Due to the crescent popularity of social media, companies have been using the so-called social plug-ins as an efficient resource to optimize their user’s experiences, address their contents to the best target audience, and, especially, propel their access numbers.
Plug-ins that allow the disclosure of content in social media, user’s commentaries, sharing, and even the apparently harmless act of “liking” a specific content, are present in basically every website nowadays.
Amidst its spread usage, the plug-ins themselves have received new functionalities, being able to, despite running their main function, also collect data – most of times, in a veiled way – of the users that browse the websites that incorporate such plug-ins.
Considering this, the German State’s Consumer Defense Center of Nordrhein-Westfalen, a non-profitable organization that looks after consumers’ interests, filed a complaint against a major technology company and an important German clothing retailer brand, arguing the breach of their users data privacy due to a veiled data collection made through the social plug-ins installed in the German retailer’s website.
In a decision that stirred up a considerable repercussion, the Court ruled in favor of the Consumer Defense Center, finding that both companies are to be held liable for collecting the consumers’ data without their consent, which is considered a privacy violation.
The case is pending trial of the companies’ appeal at the Düsseldorf’s Court of Appeals. In this regard, the Court recently requested the European Court of Justice (“ECJ”) some clarifications regarding the European Council’s Directive no. 95/46, which set the standards of personal data protection in the European Union.
By the end of July, 2019, the ECJ issued its understanding, according to which the company that hosts the website that uses social plug-ins: (i) is held liable for their users’ data collection and sharing; and (ii) has the duty to inform its users that their website performs data collection and sharing.
Despite the current status of the case, companies are already searching for alternatives in order to mitigate risks, such as issuing alerts in their websites that inform the users of the data collection and sharing.
As to repercussions in the Brazilian context, the question finds similarities in the new General Data Protection Law, that provides the joint liability of data processing operators. This means that the ECJ’s interpretation of the case and the trial by the Düsseldorf Court of Appeals must be followed up close, due to this lawsuit possibly becoming a leading case to future Brazilian cases that deal with data privacy protection, as well as an alert to companies that deal with user’s data processing, specially through social media plug-ins.