HOME

TheInfoList



OR:

NOYB – European Center for Digital Rights (styled as noyb, from "none of your business") is a non-profit organization based in Vienna, Austria established in 2017 with a pan-European focus. Co-founded by Austrian lawyer and privacy activist Max Schrems, NOYB aims to launch strategic court cases and media initiatives in support of the General Data Protection Regulation (GDPR), the proposed ePrivacy Regulation, and information privacy in general. The organisation was established after a funding period during which it has raised annual donations of €250,000 by supporting members. Currently, noyb is financed by more than 4,400 supporting members. While many privacy organisations focus attention on governments, noyb puts its focus on privacy issues and privacy violations in the private sector. Under Article 80, the GDPR foresees that non-profit organizations can take action or represent users. noyb is also recognized as a "qualified entity" to bring consumer class actions in Belgium.


Notable actions


EU–US data transfers/'Schrems I' (2016)

The Irish Data Protection Commission (DPC) filed a lawsuit against Schrems and
Facebook Facebook is an online social media and social networking service owned by American company Meta Platforms. Founded in 2004 by Mark Zuckerberg with fellow Harvard College students and roommates Eduardo Saverin, Andrew McCollum, Dustin Mosk ...
in 2016, based on a complaint from 2013, which had led to the so-called " Safe Harbor Decision". Back then, the
Court of Justice of the European Union The Court of Justice of the European Union (CJEU) (french: Cour de justice de l'Union européenne or "''CJUE''"; Latin: Curia) is the judicial branch of the European Union (EU). Seated in the Kirchberg quarter of Luxembourg City, Luxembo ...
(CJEU) had invalidated the Safe Harbor data transfer system with its decision. When the case was referred back to the DPC the Irish regulator found that Facebook had in fact relied on Standard Contact Clauses, not on the invalidated Safe Harbor. The DPC then found that there were "well-founded" concerns by Mr Schrems under these instruments too, but instead of taking action against Facebook, initiated proceedings against Facebook and Mr Schrems before the Irish High Court. The case was ultimately referred to the CJEU in C-311/18 (called 'Schrems II': see Max Schrems#Schrems II). noyb supported this private case of Mr Schrems.


"Forced consent" complaints (2018)

Within hours after
General Data Protection Regulation The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in par ...
rules went into effect on 25 May 2018, noyb filed complaints against Facebook and subsidiaries
WhatsApp WhatsApp (also called WhatsApp Messenger) is an internationally available freeware, cross-platform, centralized instant messaging (IM) and voice-over-IP (VoIP) service owned by American company Meta Platforms (formerly Facebook). It allows u ...
and
Instagram Instagram is a photo and video sharing social networking service owned by American company Meta Platforms. The app allows users to upload media that can be edited with filters and organized by hashtags and geographical tagging. Posts can ...
, as well as
Google LLC Google LLC () is an American multinational technology company focusing on search engine technology, online advertising, cloud computing, computer software, quantum computing, e-commerce, artificial intelligence, and consumer electronics. ...
(targeting Android), for allegedly violating Article 7(4) by attempting to completely block use of their services if users decline to accept all data processing consents, in a bundled grant which also includes consents deemed unnecessary to use the service. Based on the complaint, the French data protection authority CNIL has issued a €50 million fine against Google LLC. The other cases are still pending.


Apple Tracking Case (2020)

In mid November 2020, noyb.eu announced that complaints were filed to both the German and Spanish Data Protection Authorities, claiming "IDFA (Apple’s Identifier for Advertisers) allows Apple and all apps on the phone to track a user and combine information about online and mobile behaviour". In a slight change from their previous legal strategy in other similar cases, noyb notes that, because the complaint is based on Article5(3) of the e-Privacy Directive and not GDPR, the Spanish and German authorities can directly fine Apple, without appealing to EU Data Protection Authorities under GDPR.


Open letter on GDPR cooperation mechanism (2020)

noyb also focuses on putting pressure on regulators to enforce privacy laws on the books. In an open letter, the NGO has accused the Irish Data Protection Commission of acting too slowly and having 10 meetings with Facebook before the coming into application of the GDPR.


Schrems II - Court of Justice Judgment on Privacy Shield (2020)

On July 16, 2020, the Court of Justice of the European Union (CJEU) invalidated Privacy Shield and decided that Facebook and other companies that fall under US surveillance laws cannot rely on “Standard Contractual Clauses” (SCCs) since US surveillance laws were found to be conflicting EU fundamental rights. This judgement was based on a long lasting case of Max Schrems and noyb. US companies’ foreign customers’ data are not protected from the U.S. intelligence services. The CJEU found that this violates the “essence” of certain EU fundamental rights. The Court has also clarified that EU data protection authorities (DPAs) have a duty to take action. The Court highlighted that a DPA is “required to execute its responsibility for ensuring that the GDPR is fully enforced with all due diligence”. Despite the invalidations made by the judgment, absolutely "necessary" data flows can continue to flow under Article 49 of the GDPR. Any situation where users want their data to flow abroad is still legal, as this can be based on the informed consent of the user, which can be withdrawn at any time. Equally the law allows data flows for what is "necessary" to fulfil a contract. Mass Complaints on EU-US Data Transfers (2020) After the Schrems II judgment, B filed 101 complaints against EU/EEA companies against controllers using Google Analytics or Facebook Connect and thereby transferring data to the US  despite the Court finding (link to Privacy Shield) that US surveillance laws violate the essence of EU fundamental rights. The organization thereby wanted to point out the lack of enforcement of Schrems II. These model complaints led to the creation of a special taskforce by the European Data Protection Board (EDPB) which is tasked to coordinate the complaints and to prepare recommendations for controllers and processors. On January 12, 2022, the Austrian Data Protection Authority (DSB) reached a partial decision in favour of noyb, stating that the continuous use of Google Analytics violates the GDPR. This decision affects most websites in the European Union since Google Analytics is the most common traffic analysis tool.


