abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb

这页面没有简体中文版本,现以English显示

文章

31 八月 2023

作者:
Natasha Lomas, TechCrunch

EU: Google's Fitbit faces three privacy complaints which allege the company is illegally exporting user data in breach of the GDPR

"Fitbit targeted with trio of data transfer complaints in Europe", 31 August 2023

Google-owned Fitbit is facing a trio of privacy complaints in the European Union which allege the company is illegally exporting user data in breach of the bloc’s data protection rules.

The complaints target Fitbit’s claim that users have consented to international transfers of their information — to the US and elsewhere — arguing the company is forcing consent from users which does not meet the required legal standard.

The lawful basis being claimed by Fitbit to export EU users’ data — consent — needs to meet certain standards to be valid. In short, it must be informed, specific and freely given. But the complaints argue Fitbit is illegally forcing consent since users wanting to use products and services they have paid for have no choice to consent to the data exports in order for the products to work.

The complaints also allege Fitbit is failing to provide adequate information to users regarding transfers of their data — meaning they also cannot provide informed consent, as the GDPR requires. They also highlight that Fitbit users are unable to withdraw consent as they should be able to under the GDPR — short of deleting their Fitbit accounts and losing all their tracked workouts. Which means Fitbit users face having their product experience penalized for revoking consent. 

European privacy rights not-for-profit, noyb, has filed the complaints with data protection authorities in Austria, the Netherlands and Italy on behalf of three (unnamed) Fitbit users.

Commenting in a statement, Maartje de Graaf, data protection lawyer at noyb, said: “First, you buy a Fitbit watch for at least €100. Then you sign up for a paid subscription, only to find that you are forced to ‘freely’ agree to the sharing of your data with recipients around the world. Five years into the GDPR, Fitbit is still trying to enforce a ‘take it or leave it’ approach.”

While the EU’s executive body, the European Commission, adopted a new adequacy data transfer agreement with US counterparts last month — a high level deal which aims to shrink the legal risks around transatlantic data flows — noyb notes that Fitbit is not claiming to rely on this so-called EU-US Data Privacy Framework for EU users’ data exports.

“Apart from that, it is only a matter of time until noyb will be challenging the validity of the new framework before the CJEU [Court of Justice of the EU]. The fundamental problems with US surveillance laws still exist.”

noyb confirmed it expects the three complaints to be funnelled back to Google’s lead data protection watchdog in the EU, Ireland’s Data Protection Commission (DPC), in line with the GDPR’s one-stop-shop mechanism for streamlining cross-border complaints.

..., given the DPC’s record on oversight of big tech, a swift outcome to this trio of Fitbit complaints seems unlikely — even as enforcement of the GDPR more generally has been gathering some momentum, thanks to a growing body of clarifying CJEU rulings in the five+ years since it came into application.

If noyb’s complaints against Fitbit trigger an investigation by the DPC — and GDPR infringements are confirmed down the line — Google could face fines in the billions of dollars given its parent company, Alphabet, saw its annual revenue reach $283BN last year. (noyb suggests it could be on the hook for fines of up to €11.28BN if the breaches are confirmed.)

隐私资讯

本网站使用 cookie 和其他网络存储技术。您可以在下方设置您的隐私选项。您所作的更改将立即生效。

有关我们使用网络存储的更多信息,请参阅我们的 数据使用和 Cookie 政策

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

分析 cookie

ON
OFF

您浏览本网页时我们将以Google Analytics收集信息。接受此cookie将有助我们理解您的浏览资讯,并协助我们改善呈现资讯的方法。所有分析资讯都以匿名方式收集,我们并不能用相关资讯得到您的个人信息。谷歌在所有主要浏览器中都提供退出Google Analytics的添加应用程式。

市场营销cookies

ON
OFF

我们从第三方网站获得企业责任资讯,当中包括社交媒体和搜寻引擎。这些cookie协助我们理解相关浏览数据。

您在此网站上的隐私选项

本网站使用cookie和其他网络存储技术来增强您在必要核心功能之外的体验。