abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb

이 페이지는 한국어로 제공되지 않으며 English로 표시됩니다.

기사

31 8월 2023

저자:
Natasha Lomas, TechCrunch

EU: Google's Fitbit faces three privacy complaints which allege the company is illegally exporting user data in breach of the GDPR

"Fitbit targeted with trio of data transfer complaints in Europe", 31 August 2023

Google-owned Fitbit is facing a trio of privacy complaints in the European Union which allege the company is illegally exporting user data in breach of the bloc’s data protection rules.

The complaints target Fitbit’s claim that users have consented to international transfers of their information — to the US and elsewhere — arguing the company is forcing consent from users which does not meet the required legal standard.

The lawful basis being claimed by Fitbit to export EU users’ data — consent — needs to meet certain standards to be valid. In short, it must be informed, specific and freely given. But the complaints argue Fitbit is illegally forcing consent since users wanting to use products and services they have paid for have no choice to consent to the data exports in order for the products to work.

The complaints also allege Fitbit is failing to provide adequate information to users regarding transfers of their data — meaning they also cannot provide informed consent, as the GDPR requires. They also highlight that Fitbit users are unable to withdraw consent as they should be able to under the GDPR — short of deleting their Fitbit accounts and losing all their tracked workouts. Which means Fitbit users face having their product experience penalized for revoking consent. 

European privacy rights not-for-profit, noyb, has filed the complaints with data protection authorities in Austria, the Netherlands and Italy on behalf of three (unnamed) Fitbit users.

Commenting in a statement, Maartje de Graaf, data protection lawyer at noyb, said: “First, you buy a Fitbit watch for at least €100. Then you sign up for a paid subscription, only to find that you are forced to ‘freely’ agree to the sharing of your data with recipients around the world. Five years into the GDPR, Fitbit is still trying to enforce a ‘take it or leave it’ approach.”

While the EU’s executive body, the European Commission, adopted a new adequacy data transfer agreement with US counterparts last month — a high level deal which aims to shrink the legal risks around transatlantic data flows — noyb notes that Fitbit is not claiming to rely on this so-called EU-US Data Privacy Framework for EU users’ data exports.

“Apart from that, it is only a matter of time until noyb will be challenging the validity of the new framework before the CJEU [Court of Justice of the EU]. The fundamental problems with US surveillance laws still exist.”

noyb confirmed it expects the three complaints to be funnelled back to Google’s lead data protection watchdog in the EU, Ireland’s Data Protection Commission (DPC), in line with the GDPR’s one-stop-shop mechanism for streamlining cross-border complaints.

..., given the DPC’s record on oversight of big tech, a swift outcome to this trio of Fitbit complaints seems unlikely — even as enforcement of the GDPR more generally has been gathering some momentum, thanks to a growing body of clarifying CJEU rulings in the five+ years since it came into application.

If noyb’s complaints against Fitbit trigger an investigation by the DPC — and GDPR infringements are confirmed down the line — Google could face fines in the billions of dollars given its parent company, Alphabet, saw its annual revenue reach $283BN last year. (noyb suggests it could be on the hook for fines of up to €11.28BN if the breaches are confirmed.)

개인정보

이 웹사이트는 쿠키 및 기타 웹 저장 기술을 사용합니다. 아래에서 개인정보보호 옵션을 설정할 수 있습니다. 변경 사항은 즉시 적용됩니다.

웹 저장소 사용에 대한 자세한 내용은 다음을 참조하세요 데이터 사용 및 쿠키 정책

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

분석 쿠키

ON
OFF

귀하가 우리 웹사이트를 방문하면 Google Analytics를 사용하여 귀하의 방문 정보를 수집합니다. 이 쿠키를 수락하면 저희가 귀하의 방문에 대한 자세한 내용을 이해하고, 정보 표시 방법을 개선할 수 있습니다. 모든 분석 정보는 익명이 보장되며 귀하를 식별하는데 사용하지 않습니다. Google은 모든 브라우저에 대해 Google Analytics 선택 해제 추가 기능을 제공합니다.

프로모션 쿠키

ON
OFF

우리는 소셜미디어와 검색 엔진을 포함한 제3자 플랫폼을 통해 기업과 인권에 대한 뉴스와 업데이트를 제공합니다. 이 쿠키는 이러한 프로모션의 성과를 이해하는데 도움이 됩니다.

이 사이트에 대한 개인정보 공개 범위 선택

이 사이트는 필요한 핵심 기능 이상으로 귀하의 경험을 향상시키기 위해 쿠키 및 기타 웹 저장 기술을 사용합니다.