Featured Article

Adtech’s compliance theatre is headed to Europe’s top court

It’s privacy crunch time for ‘consent’ to track…

Comment

Seamless Eyes Spy Abstract Background Pattern
Image Credits: filo / Getty Images

For those watching the slow motion unpicking of surveillance advertising in the European Union here’s a fresh development on the long and winding road to a long-overdue legal reckoning: Multiple grounds for appeal lodged by industry body, the IAB Europe, against a breach finding earlier this year against its self-proclaimed “best practice” framework for obtaining consents from web users for their data to be processed for behavioral advertising, have been dismissed by the Brussels Market Court of Appeal.

At the same time, legal questions have been referred to Europe’s top court related to a number of other appeals grounds — which means a hard ruling will be coming down the pipe for a flagship component of surveillance adtech’s elaborate machinery in the coming years.

At specific issue here is a “cross industry” framework specced out and promoted by the IAB Europe, and taken up by scores of publishers and advertisers to claim they’re obtaining web users ‘consent’ to ad tracking but which critics argue boils down to elaborate ‘compliance theatre’ — enacting a pantomime of consent to workaround the EU’s privacy laws.

This consent tool, aka the Transparency and Consent Framework (TCF), underlies the majority of irritating ad consent pop-ups that plague web users in the region — yet it was found in breach of the bloc’s General Data Protection Regulation (GDPR) earlier this year, after a lengthy investigation by Belgium’s data protection authority, confirming what privacy and legal experts had been warning for years: That majority consent to tracking ads is a big fat lie.

GDPR violations confirmed in the Belgian authority’s decision on the TCF, back in February, cover major principles like the lawfulness of processing; fairness and transparency; security of processing; integrity of personal data; and data protection by design and default, among others.

The IAB Europe itself was also found to have breached the GDPR. And the online ad industry body was given a hard deadline of six months to fix a laundry list of violations — although the TCF has been allowed to persist in the meanwhile (so the annoying pop-ups haven’t yet gone away).

The IAB Europe responded to the regulatory slap-down by firing up its lawyers and lodging an appeal — seeking to undo the Belgian DPA’s decision by arguing against it from multiple angles, from claims of procedural unfairness to flat denials that its role or the technologies it steers breach any EU laws.

Simultaneously, in a further denial of an existential privacy problem with tracking ads, the body said it planned to press on and submit the TCF as a “transnational Code of Conduct,” apparently eyeing grafting on ‘compliance’ with U.S. regulatory requirements (like California’s CCPA). (An associated, U.S.-based adtech body, the IAB Tech Lab, published a draft replacement “global” framework this summer, called the “Global Privacy Platform,” which it claims “streamlin[es] technical privacy and data protection signaling standards into a singular schema and set of tools which can adapt to regulatory and commercial market demands across channels” — but which critics warn merely repeats many of the same glaring flaws that have landed the TCF in legal hot water in Europe, so the lack of reforming zeal is palpable.)

But how much mileage the IAB can get out of denying legal reality in the EU — where data protection is (at least on paper) comprehensive and privacy is a fundamental right — is the big question.

In a first blow to its appeal against the TCF’s GDPR strike down, a bunch of its procedural gripes have now been tossed.

Grounds for appeal?

Of eight grounds decided on by the Brussels court at this point in the appeal, five were found to be entirely unfounded — with only two of the final grounds considered “well-founded in part,” as the Court’s ruling puts it. (Those related to a finding that additional allegations and complaints — centered on whether a mechanism in the IAB’s framework constitutes personal data — were incorporated into the decision after the hearing without “sufficient diligence.” Although the court stresses that the authority would not have had to open a whole new investigation, as the IAB had argued, so this looks like a fairly minor procedural win.)

The other five grounds that the court has decided on at this stage — such as the IAB’s assertion that the complaints were inadmissible or the authority’s Inspection Report was “incomplete and biased” — were all dismissed.

However there are yet more grounds lodged by the IAB (the ruling lists 19 in all). And the appeal is now suspended pending the Court of Justice (CJEU)’s response to legal questions related to these grounds.

The referred questions center on whether a per-user consent string passed via the TCF constitutes personal data (the IAB argues not but the Belgian DPA decided it did, as the complainants also argue); and whether the IAB, which couches itself as a humble industry standards body, is a joint data controller for the purposes of the TCF and the so-called “TC string” (again, it argues not but it was found by the authority to be a joint controller).

“That the Brussels Court of Appeal has referred our questions to the European Court of Justice shows the importance of this case,” said one of the original complainants, Dr. Johnny Ryan, senior fellow at the Irish Council for Civil Liberties, in a statement. “Today’s judgement is the next step in our effort to put an end to the consent pop-ups that have harassed Internet users in Europe for years. We now look forward to the answers from the European Court of Justice and subsequently a judgement on the merits of the Brussels Court of Appeal.”

The CJEU could take a few years to produce a ruling on these questions but there’s no route of appeal on what it decides. So the train has now left the station.

