It's not yet on everyone's lips, but companies should gradually get a move on, especially if they handle customer data. We're talking about the General Data Protection Regulation (GDPR), which comes into force at the beginning of 2018. Never heard of it? Then it's high time, because there isn't much time left to prepare. Changes will specifically affect all companies that handle customer data, and faux pas will then be subject to severe penalties. But first, let's go back to the beginning. For three years now, representatives of the European Union have been negotiating an EU-wide regulation for the protection of natural persons with regard to the processing of personal data.
Aim of the GDPR
The declared aim and purpose is, among other things, to establish “the harmonisation of the rules for the protection of fundamental rights and freedoms of natural persons with regard to the processing of personal data and to ensure the free movement of personal data between Member States”. The special thing about this legal provision, in contrast to other EU regulations, is that individual Member States are not allowed to weaken or strengthen data protection through national ratification procedures. Nevertheless, minor deviations can be achieved through national legislative procedures to adapt them to national law. This also means that looking at German legislation can be worthwhile, but is not always applicable to Austria. This should always be considered. Let's continue now.
What is regulated
Among other things, the regulation governs the legal bases for data processing, the rights of data subjects, and the obligations of controllers. The existing rights of data subjects are extended and supplemented with new rights. The result was Regulation (EU) 2016/679 of the European Parliament and of the Council on 4 May 2016.
Who does the General Data Protection Regulation affect?
The General Data Protection Regulation affects all companies that collect or process personal data in any way. In the following, we would like to dedicate ourselves to the innovations that will specifically affect us as service providers, processors and customers. Potential pitfalls will also be highlighted.
It should be mentioned at this point that legal advice should always be sought for definitive security, and the information and research provided have been prepared to the best of our knowledge, but without guarantee. While previous penalties for companies, for example, in the event of failure to provide information or correction in a timely manner, were manageable, these will be significantly more severe in the future. The penalty framework provides for fines of up to 20 million euros or 4% of the company's turnover. Not a small sum, we might add, especially since it is to be assumed that the first warnings will follow immediately after the regulation comes into force.
Consent
The General Data Protection Regulation is drafted as a so-called prohibition law with a proviso for permission. This means that handling personal data is generally prohibited unless a legal provision permits it or the data subject's permission has been given or obtained.
However, the question of what constitutes valid consent is highly controversial and still the subject of many discussions.
Under point 32 ff. ((EU) 2016/679), scenarios of consent are described. It must be noted that consent must be unambiguous, freely given, specific, informed, and unambiguous. This means, for example, that a checkbox is permissible, but its pre-selection is not. Likewise, consent given involuntarily or through inaction is invalid. A user must therefore always be clearly and unambiguously informed about the use of their data. For us, however, the question also arises whether data processing can be directly included in the contract or the general terms and conditions (GTCs) in order to operate within a legally secure framework. One thing first: dangerous and highly controversial.
Discussion of the so-called Prohibition of Coupling
Dürager & Kotschy state that doubts about voluntariness arise when consent clauses for data use are subjected to a common consent declaration together with other clauses, without the data subject being able to choose between the clauses. According to the authors, this problem regularly arises in connection with contracts in the form of General Terms and Conditions (GTCs) when the data subject cannot delete specific data use clauses – according to the will of the other contracting party. (INNOVATIONS ON CONSENT UNDER THE GDPR Contribution to the General Data Protection Regulation) According to Dürager & Kotschy (P.9ff), further uncertainties arise for practice, as no indications are provided as to when situations exist in which coupling might be permissible because there is no doubt about the voluntariness of consent.
The authors discuss a complex of questions that is important for us and our customers, with practical relevance, in connection with marketing applications. Among other things, they raise the question of whether there are limits to a “waiver of fundamental rights for remuneration” or whether the freedom of contract design prevails. This would be the case, for example, if a user is given the choice of providing services for a fee or whether payment based on data processing is permissible. Unfortunately, no definitive answers can be provided here yet, and at this point, we only have the option of waiting for further rulings, etc.
Processing of Data based on Legitimate Interests
Immediately relevant to us is also point 47. This passage describes legitimate interests between processor and data subject and also touches upon the customer relationship. One passage states: “A legitimate interest could exist, for example, where there is a relevant and appropriate relationship between the data subject and the controller, e.g., where the data subject is a customer of the controller or in his service.” However, in the passage itself, the fundamental freedoms of the data subject are given higher weighting than the interests of the processor.
The following sentence can be found at the end: “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” From this, it can be concluded that if consent for further processing (see above) is given, newsletters can, for example, be sent to customers, provided that a proper opt-in/opt-out option is available. (P. 111 ((2012/0011 (COD))
Although the basis in this matter is very vague and an opt-in might not be conceivable, one should always offer an opt-in to be on the safe side, even to meet the documentation requirements. Since the topic is very extensive and complex, we will discuss the documentation requirements and further outlooks on this upcoming amendment in a subsequent article.
Digression: Austrian Data Protection Authority
On the website of the Data Protection Authority of the Republic of Austria, you will find all relevant legal texts applicable to Austria in their current version. Always worth a look for further in-depth study.

