{"id":2708,"date":"2021-09-09T13:28:00","date_gmt":"2021-09-09T19:28:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2708"},"modified":"2024-12-05T10:36:17","modified_gmt":"2024-12-05T16:36:17","slug":"lessons-from-edpb-binding-decision","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/","title":{"rendered":"A New Irish Fine: Lessons Learned from the EDPB Binding Decision"},"content":{"rendered":"\t\t<section id=\"block_8f96f259d4ff03ee3b870f3982a7b042\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>A New Irish Fine: Lessons Learned from the EDPB Binding Decision<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_96c6f142e1c145fb78be2653e167b173\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>WhatsApp fined 225 million Euros for violations of the GDPR<\/h2>\n<p>The Irish Data Protection Commission (DPC) has\u00a0<a href=\"https:\/\/dataprotection.ie\/en\/news-media\/press-releases\/data-protection-commission-announces-decision-whatsapp-inquiry\">imposed a fine of \u20ac225 million<\/a>\u00a0on WhatsApp\u2019s European headquarters following an\u00a0<a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/consistency-findings\/register-for-decisions_en\">investigation<\/a>\u00a0that took many years to complete.<\/p>\n<p>In addition to the fine, WhatsApp has received a compliance order, which it needs to fulfill within 3 months.<\/p>\n<p>The sanctions are imposed for violating the transparency principle and requirements under the European Union\u2019s General Data Protection Regulation (GDPR).<\/p>\n<p>This in itself is noteworthy, but the case becomes more interesting because the sanctions are a result of a\u00a0<a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/binding-decision-board-art-65\/binding-decision-12021-dispute-arisen_en\">Binding Decision<\/a>\u00a0by the European Data Protection Board (EDPB) following objections against the draft findings and sanctions proposed by the Irish DPC.<\/p>\n<p>The full report of the EDPB on the dispute resolution procedure sheds light on the considerations of the various regulators, as well as on some novel and updated interpretations of the GDPR by the EDPB.<\/p>\n<p>Here are three decision elements that might be relevant for other companies.<\/p>\n<h2>Legitimate interest<\/h2>\n<p>Processing personal data based on a legitimate (business) interest has been possible in Europe for a long time already.<\/p>\n<p>Under the former 1995 Data Protection Directive, the Article 29 Working Party (WP29, the predecessor of the EDPB) issued an\u00a0<a href=\"https:\/\/ec.europa.eu\/justice\/article-29\/documentation\/opinion-recommendation\/files\/2014\/wp217_en.pdf\">opinion<\/a>\u00a0on how the legitimate interest should be used.<\/p>\n<p>In any case, a legitimate interest should be \u201csufficiently clearly articulated\u201d and \u201crepresent a real and present interest\u201d in order to be valid. If that is not the case, the required balancing test could not be completed.<\/p>\n<p>Furthermore, where legitimate interest is used, information needs to be provided to the individual on the basis of Article 13(1)(d) GDPR.<\/p>\n\t\t\t\t\t\t\t\t<blockquote class=\"w-indent\">\n\t\t\t\t\t\t\t\t\t<p>In the WhatsApp Binding Decision, the EDPB writes that it\u00a0\u201cconsiders that the purpose of these duties of the controller is to enable data subjects to exercise their rights under the GDPR, such as the right to object pursuant to Article 21 GDPR, which requires the data subject to state the grounds for the objection relating to his or her particular situation.\u201d<\/p>\n\t\t\t\t\t\t\t\t<\/blockquote>\n\t\t\t\t\t\t\t\t<p>Therefore, \u201cfull information on each and every processing operation\u201d needs to be provided to the individual.<\/p>\n<p>One of the concerns was raised\u00a0<strong>against the way WhatsApp provided notice on their use of legitimate interests.<\/strong><\/p>\n<p>Several purposes for data processing and several legitimate interests were listed, without making clear how each of these relate to each other.<\/p>\n<p>Also the use of words like \u201cother business services\u201d or \u201cmaintaining innovative services and features\u201d cannot meet the approval of the data protection authorities, because they \u201cdo not meet the necessary threshold of clarity and intelligibility.\u201d<\/p>\n<h3><b>Recommendation:<\/b><\/h3>\n<p>When relying upon legitimate interest(s) for your data processing operations, ensure each legitimate interest is made clear in your privacy notice, with a clear link to the types of data used for each data subject category and the intended purpose(s).<\/p>\n<h2>Matching address books<\/h2>\n<p>The second contentious issue is the question whether phone numbers of non-users, collected when matching an address book with WhatsApp\u2019s current user list to facilitate connections, remain personal data, even after so-called lossy hashing.<\/p>\n<p>Lossy Hashing is an encryption technique which basically \u2018translates\u2019 the phone number of a non-user into a code that at first glance does not have any meaning.<\/p>\n<p>The EDPB discusses the objections of multiple data protection authorities.