
It’s complicated. You could make the decision to leave a social platform because you’d like to use another application that has better terms. But when you install it, and invite everyone you like to join you, you may find a person who decides to stay. Perhaps they dislike the other company’s data practices even more than those they currently use. But your acceptance button records nothing but an agreement that the transaction is settled.
This is the rationale behind Enrique Dans’ manifesto for European rejection of the way Big Tech has come to influence society, seen through the lens of the European approach to personal information, which connects it back to the rights of the person it concerns, rather than just what accepting the service’s conditions means. Wherever you come down on consent under the GDPR, it’s clear that freely given, informed permission about how this data may be used precisely has to be given beforehand.
It’s difficult to talk about freely without acknowledging that the ability to stop using a service is less meaningful if stopping carries a substantial cost. Or that in some cases, a technically optional arrangement is in practice so difficult to refuse that doing so would be unwise.
This is not to suggest that this invalidates any agreement made in such situations, or that every platform is equally problematical. But if people know they won’t be able to prove they disapprove of anything they do, then that is an excellent reason for a regulator to specify what freely means.
Imagine trying to figure out what someone could turn down, and whether or not that choice would deprive them of the ability to use the product in question, and whether or not they will be able to use what’s left. It’s a useful thought experiment to get out from under the rather narrow question of whether clicking a consent form documents a decision.
Dans also gives a good overview of how the principle of informational self-determination has evolved in Germany since a 1983 ruling by the Federal Constitutional Court over a census.
Of particular interest is the Court’s analysis of how informational self-determination is weakening if people are uncertain about who knows them and what use will be made of that information.
A census and a social platform application collect information about you for entirely different purposes. However, what information is collected, and how it is used, depends on your position. The fact that you have no influence over the data collection helps little to protect your interests. Likewise, obtaining information about you does not give the institution collecting the data a license to view the individual as a mere aggregate of that information. A history of such issue is useful for considering whether any modern regulation has been able to address it.
According to Dans, the fact that Europe has not been successful at solving the privacy problems, is a qualification that limits its claim to have diagnosed the problem before the United States. While the recognition of a danger is an important first step, it is not an accomplishment by itself if an effective means of reducing that danger has not been found.
Yet another explanation for what is seen as a difference between Washington and Brussels is that the companies themselves are American, and that their regulation may have political costs for the United States that do not exist for the EU.
This means control over the information and services with which you interact. It means the ability to easily leave a service when it no longer meets your needs. It requires service providers to explain clearly the information they collect and what they do with it. And better information about what services collect your data gives you more bargaining power in deciding whether to accept or not.
And this is all independent of how American and European attitudes towards privacy might change, or how American attitudes about the economically disruptive effects of privacy protection might evolve alongside European ones. Building an argument that depends on any of those things running exactly the same direction on either side of the Atlantic will clearly outrun the pace of change.
Rather, the ability to control the information and services with which you interact is as broadly applicable to foreign companies as it is to the dominant platforms in the US.
As well as affecting alternatives directly, compliance might indirectly affect who is able, and willing, to compete. For example, if a requirement imposes substantial fixed costs that only large providers can absorb, this might reduce competition, but evidence would be needed for that. Some obligations might also make it less easy for existing users to improve the protections that they already have. It would be necessary to know whether that is a risk, and if so whether the business costs of compliance, if any, and the number of companies likely to remain in the market, provided a sufficient measure of the effect. There will be people seeking to exercise the rights that the law offers, some of whom will be told this is not as straightforward as it should be, others who will find they cannot afford to lose what could be a valuable service, and for whom the right to challenge the use of their information may be too burdensome.
Europe’s historical experience and position in the platform economy explain its institutions’ desire to provide this type of protection. Consider whether protections like these actually provide the desired results. The question of whether people have the option to refuse unwanted data and whether a complaint is likely to change the company’s behavior has already been addressed. There is also the option of leaving. Someone who objects to the terms but stays, because the alternatives are worse, is nonetheless included in the assessment, however clearly their agreement has been recorded.
References:
Three reasons Europe learned to distrust Big Tech before America did
Guidelines 05/2020 on consent under Regulation 2016/679
Judgment of the First Senate of 15 December 1983 — 1 BvR 209/83