There will — in fairly short order — be a hardened verdict from the court on crux points like whether an entity that devises and promotes mass surveillance adtech infrastructure, and whose rules dictate core procedures of this tracking machinery, is able to evade the full force of EU privacy law by claiming it’s just a standards body guv! And on the IAB’s flagship sleight-of-hand — when it claims TC strings aren’t personal data and don’t link to individuals ergo there’s no need for a legal basis for processing them anyway — which would be quite the get-out-clause for behavioral ads from EU data protection law if allowed to stand by the court.

(The Belgian DPA’s response to that argument was to point out that the TCF links the consent string to the user’s IP address, which is absolutely considered personal data under GDPR; and that users of the tool are also able to identify users via other data; and that, indeed, the whole point of the TC string is to identify the user.)

At this point it pays to refresh the memory on how the GDPR defines personal data [with added emphasis ours]:

‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

So now EU citizens annoyed by countless illegal pop-ups must hold their breath for a CJEU ruling. (But the finest legal minds in Europe surely won’t need to cogitate for too long to call out this mulligan.)

Next stop, enforcement?

In the meanwhile, the Belgian DPA could — and really should — restart enforcement of the original order, given the vast scale of the violations and risks to Europeans’ fundamental rights of allowing unlawful mass surveillance by out-of-control adtech to continue unchecked.

Asked about his expectations for enforcement, Ryan told TechCrunch he’s looking into whether the authority’s decision can now finally be applied (a preliminary Belgian ruling on the TCF, also finding it in breach of the GDPR, dates back almost two full years at this point).

“The extension was until the Markets Court decision. So it should be able to apply it now,” he suggested, adding: “The tracking-based online ad industry must reconcile itself to the likelihood that EU data protection law will actually be enforced.”

We also reached out to the Belgian authority and to the IAB Europe with questions — but neither had responded at press time.

Update: A spokesperson for the Belgian DPA confirmed that the ad industry body submitted an action plan to it in April — “as required in our February decision”. “The BE DPA does intend to pursue its assessment of the measures proposed in the Action Plan sent in April by IAB Europe. However, the BE DPA will not comment further on the content of the action plan at this moment,” they added.

The spokesperson further specified that the action plan the IAB submitted to it “was not presented as the so-called Global Privacy Platform, which has, it seems, been entirely developed by IAB Tech Lab.

Following the Brussels court referral, the IAB Europe posted a statement on its website about the developments — acknowledging what it refers to as an “interim ruling”, as well as the referral of questions to the CJEU which it said it “welcomes.”

“The interpretation of the notions of personal data and controllership embraced by the APD [Belgian DPA] is unnecessarily broad from a consumer protection point of view and has significant negative implications for the development of open standards and the Codes of Conduct foreseen in the GDPR,” added Townsend Feehan, IAB Europe’s CEO, in a canned comment. “It would place an unacceptable financial burden on host organisations, discouraging the development of these important compliance tools.”

In a statement posted on its website after the court referral, the Belgian authority said that it will “now have to further analyse the ruling before being able to express itself in more detail on its content” but it professes itself “already pleased with this decision, which will further clarify key concepts of the GDPR such as the definition of the concept of data controller, and its applicability to framework designers.”

Hielke Hijmans, chairman of the DPA’s Litigation Chamber, added in a statement: “The IAB Europe case, in which we ruled in February, has an impact that goes far beyond Belgium. That’s why we think it is a good thing that it is being discussed at the European level, at the Court of Justice of the EU.”

The authority also wrote that its decision has “made an important contribution to the protection of Internet users’ privacy in Europe, through its analysis of the mechanism for recording users’ preferences for targeted online advertising,” further arguing: “It will raise awareness about online advertising, and especially about the mechanism behind the consent to receive targeted advertising.”

The DPA’s statement went on to say that Belgium will “discuss possible next steps with its EU counterparts.”

Which, well, sounds a little bit like ‘watch this space’…

Behavioral ad industry gets hard reform deadline after IAB’s TCF found to breach Europe’s GDPR

European parliament backs big limits on tracking ads

More TechCrunch

These messaging features, announced at WWDC 2024, will have a significant impact on how people communicate every day.

At last, Apple’s Messages app will support RCS and scheduling texts

iOS 18 will be available in the fall as a free software update.

Here are all the devices compatible with iOS 18

The tests indicate there are loopholes in TikTok’s ability to apply its parental controls and policies effectively in a situation where the teen user originally lied about their age, as…

TikTok glitch allows Shop to appear to users under 18, despite adults-only policy

Lhoopa has raised $80 million to address the lack of affordable housing in Southeast Asian markets, starting with the Philippines.

Lhoopa raises $80M to spur more affordable housing in the Philippines

Former President Donald Trump picked Ohio Senator J.D. Vance as his running mate on Monday, as he runs to reclaim the office he lost to President Joe Biden in 2020.…

Trump’s VP candidate JD Vance has long ties to Silicon Valley, and was a VC himself

Hello and welcome back to TechCrunch Space. Is it just me, or is the news cycle only accelerating this summer?!

TechCrunch Space: Space cowboys

Apple Intelligence features are not available in the developer beta, which is out now.

