Home Data-Driven Thinking An Evolution, Not A Revolution: Underscoring The Nuances Of GDPR

An Evolution, Not A Revolution: Underscoring The Nuances Of GDPR

SHARE:

Data-Driven Thinking” is written by members of the media community and contains fresh ideas on the digital revolution in media.

Today’s column is written by Guillaume Marcerou, global privacy director at Criteo.

When General Data Protection Regulation (GDPR) goes into effect on May 25, it will unify the various data privacy laws that exist across all 28 member states of the EU, including the UK.

This is a nuanced but critical point. Major global corporations with EU offices are already accustomed to complying with country-level data privacy and security requirements and are thus already complying with key elements of GDPR.

As the clock winds down to the regulation, it is imperative that marketers understand the intricacies of the policies, beginning with the areas for interpretation most commonly misconstrued.

The True Purpose Of GDPR

The GDPR aligns data protection policies across EU member states while providing consistent application and enforcement by local data protection authorities in each EU member state. Its objectives are to:

  • Modernize the legal system to protect personal data in an era of globalization and technological innovation.
  • Strengthen individual rights while reducing administrative burdens to ensure a free flow of personal data within the EU.
  • Bring clarity and coherence to personal data protection rules and ensure consistent application and effective implementation across the EU.

User Consent Qualifications

Since 2009 and the amendment of the ePrivacy EU Directive – also known as the cookie directive – in-browser messages have been the rule to obtain cookie consent within the EU.

There is an important difference between unambiguous and explicit consent.

Explicit consent means the user must opt in. This applies to sensitive personal data such as race, religion, sexual orientation, political affiliation and health status.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

The GDPR requires companies to obtain unambiguous consent from users. For example, a message may be first shown to inform users, and then if users click any link on the page, they must acknowledge the use of cookies. This includes a user continuing to browse a website. Since online identifiers – cookies – alone are categorized as nonsensitive personal data, an explicit opt-in is not required.

This definition of nonambiguous consent is supported by numerous international governing bodies and agencies, including the guidance issued by the Spanish Data Protection Authority and other authorities.

Important Definitions

Consent can only be valid if it is “freely given,” where the data subject can exercise a real choice, and there is no risk of deception, intimidation, coercion or significant negative consequences if he or she does not consent. Ultimately, users must have the ability to refuse services directly from the cookie message without suffering any consequences.

For consent to be valid, it must be “specific” and “informed” by appropriate information. In other words, blanket consent without specifying the exact purpose of the processing is not acceptable. For example, an opt-out message that specifically informs users they are consenting to “cross-site tracking technology” would not pass muster.

Finally, consent must be “nonambiguous” and derive from an active behavior from which consent can be reasonably deduced. For example, a nonambiguous action would be when an individual continues to browse a website by clicking on a link on the page and accepting the use of cookies to monitor his or her browsing after specifically being informed by an in-browser message. By continuing to browse the website he or she accepts the use of third-party cookies for personalized advertising purposes.

The GDPR is a positive development that will foster trust in the digital economy and provide an environment of transparency, control and certainty for advertisers and customers. If GDPR provides efficient tools to reinstate trust in the ecommerce ecosystem, it comes with a shared responsibility for all actors to review their practices to effectively make this trust happen.

Follow Criteo (@criteo) and AdExchanger (@adexchanger) on Twitter.

Must Read

A comic depicting people in suits setting money on fire as a reference to incrementality: as in, don't set your money on fire!

Retail Media Is Starting To Come To Grips With The Fact That We All Know Nothing

Retail media is entering what might be called its Socratic phase. The closer we to get to understanding an ad campaign’s real impact and business results, the clearer it is that we have no idea how this thing works.

Meta Reels trending ads

Meta Has New Tools For Brand And Performance Goals, With A Focus On AI (Of Course)

Meta is rolling out Reels trending ads, value rules beyond just conversions, upgrades to Threads and pixel-free landing page optimization.

Comic: Shopper Marketing Data

Google Search Ads 360 Adds Criteo As First On-Site Retail Media Supply Partner

Criteo announced a partnership with Google Search Ads 360 (SA360), Google’s enterprise search advertising platform, making Criteo the first third-party vendor to integrate with Google for on-site retail media supply.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Minute Media’s Latest Acquisition Brings Automated Content Creation To Its Online Sports Video Network

As display falters, Minute Media is acquiring AI tech that cuts longer-form video content and full-length games into bite-size clips.

With GAM Going Direct To Buyers, SPO Is The New Normal

GAM’s dinner with ad agencies sparked speculation that Google is preparing to spin off its bundled SSP and ad server as a remedy to its ad tech monopoly. But Google says it’s just part of the trend of SSPs going direct to buyers.

Google’s Proposed Fix To Its Ad Tech Monopoly Is At Odds With The DOJ’s Remedies

Late Friday evening, Google filed its proposed remedies to its ad tech monopoly to District Court Judge Leonie Brinkema, and unsurprisingly, they’re rather mild – and very different from what the Department of Justice is looking for.