy

Jocelyn Poirier, BCF’s Chief Privacy Officer

43 BCF Professionals Stand Out with 78 Nominations in the 2023 Editions of Best Lawyers in Canada and Ones to Watch

Seven New Lawyers Join BCF

Adoption of Bill 96: Be Ready

Pride Month: The Value of Diversity

BCF, the 3rd Largest Law Firm in Québec

Canada’s Best Managed Companies: BCF Recognized for 15th Consecutive Year

BCF Recognized by the Globe and Mail as one of Canada’s top Law Firms

Chambers Canada 2022: BCF Earned Band 1 Ranking in Québec for Corporate and Commercial Law

Seven New Lawyers Join BCF

Privacy and Data Protection Class Actions: Trends, Challenges and Best Practices

A First in Canada: Privacy Class Action Dismissed on the Merits

escalier

BCF Welcomes Seven New Lawyers

Collaboration in the Time of COVID-19: Legal Considerations for Successful AI and Healthcare Partnerships

Shaun E. Finn and Danielle Miller Olofsson Publish a Unique Practical Handbook on Privacy and Data-Protection Class Actions

What Are the Implications of the End of EU-U.S. Privacy Shield Framework for Your Business?

Investigation on Tim Hortons’ Application

Québec’s Bill 64 to Amend Data Protection Legislation: A Bill with Teeth?

Does the Use of Thermal Imaging Cameras in Stores Comply with Privacy Laws?

COVID-19: Solutions to Address this Situation

COVID-19: Finally a Toolbox for Developers of Geolocalisation Applications

Tracking the COVID-19 Pandemic with Cellphones

COVID-19: Don’t Forget Data Protection When Designing a Response Strategy

BCF once again ranks as one of Montreal's Top Employers

BCF Names 16 New Partners for Its 25th Anniversary

Are You a Leader or a Follower?Results of the Innovation Survey

Chambers Canada 2020: BCF Recognised in Corporate and Commercial Law

Strategic Forum on Innovation

Different Legislative Approaches to 5G

Innovating to Survive: Are You a Leader or a Follower?

Is Your Company Implementing a New Technology System? Remember to Protect Your Data

5G Technology Is Coming: Legal Questions Abound

Legal Issues Surrounding the Industrial Revolution 4.0

Where Does Québec Stand in Terms of Privacy Class Actions?

De-fogging the Cloud Act

fenetres

Google and CNIL: a Case of Inappropriately Obtained Consent

Best Practices for Québec Companies Receiving European Data

Anonymization? Think Again

The Deep Web and Dark Web Demystified for Businesses

The GDPR is Coming: How to Get Ready

Protection of Personal Data: New Measures Put in Place by the European Union

Is Your Organisation Collecting Too Much Data and Is It Well Protected?

Get the latest thought leadership