In case No. C-40/17 (“Fashion ID GmbH & co. KG”) the Court of Justice of the EU found that even under Directive 95/46 data controllers must fulfill their obligations towards data subjects in cases where their website has a Facebook ‘Like’ button.
The judgement raises the question on the responsibility of data controllers who transfer parts of personal data to third parties or social network platforms for processing. Nowadays every website contains plug-ins for various social networks (Facebook, Twitter, etc.) which are aimed to develop the online presence of products offered. Similarly to Fashion ID, all those plugins can transfer personal data of the website’s visitors to a social network of choice, which can in turn send the visitors’ personal data to its corporate backers even in cases where the visitors have no social network profiles whatsoever.
The Court found that the website administrator’s obligations in their capacity as data controller pursuant to the Directive are limited to liability in relation to data processing for which they determine the purposes and means of processing, namely the very transfer of personal data to Facebook.
To limit the dangers of transfer of personal data via prima facie harmless plug-ins, data controllers who maintain websites have to:
1. Explicitly inform the visitors of the possibility of their data being transferred to third party data controllers;
2. Ask the visitors for their consent for such processing of personal data. The visitors must have the option to refuse the transfer of their data to the data controllers who own the plugins. Other grounds for data processing pursuant to Art. 6 GDPR will hardly be applicable in this case;
3. Enter into comprehensive joint data controllers agreements pursuant to Art. 26 GDPR with the plugin operators. Failure to conclude such an agreement can be independent grounds for fines for breach of Art. 26, para. 1 GDPR, even if the rights of the data subjects have not been breached in any other way.
The complete and uncompromising performance of obligations under GDPR guarantees the safety of both data subjects and their data, as well as of the data controllers in the increasingly regulated world of IT and the Internet.
—————————
Sources: Judgment of the Court (Second Chamber) of 29 July 2019 in case No. C-40/17 (“Fashion ID GmbH & Co. KG”)
Regulation (EU) 2016/679 нof the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; GDPR)
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
Do not hesitate to contact us at office@codilex.eu if you have any questions dealing with the complex challenges of personal data protection.


