When Digging into Google’s push to freeze ePrivacy

Per the US states’ suit, a couple of years after a European Commission proposal to update the EU’s ePrivacy Directive — to replace it with a more widely applicable Regulation — the tech giant was privately celebrating what it described as a “successful” tilt at “slowing down and delaying” the privacy legislation.

 

The update to the EU’s privacy rules around people’s electronics communications (and plenty more besides) remains stalled even now, with negotiations technically ‘continuing’ — just without any agreement in sight. So Google’s ‘success’ looks overwhelming. As well as putting questions to Google, TechCrunch contacted Amazon, Apple, Facebook and Microsoft about the August 6 meeting referenced in Google’s memo.

 

A spokeswoman for Microsoft declined comment — saying only: “We have nothing to share.”

 

Amazon and Facebook did not respond to repeated requests for comment.

 

However, last December Politico reported on an internal Amazon document, dating from 2017, which showed the ecommerce giant making an eerily similar boast about eroding support for the ePrivacy Regulation.

 

“Our campaign has ensured that the ePrivacy proposal will not get broad support in the European Parliament,” Politico reported Amazon writing in the document. “Our aim is to weaken the Parliament’s negotiation position with the Council, which is more sympathetic to industry concerns,” the text went on.

 

According to its report, Amazon’s lobbying against ePrivacy focused on pushing the Parliament for “less restrictive wording on affirmative consent and pushing for the introduction of legitimate interest and pseudonymization in the text” — which, as the news outlet observes, are legal grounds that would give companies greater scope to collect and use people’s data.

 

Amazon’s motivation for wanting to degrade the level of privacy protections wrapping Europeans’ data is clear when you consider the $42M fine it was slapped with last year by a single EU data protection watchdog (France’s CNIL) under current ePrivacy laws. Its infringement? Dropping tracking cookies without consent.

 

Amazon’s digital advertising business isn’t as massive as Google’s (although it is growing). But the ecommerce behemoth has plenty of incentive to track and profile Internet users — not least for targeting them with stuff for sale on its ‘everything store’.

 

A beefed up ePrivacy could put limits on such tracking. And evidently, Amazon would prefer that it didn’t have to ask your permission for its algorithms to figure out how to get you to buy more stuff on Amazon.fr or .de or .es and so on.

 

But what about Apple? It’s certainly unusual in the list as a (rare) tech giant that’s built a reputation as a champion of user privacy.

 

 

 

That said, the adtech giant can’t take all the credit: The US states’ case against Google quotes an internal memo from July 2019 — in which it claims to have been “working behind the scenes hand in hand” with the other four of the ‘big five’ tech giants (GAFAM) to forestall consumer privacy efforts.

 

Here’s the relevant allegation from the

Yet it’s not ‘simplified’ rules that are needed to fix cookie consent; it’s enforcement against systematic rule-breakers that have been allowed to make a mockery of the law in order they they can keep profiting by ignoring everyone’s right to privacy.

The long and short of this is that the damage to consumers and civic society across Europe as a result of regulatory inaction on adtech — and because of Google’s ‘successful’ lobbying against ePrivacy — looks staggeringly high.

While GDPR enforcement on adtech has been largely stalled these past three+ years, thanks (in no small part) to big tech’s forum shopping, if there had been an updated ePrivacy Regulation sitting alongside GDPR — adding enhanced transparency and consent requirements — it could have blasted tracking-based business models right out of EU waters years ago.That in turn could mean ePrivacy ends up creating legislative cover for surveillance-based business models — reversing the stronger protections earlier EU lawmakers had intended and further undermining the GDPR’s (already weak) application against adtech… In short, a disaster for fundamental rights.

Whereas, if the ePrivacy update had been passed at around the same time as the GDPR, Olejnik reckons it would have resulted in a more practically successful upgrade of EU data protection rules.

“There would be chances to synchronise the upgrade,” he suggests. “It would also avert the subsequent backlash due to ‘GDPR paranoia’, which instantly made everybody — including policymakers and the industry — ultra-careful and less happy about any changes in this domain. So the changes would be of a practical nature.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author