<\/p>\n<p>In short, all argue that the original Irish DPC finding that lossy hashed data does not constitute personal data is incorrect, since re-identification is possible and does not require a lot of effort.<\/p>\n<p>This is due to the way the technique is implemented by WhatsApp, by only using\u00a0up to 16\u00a0phone numbers, instead of the\u00a0full available, and by \u201clinking a lossy hash to mobile phone numbers of those users who uploaded numbers via the Contact Features that fall into the group of different phone numbers that would have generated that same lossy hash.\u201d<\/p>\n<p>Furthermore, if these data are regarded as personal data, additional violations of the GDPR should be noted, both in terms of the legal basis to process these data and the information provided to individuals.<\/p>\n<h3><b>Recommendation:<\/b><\/h3>\n<p>The EDPB does not raise principled objections against the possibility to match user lists against a database, while using a lossy hash on non-users to limit the amounts of available data.<\/p>\n<p>However, a \u201ctable of lossy hashes together with the associated users\u2019 phone numbers [retained] as Non-User List constitutes personal data.\u201d<\/p>\n<p>As such, this processing activity requires its own legal basis and proper information to be provided to individuals.<\/p>\n<h2>Calculating sanctions<\/h2>\n<p>The final learning point in the EDPB Binding Decision relates to the calculation of the administrative fine.<\/p>\n<p>In their draft decision, the Irish DPC set a proposed range for the fine amount, with a cap that was calculated on the basis of the annual combined global turnover for Facebook Inc and WhatsApp Ireland, given they should be regarded as a group of undertakings under the GDPR.<\/p>\n<p>The question raised however, was \u201cwhether turnover is relevant only to determine the maximum fine that can be lawfully imposed, or whether it is potentially also relevant in the calculation of the fine amount\u201d.<\/p>\n<p>The EDPB considers a \u201cconclusion that turnover may be considered exclusively to calculate the maximum fine amount is unsustainable,\u201d because a fine needs to be effective, proportionate and dissuasive.<\/p>\n<p>Furthermore, GDPR explicitly provides for dynamic fines, which should allow for taking into account turnover as well as other considerations, like intent or negligence and others mentioned in Article 83(2) GDPR.<\/p>\n<p>This is also considered in line with case law from the Court of Justice, especially when it comes to the dissuasiveness of the fine.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/compliance\/\" class=\"badge\">Compliance<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/eu\/\" class=\"badge\">EU<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/gdpr\/\" class=\"badge\">GDPR<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>Irish Data Protection Commission imposes \u20ac225M fine on WhatsApp for GDPR violations. Sanctions follow EDPB binding decision. Explore the new Irish fine details.<\/p>\n","protected":false},"featured_media":1687,"template":"","topic-resource":[61,69,63],"type-resource":[6],"class_list":["post-2708","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-compliance","topic-resource-eu","topic-resource-gdpr","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>A New Irish Fine: Lessons Learned from the EDPB Binding Decision | TrustArc<\/title>\n<meta name=\"description\" content=\"Irish Data Protection Commission imposes \u20ac225M fine on WhatsApp for GDPR violations. Sanctions follow EDPB binding decision. Explore the new Irish fine details.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/\",\"name\":\"A New Irish Fine: Lessons Learned from the EDPB Binding Decision | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"datePublished\":\"2021-09-09T19:28:00+00:00\",\"dateModified\":\"2024-12-05T16:36:17+00:00\",\"description\":\"Irish Data Protection Commission imposes \u20ac225M fine on WhatsApp for GDPR violations. Sanctions follow EDPB binding decision. Explore the new Irish fine details.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/lessons-from-edpb-binding-decision\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"A New Irish Fine: Lessons Learned from the EDPB Binding Decision | TrustArc","description":"Irish Data Protection Commission imposes \u20ac225M fine on WhatsApp for GDPR violations. Sanctions follow EDPB binding decision. Explore the new Irish fine details.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/","url":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/","name":"A New Irish Fine: Lessons Learned from the EDPB Binding Decision | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","datePublished":"2021-09-09T19:28:00+00:00","dateModified":"2024-12-05T16:36:17+00:00","description":"Irish Data Protection Commission imposes \u20ac225M fine on WhatsApp for GDPR violations. Sanctions follow EDPB binding decision. Explore the new Irish fine details.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/lessons-from-edpb-binding-decision\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1687"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2708"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2708"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}