Without Apple Intelligence, iOS 18 beta feels like a TV show that’s waiting for the finale

Apple released the public betas for its next generation of software on the iPhone, Mac, iPad and Apple Watch on Monday. You can now test out iOS 18 and many…

Apple’s public betas for iOS 18 are here to test out

One major dissenter threatens to upend Fisker’s apparent best chance at offloading its unsold EVs, a deal that would keep the startup’s bankruptcy proceeding alive and pave the way for…

Fisker has one major objector to its Ocean SUV fire sale

Payments giant Stripe has delayed going public for so long that its major investor Sequoia Capital is getting creative to offer returns to its limited partners. The venture firm emailed…

Major Stripe investor Sequoia confirms $70B valuation, offers its investors a payday

Alphabet, Google’s parent company, is in advanced talks to acquire Wiz for $23 billion, a person close to the company told TechCrunch. The deal discussions were previously reported by The…

Google’s Kurian approached Wiz, $23B deal could take a week to land, source says

Name That Bird determines individual members of a species by identifying distinguishing characteristics that most humans would be hard-pressed to spot.

Bird Buddy’s new AI feature lets people name and identify individual birds

YouTube Music is introducing two new ways to boost song discovery on its platform. YouTube announced on Monday that it’s experimenting with an AI-generated conversational radio feature, and rolling out…

YouTube Music is testing an AI-generated radio feature and adding a song recognition tool

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Elon Musk confirms Tesla ‘robotaxi’ event delayed due to design change

What this means for the space industry is that theory has become reality: The possibility of designing a habitation within a lunar tunnel is a reasonable proposition.

Moon cave! Discovery could redirect lunar colony and startup plays

Get ready for a prime week of savings at TechCrunch Disrupt 2024 with the launch of Disrupt Deal Days! From now to July 19 at 11:59 p.m. PT, we’re going…

Disrupt Deal Days are here: Prime savings for TechCrunch Disrupt 2024!

Deezer is the latest music streaming app to introduce an AI playlist feature. The company announced on Monday that a select number of paid users will be able to create…

Deezer chases Spotify and Amazon Music with its own AI playlist generator

Real-time payments are becoming commonplace for individuals and businesses, but not yet for cross-border transactions. That’s what Caliza is hoping to change, starting with Latin America. Founded in 2021 by…

Caliza lands $8.5 million to bring real-time money transfers to Latin America using USDC

Adaptive is a platform that provides tools designed to simplify payments and accounting for general construction contractors.

Adaptive builds automation tools to speed up construction payments

When VanMoof declared bankruptcy last year, it left around 5,000 customers who had preordered e-bikes in the lurch. Now VanMoof is up and running under new management, and the company’s…

How VanMoof’s new owners plan to win over its old customers

Mitti Labs aims to transform rice farming in India and other South Asian markets by reducing methane emissions by 50% and water consumption by 30%.

Mitti Labs aims to make rice farming less harmful to the climate, starting in India

This is a guide on how to check whether someone compromised your online accounts.

How to tell if your online accounts have been hacked

There is a general consensus today that generative AI is going to transform business in a profound way, and companies and individuals who don’t get on board will be quickly…

The AI financial results paradox

Google’s parent company Alphabet might be on the verge of making its biggest acquisition ever. The Wall Street Journal reports that Alphabet is in advanced talks to acquire Wiz for…

Google reportedly in talks to acquire cloud security company Wiz for $23B

Featured Article

Hank Green reckons with the power — and the powerlessness — of the creator

Hank Green has had a while to think about how social media has changed us. He started making YouTube videos in 2007 with his brother, novelist John Green, at a time when the first iPhone was in development, Myspace was still relevant and Instagram didn’t exist. Seventeen years later, posting…

Hank Green reckons with the power — and the powerlessness — of the creator

Here is a timeline of Synapse’s troubles and the ongoing impact it is having on banking consumers. 

Synapse’s collapse has frozen nearly $160M from fintech users — here’s how it happened

Featured Article

Helixx wants to bring fast-food economics and Netflix pricing to EVs

When Helixx co-founder and CEO Steve Pegg looks at Daisy — the startup’s 3D-printed prototype delivery van — he sees a second chance. And he’s pulling inspiration from McDonald’s to get there.  The prototype, which made its global debut this week at the Goodwood Festival of Speed, is an interesting proof…

Helixx wants to bring fast-food economics and Netflix pricing to EVs

Featured Article

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

India is struggling to get new smartphone buyers, as millions of Indians don’t go for an upgrade and continue to be on feature phones.

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

Roboticists at The Faboratory at Yale University have developed a way for soft robots to replicate some of the more unsettling things that animals and insects can accomplish — say,…

Meet the soft robots that can amputate limbs and fuse with other robots

Featured Article

If you’re an AT&T customer, your data has likely been stolen

This week, AT&T confirmed it will begin notifying around 110 million AT&T customers about a data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers. The stolen data contains phone numbers and AT&T records of calls and text messages during a six-month period in…

If you’re an AT&T customer, your data has likely been stolen