Google Advertising ID tracking (2021)

On April 7, 2021, noyb filed a complaint in France charging that Android users were being tracked by Google without giving consent. "Google’s software creates the AAID without the user’s knowledge or consent. The identification number functions like a license plate that uniquely identifies the phone of a user and can be shared among companies. After its creation, Google and third parties (e.g. applications providers and advertisers) can access the AAID to track users’ behaviour, elaborate consumption preferences and provide personalised advertising. Such tracking is strictly regulated by the EU “Cookie Law” (Article 5(3) of the e-Privacy Directive) and requires the users’ informed and unambiguous consent."


Facebook and DPC complaint (2021)

NOYB has filed a complaint against the irish
Data Protection Commissioner The Office of the Data Protection Commissioner ( Irish: An Coimisinéir Cosanta Sonraí) (DPC), also known as Data Protection Commission, is the independent national authority responsible for upholding the EU fundamental right of individuals t ...
(DPC) in for corruption and possible bribery in 2021 under austrian law for an affair concerning Facebook.


Administrative fine for Grindr over illegal sharing of user data (2021)

Together with the Norwegian Consumer Council, noyb filed three strategic complaints against the dating app
Grindr Grindr () is a location-based social networking and online dating application targeted towards members of the gay, bisexual, transgender, and queer community. It was one of the first geosocial apps for gay men when it launched in March 2009 a ...
and several adtech companies over illegal sharing of users’ data in January 2020.  The data shared was GPS location, IP address, Advertising ID, age, gender and the fact that the user in question was on Grindr. Users could be identified through the data shared, and the recipients could potentially further share the data. These complaints are based on the report “Out of Control” by the Norwegian Consumer Council. One year after the complaint was filed, the Norwegian Data Protection Authority upheld the complaint against Grindr, confirming that Grindr did not receive valid consent from users in an advance notification. The Authority imposed a fine of 100 million NOK (€9.63 million) on Grindr which was then reduced to 65 million NOK (€6.5 million) in the final decision since Grindr's actual revenue was lower than previously assumed and the company undertook measures to remedy deficiencies in their previous consent management platform.


Action against the use of " Dark Patterns" in cookie banners (2021)

On August 10, 2021, noyb filed 422 complaints against companies using deceptive cookie banners on their website. This wave of complaints was the outcome of a “Legal Tech” initiative by the organization in the course of which thousands of websites in Europe had been automatically checked for violations with a tool that was developed specifically for this purpose. In response to those complaints an EDPB taskforce was set up to exchange views on legal analysis and possible infringements and to streamline communication In its effort to overcome the necessity of cookie banners, noyb has also co-developed Advanced Data Protection Control together with the Sustainable Computing Lab of the Vienna University of Economics. The ADPC browser signal poses a feasible alternative to cookie banners through its automated mechanism for the communication of users’ privacy decisions and data controllers’ responses.


Austrian Court: Google Analytics illegal in Europe (2022)

In early 2022, an Austrian court ruled that the use of
Google Analytics Google Analytics is a web analytics service offered by Google that tracks and reports website traffic, currently as a platform inside the Google Marketing Platform brand. Google launched the service in November 2005 after acquiring Urchin. As o ...
on European websites was illegal. The case in question was filed in August 2020, from a Google user accessing an Austrian website for health related issues. The website used Google Analytics, and data about the user was transmitted to Google. The Google user complained to the Austrian data protection authority alongside noyb. The issue at hand has a direct reference to Article 44 under GDPR, since the user cannot be afforded the correct level of protections established, thus making it a clear violation of GDPR. France's data watchdog CNIL concurred with the Austrian ruling in mid February 2022. Schrems duly commented: Furthermore, in mid 2022, the Austrian DPA also ruled that
Google Google LLC () is an American multinational technology company focusing on search engine technology, online advertising, cloud computing, computer software, quantum computing, e-commerce, artificial intelligence, and consumer electronic ...
's
anonymization Data anonymization is a type of information sanitization whose intent is privacy protection. It is the process of removing personally identifiable information from data sets, so that the people whom the data describe remain anonymous. Overv ...
was insufficient in protecting user privacy, and that Article 44 of
GDPR The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in part ...
does not allow for a risk-based approach that Google had argued for.


Other

NOYB also started a collaborative wiki on the
General Data Protection Regulation The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in par ...
, calle
GDPRhub.eu
On the webpage they collect English summaries of local GDPR decisions by Data Protection Authorities or Courts.


References


External links

* {{Portal bar, Austria, European Union, Law 2017 establishments in Austria Information privacy Information technology organisations based in Austria Internet privacy organizations Data protection Cross-European advocacy groups Privacy organizations