According to Advocate General Jean Richard de la Tour, Member States may allow associations whose purpose is to protect consumers' interests to appear before courts with representative actions to protect them from personal data infringements. These actions should be based on a breach of the law which the data subjects are directly affected by the General Data Protection Regulation.
The German Bundesverband der Verbraucherzentralen und Verbraucherverbände – Verbraucherzentrale Bundesverband e.V.
(Federal Association of Headquarters and Consumer Associations, "Consumer Association") accuses Facebook Ireland of the infringement, in the framework of making the App-Center platform available with free games from operators third (1), personal data protection rules and rules to combat unfair competition and consumer protection.
In this context, the association of consumer organisations directed the German courts to order the cessation of harmful practices.
The Bundesgerichtshof (Federal Court of Justice, Germany) considers that Facebook Ireland did not provide users in a concise, transparent, understandable and easily accessible form, and a clear and simple language of the necessary information on the purpose for which their data are processed, as well as information on the recipient of the data. According to this court, Facebook Ireland has committed an infringement of the General Data Protection Regulation (‘GDPR’) (2).
However, the Bundesgerichtshof has doubts about the admissibility of the action brought by the association of consumer organisations.
It wonders whether a society whose purpose is to protect the interests of consumers, such as the association of consumer organisations, is still entitled, after the entry into force of the GDPR, to appear before civil courts with a lawsuit concerning the infringement of that regulation, regardless of the specific violations of the rights of individual data subjects and without the authority they have received.
In particular, the Bundesgerichtshof takes the view that, under the circumstances that GDPR confers on supervisory authorities increased powers in the field of monitoring, investigation and adoption of corrective measures, it follows that the task of enforcing this regulation is primarily the responsibility of those authorities.
The Bundesgerichtshof therefore asked the Court of Justice to interpret the GDPR.
In its opinion, Jean Richard de la Tour proposed to the Court to interpret the GDPR in such a way that it does not preclude national rules allowing associations to protect consumers' interests, to bring actions before courts against potential perpetrators of personal data infringements, citing a ban on unfair commercial practices, a violation of consumer protection laws or a ban on the application of invalid general contractual conditions, if the representative action is intended to enforce rights which persons whose data are processed derive directly from that regulation.
The Advocate General recalled that in the Fashion ID judgment (3) The Court took a position on a similar issue regarding the previous GDPR Directive 95/46 (4) . It decided at the time that this Directive does not preclude national rules allowing associations to protect consumers' interests from acting against the alleged infringer of personal data protection by judicial procedure.
The Advocate General considered that neither the fact of replacing Directive 95/46 the regulation, nor the fact that the GDPR contains a provision on representing data subjects, in the context of legal redress, cannot constitute grounds for contesting the Court’s decision in this regard.
In his opinion, Member States may also provide for the possibility, without the authorisation of the data subject and without the need to rely on specific cases of individually identified persons, representative actions to protect the collective interests of consumers, where they invoke a violation of the provisions of that Regulation which confer on data subjects the right of the subject.
This is the case, in turn, where consumer organisations bring an action against Facebook Ireland.
The Advocate General also stated that the GDPR does not preclude national rules which entitle associations whose purpose is to protect consumers' interests to appear before courts with actions aimed at ensuring compliance with the rights conferred by this Regulation, namely by establishing rules aimed at protecting consumers or combating unfair commercial practices.
Such rules may contain provisions similar to those contained in the Regulation, in particular as regards information on the processing of data subjects.
In this case, a breach of such a rule on the protection of personal data may at the same time entail a breach of the rules on consumer protection or protection against unfair commercial practices.
According to the Advocate General, such defence by collective consumer interests associations is in particular consistent with the GDPR's objective of ensuring a high level of protection of personal data.
Footnotes:
- Looking through the games available at App-Center on the day 26 November 2012 the user may have noticed a number of information displayed after clicking on the "Sofort spielen" (Play Now). This information indicated that the use of this application allows the game provider to obtain certain personal data and to publish on behalf of the user certain information, such as the results he obtained in the game. The use of the application involved acceptance by the user of its general conditions and its data protection policy. In addition, in the case of Scrabble, it is indicated that the user allows the application to post on his behalf posts concerning his status, as well as photos and other information.
- Regulation (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 (General Data Protection Regulation (Official Journal of the European Union L (2016), No. 119, p. 1).
- Judgment of the Court of Justice 29 July 2019 on Fashion ID (C-40/17; see also press release no. 99/19).
- Directive 95/46 of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data Official Journal of the European Union L (1995), No. 281, p. 31).