The problem is that, effective in a few months, this argument is not considered sufficient. You don't get get automatic permission to use private data just because you "need" that for revenue. People have an unconditional right to their private data, your business does not have an unconditional right to revenue or success. You get only the data that users consent to. If that's not sufficient for your ads, revenue and service, then tough luck, adapt or cease operations; if your business model is not compatible with user privacy then that business model simply is not valid anymore.
You are debating different thing. The debate is, can a business deny service, or offer degraded service instead, if no consent is given. Nothing I have read suggest otherwise.
4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
This is exactly what it means - it doesn't explicitly prohibit a business to deny service; however in this case the regulator is likely to rule that the consent they received from those users who did click "agree" was not freely given, and the business is using their data in violation of this directive.
I.e. instead of "can a business deny service, or offer degraded service instead, if no consent is given" think about the concept "if a business is known to deny service or offer degraded service instead if no consent is given, is that consent freely given or not?", and how will your business demonstrate to the regulator the legal basis that gives that you have the right to use that data - since now by default you're not allowed to have and use it. The evaluation criteria is not "did they click a box with required parameters" but rather "does your whole consent-gathering process ensure that you're not counting consent that users did not want to give" - if your consent-gathering process is flawed and systematically results in people who didn't want to consent being listed as "True" in your consent-database, then it means that you don't have consent from anyone.
This is an clear, large financial risk, since if a business does it this way I'm likely to intentionally go to their website, click 'Agree', enter my data, on the same day file the standard request to the business requesting information of the data they have on me and the legal grounds for using that, and if all they've got to say is "well, you clicked the agree button where the other choice was to refuse service" then I'll immediately file a complaint with the regulator that they're using my data without freely given consent (as the service was conditional on that consent) and deserve a fine for this violation. And the fines are substantial.
Unless the business can show that private data is necessery for good service which it is as data brings more revenue, and more revenue enables good service.
So a user would have two options: 1. Disagree, pay with money, 2. Agree, pay with private data.
No, that's simply not true - the exemption is if the data needs to be used to actually do the service right now. Quoting the actual directive, "processing is necessary for the performance of a contract to which the data subject is party"; there's no "good service" there, nor future improvements of that service, nor sustained profitable operation of the company. And "necessary" means just that; if you physically can perform the contract without this data, then the data is not legally necessary even if you'd go bankrupt if everyone did that. This exemption covers things like storing your address for deliveries of goods, a messaging app storing your contact info, instagram storing your photos - things where that data is inherently needed to execute that service.
Data can be helpful to improve some recommendations that will make service better in the future - fine, the users can opt-in and some will do that; but that's not an automatic justification to use that data;
Data can be helpful to support the future development your service with revenue - fine, the users can opt-in and some will do that (i.e. many people turn off adblockers and give patreon funding to services they like), but again, that's not going to be legal justification to use data of those who don't want to.
There are a bunch of other exemptions where you can use that data without consent (compliance with other legal requirements, overriding public interest as in e.g. press about public officials), but "I need money to continue operating" is not among them. GDPR is intended to solve the conflict between "I don't want to provide data" vs "I need data-based revenue to continue operating" in the favor of users. If you really do need that data based revenue to operate, then the users can "vote" (by opt-in) whether they consider your continued operation valuable enough to hand over their data voluntarily.
A mobile app for photo editing asks its users to have their GPS localisation activated for the use of its services.
The app also tells its users it will use the collected data for behavioural advertising purposes. Neither geo-localisation or online behavioural advertising are necessary for the provision of the photo editing service andgo beyond the delivery of the core service provided. Since users cannot use the app without consenting to thesepurposes, the consent cannot be considered as being freely given.
[Example 6]
A bank asks customers for consent to use their payment details for marketing purposes. This processing activity is not necessary for the performance of the contract with the customer and the delivery of ordinary bank account services. If the customer’s refusal to consent to this processing purpose would lead to the denial of banking services, closure of the bank account, or an increase of the fee, consent cannot be freely given or revoked.
You appear to be right. GDPR effectively bans targeted ads in EU which means a significant source of revenue, enough to be fatal, is now illegal. It seems to me that EU does not like private data as payment.
I wish good luck to citzens and businesses cause I certainly wouldnt/couldnt, as a business, provide EU.
Which many wont. Yet business still have to provide same service as someone who has. Cost remains same but now profit reduced drastically. Thus its not economical to provide to EU.
> Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.
Article 43:
> Consent is presumed not to be freely given [...] if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.
I've only read interpretations of said guidance from the ICO, DPN, and DPC but they are exactly what you would expect from those two articles.
- Private Data is useful for Ads, but not the only way to run them.
- Ads are useful way of generating Revenue, but not the only way to get it.
- Revenue is useful to provide a Service, but not necessary, as evidenced by almost every startup out there ;).
Ok, I'm joking with the third a bit, but for the first two points - sure, data->ads->revenue might have been the easiest way to make money on the Internet, but it's not the only way, and the point of GDPR is for companies to explore other, less user-hostile options.
Exactly this. A veneer of personalization can make it so that you must consent to get the service. Realistically not every use can be put down a priori because that would preclude allAB testing of new features. I’m expecting a much larger “cookie pop up” but getting an option to reset data will be nice (until I need to use the service again)
Note that you must get consent for each separate use. If users give you consent to use that data for service personalization, then that must be separate from using the same data for ad personalization and from consent for sharing that data with third parties - even if the first use case is objectively needed by your users, the other uses must be opt-in and can be refused.
"Realistically not every use can be put down a priori because that would preclude allAB testing of new features." means just that - it does preclude you from AB testing of new uses of that data as you might have done before. It's illegal now unless you get user consent beforehand. It doesn't prevent AB testing as such, but it does prevent "hidden" AB testing that doesn't inform users and doesn't give them an option to refuse.
And crucially, under the consent basis, you have to explicitly enumerate the 3rd parties by name. You can no longer use a defined, every precisely defined, class of 3rd parties.
The other available basis, legitimate interests, would be extremely hard to use as a basis for 3rd party target data sharing.
Whats the problem ?