Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

EDPB Clarifies Consent Requirements for 'Pay or Okay' Models

The European Data Protection Board has adopted a significant opinion on the 'consent or pay' model increasingly used by large online platforms. The EDPB stated that in most cases, these platforms will not be able to comply with the GDPR's requirements for valid consent if they only present users with a binary choice between consenting to personal data processing for behavioral advertising or paying a fee. The board highlighted that consent must be freely given, and the lack of a genuine choice can invalidate it. It also strongly encourages platforms to develop a free 'equivalent alternative' that does not involve behavioral advertising, suggesting this as a key way to ensure choice is real.

Today's question

A filing system under GDPR Article 4(6) is:

  1. Any structured set of personal data accessible by specific criteria
  2. Any computer system used by a controller is a filing system
  3. Databases managed by IT departments are the type that qualifies
  4. Paper files stored in physical offices are the filing systems

Answer this question on the site

Worth knowing

  1. New Draft of American Privacy Rights Act Released by Congress

    A revised discussion draft of the bipartisan American Privacy Rights Act has been released by U.S. congressional leaders, signaling continued momentum for a federal privacy law. The updated text includes key changes to definitions, expands the scope of entities covered, and makes adjustments to the private right of action, as lawmakers work to find a compromise that can pass both chambers.

  2. UK ICO Issues Final Guidance on Biometric Data Processing

    The UK Information Commissioner's Office published its finalized guidance on processing biometric data for purposes of unique identification under the UK GDPR. The guidance clarifies what constitutes 'special category' biometric data, stresses the high risk nature of the processing, and confirms that a Data Protection Impact Assessment (DPIA) is mandatory in most cases.

  3. FTC Expands Scope of Health Breach Notification Rule

    The U.S. Federal Trade Commission finalized updates to the Health Breach Notification Rule, significantly broadening its reach to cover health apps and other non HIPAA covered digital health services. The rule now makes it clear that an unauthorized disclosure of identifiable health information to a third party, such as an advertising platform, constitutes a 'breach of security' requiring notification to consumers and the FTC.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.