UK GDPR Reforms Back on the Table, Noyb Targets Microsoft's Xandr, California Tightens CCPA Rules
Privacy Corner Newsletter: July 18, 2024
By Robert Bateman and Privado.ai
In this edition of the Privacy Corner Newsletter:
The UK’s new government will resurrect parts of its predecessor’s controversial data protection reform bill
The newly elected UK government has set out its legislative agenda, including the introduction of a Digital Information and Smart Data Bill (DISDB) that will apparently include elements of the previous government’s Data Protection and Digital Information Bill (DPDIB).
? So the DPDIB is back?
Not exactly. While we don’t yet have a copy of the government’s planned DISDB, it appears that the bill will incorporate some of the DPDIB’s provisions, including:
The speech also mentioned “targeted reforms to some data laws”, which could mean that other DPDIB provisions return under the new bill.
? What about the AI bill?
Prior to the King’s Speech, the government had mentioned “AI legislation” impacting larger tech companies, leading many to predict the introduction of an AI bill akin to the EU AI Act. But no AI bill has emerged.
In February, Member of Parliament (MP) Peter Kyle (now Security of State for Business, Innovation, and Skills) discussed a “statutory code” requiring AI companies to “share testing data” with the government.
A statutory code is not a bill, which could explain its absence from the list of 39 bills introduced under the King’s Speech.
The government also says its proposed Product Safety and Metrology Bill will “enable the UK to keep pace with technological advances, such as AI”.
So it appears that some form of AI-specific regulation is planned in the UK—even if it isn’t quite as extensive as the EU AI Act (which, incidentally, was published in the EU’s Official Journal last week).
Noyb’s latest complaint targets Xandr, a Microsoft-owned adtech firm that rejected nearly 2,000 data requests last year
Privacy campaign group noyb has submitted a complaint to the Italian Data Protection Authority (DPA) against Xandr, an adtech company owned by Microsoft.
? What’s the background?
As noted above, Xandr is an adtech company owned by Microsoft. The company operates an ad-bidding system and a DSP that associates internet users with inferences about their preferences and characteristics (“market segments”) based on data collected via cookies.
The complainant in this case visited certain websites where cookies were placed on his device by:
Using each company’s respective cookie ID, the complainant made data subject rights requests to Emetriq and Xandr.
领英推荐
? How did the companies respond?
Emetriq came back with a list of market segments associated with the relevant cookie ID. The company revealed that it had inferred, reportedly within a period of two hours, that the complainant was:
Obviously, these inferences are contradictory. Noyb therefore alleges that Xandr, which receives data from Emetriq, violates the accuracy principle and misleads its customers regarding the quality of its data.
Xandr said it could not facilitate the complainant’s requests because its ad platform “contains consumers’ pseudonymous personal data and not personally identifiable information (such as name or plain text email address),” but later stated that it would delete the cookie ID provided by the complainant.
? But the complainant provided pseudonymous data, not his name or email
Indeed, Xandr’s response does not appear to relate to the complainant’s request. On its website, Xandr publishes metrics relating to “consumer data requests” revealing that, in 2022, Xandr:?
? Why is Xandr telling people this?
Xandr might be publishing these response rates as part of its obligations under the California Consumer Privacy Act (CCPA). Under the California Attorney General’s CCPA Regulations, certain larger businesses must publish metrics relating to compliance with the law’s consumer rights.
Xandr could also be relying on the CCPA’s definition of “deidentified” information to assert that it cannot associate noyb’s complainant with any data it holds. However, the company did agree to delete the identifier provided by the complainant.
Noyb has complained to the Data Protection Authority (DPA) in Italy, where the complainant lives, and argues that the Italian DPA should investigate Xandr directly rather than investigating its parent company, Microsoft.
While this argument is not unreasonable, a cynic might suggest it is noyb’s latest attempt to avoid the GDPR’s One-Stop Shop process, under which its complaint would be sent to Microsoft’s lead supervisory authority, the Irish DPA. The Italian DPA tends to be more decisive in its enforcement.
Proposed CCPA Regulations would introduce cybersecurity audits, add new definitions, and change the law’s application threshold
The California Privacy Protection Agency (CPPA) has published draft California Consumer Privacy Act (CCPA) Regulations with major implications for businesses subject to the law.
? What’s changed under these new proposed regulations?
The CPPA proposes many changes. Here are a few highlights, but bear in mind that we’re still at an early stage of the rulemaking process (despite being absurdly behind schedule).
? What about the cybersecurity audits?
As currently proposed, the following types of businesses will need to conduct annual cybersecurity audits:
The CPPA estimates that around 25,352 businesses in California will meet this threshold (note that many businesses outside California will, too).
Covered businesses will have to conduct their first audit within two years of the regulations taking effect. From that point on, businesses must send the CPPA a certification confirming that they have carried out the audit every year.
The proposed cybersecurity audit requirements are too extensive to list here in detail. Businesses can appoint a suitable person internally—subject to certain safeguards to ensure their independence—or hire an external auditor.
An economic assessment suggests that cybersecurity audit proposals would cost California businesses over $2 billion, with the total economic impact of the proposed regulations coming in at over $4.2 billion. And that’s just for businesses based in California.
As such, we can expect some resistance to these proposals from groups like the California Chamber of Commerce—and support from California-based tech consultancies.
What We’re Reading