Advance Notification of an Administrative Fine – Disqus Inc
Total Page:16
File Type:pdf, Size:1020Kb
Disqus Inc. 717 Market St San Francisco CA 94103 Your reference Our reference Date 20/01801-5 02.05.2021 Advance notification of an administrative fine – Disqus Inc. Table of contents 1. Background ....................................................................................................................2 2. Advance notification .......................................................................................................3 3. Facts of the case ..............................................................................................................4 3.1 Factual background ..................................................................................................4 3.2 Press coverage by the NRK ......................................................................................7 3.3 Press coverage by Computerworld.no .......................................................................8 4. Relevant GDPR requirements .........................................................................................8 4.1 Material scope ..........................................................................................................8 4.2 Controller .................................................................................................................9 4.3 Territorial scope .......................................................................................................9 4.4 The supervisory authority ....................................................................................... 10 4.5 Principles relating to processing of personal data .................................................... 12 4.6 Profiling ................................................................................................................. 12 4.7 Transparent information, communication and modalities for the exercise of the rights of the data subject ............................................................................................................. 12 4.8 Information to be provided where personal data are collected from the data subject 13 4.9 Lawfulness of processing ....................................................................................... 14 5. Our assessment of the case ............................................................................................ 15 5.1 Material scope of the GDPR ................................................................................... 15 5.2 Controller ............................................................................................................... 16 5.3 Territorial scope of the GDPR ................................................................................ 17 Postal address: Office address: Phone: Fax: Ent.reg: Home page: P.O. Box 458 Sentrum Tollbugt 3 +47 22 39 69 00 +47 22 42 23 50 974 761 467 www.datatilsynet.no/en/ N-0105 OSLO 5.3.1 The applicable law .......................................................................................... 17 5.3.2 “the offering of goods or services…”............................................................... 17 5.3.3 “monitoring” the behaviour of data subjects in the EEA .................................. 19 5.4 The NO DPAs competence ..................................................................................... 20 5.5 The accountability principle ................................................................................... 23 5.6 Information to the data subjects .............................................................................. 25 5.6.1 Transparent information, communication and modalities for the exercise of the rights of the data subject ............................................................................................... 25 5.6.2 Information to be provided where personal data are collected from the data subject 27 5.7 Legal basis ............................................................................................................. 28 5.7.1 Disqus’ information regarding the processing activities ................................... 28 5.7.2 Disqus’ processing activities ........................................................................... 30 5.7.3 Our assessment of the legal basis ..................................................................... 30 6. Corrective measures ...................................................................................................... 41 6.1 General principles when assessing administrative fines .......................................... 41 6.2 Whether to impose an administrative fine ............................................................... 42 6.3 Deciding the amount of the administrative fine ....................................................... 49 7. Process ......................................................................................................................... 50 8. Access to documents ..................................................................................................... 50 9. Concluding remarks ...................................................................................................... 50 1. Background On 8 May 2020, the Norwegian Data Protection Authority (“NO DPA”, “we”) ordered Disqus Inc. (“Disqus”, “you”) to provide information regarding the processing of personal data about data subjects in Norway through the Disqus Widget, a comment widget used on multiple websites of Norwegian companies (hereinafter “the widget”). Disqus replied to the order to provide information by e-mail on 10 July 2020. Our order to provide information was sent after a series of news articles published by the NRK, the Norwegian Broadcasting Corporation, in which NRK described how Disqus processed personal data about Norwegian users, while, according to NRK, being unaware that the General Data Protection Regulation (“GDPR”) was applicable.1 1 See section 3.2 for more information. 2 The information Disqus has provided has not mitigated our concerns regarding the processing of personal data in question and its relation to the fundamental data protection principles of lawfulness and transparency. In light of the factual circumstances of the case, the pertinent processing of personal data appears to be in breach of several of the articles of the GDPR. We are therefore notifying you of our intent to sanction the apparent breaches with an administrative fine – see our reasoning in the paragraphs below. The purpose of an advance notification is to ensure that the case is clarified as thoroughly as possible before an administrative decision is made, and to allow for contradiction.2 In other words, this is a draft decision. Before making a final decision, we will take into account Disqus’ comments to this draft, which must be submitted within the time limit specified below in section 7. 2. Advance notification In line with the Norwegian Public Administration Act section 16, we hereby provide advance notification of our intent to make the following decision: Pursuant to article 58(2)(i) GDPR, we impose an administrative fine against Disqus Inc. of 25 000 000 - twenty five million - NOK, for a. having processed the personal data of data subjects in Norway, collected from the websites NRK.no/ytring, P3.no, tv.2.no/broom, khrono.no, adressa.no, rights.no and document.no, through tracking, analysing and profiling, and disclosing personal data to third party advertisers, without a legal basis pursuant to Articles 5(1)(a) and 6(1) GDPR, b. failure to provide the data subjects with information in accordance with Articles 5(1)(a), 12(1) and 13 GDPR, and c. failure to identify GDPR as the applicable legal framework for processing the personal data of data subjects in Norway pursuant to Article 5(2) GDPR. The NO DPA is the supervisory authority established in line with Article 51(1) GDPR to monitor the application of the GDPR on the territory of the Kingdom of Norway. This follows from the Norwegian Personal Data Act Section 20. We have the powers to impose an administrative fine pursuant to Article 58(2)(i). In the present case, we have focused our investigation on Disqus’ responsibility under the GDPR as a controller being present on the websites mentioned above for the pertinent data 2 See section 17 first para. of Act relating to procedure in cases concerning the public administration (Public Administration Act) (LOV-1967-02-10). 3 processing operations. However, there might be additional issues regarding e.g. the website owners’ responsibility under the GDPR for admitting Disqus to their websites. The fact that some issues have fallen outside the scope of our investigation does not preclude those issues from being addressed in the future. We may decide to investigate additional issues later on, following individual complaints or ex officio, see the tasks and powers of the supervisory authorities laid down in Articles 57 and 58 GDPR. 3. Facts of the case 3.1 Factual background Disqus is an American company owned by Zeta Global, which offers an online public comment sharing platform, into which users may log in and create profiles in order to participate in conversations. Advertising is the predominant business model, according to the Disqus privacy policy.3 Through news articles published by the NRK, we were made aware that Disqus has collected and disclosed personal data to third party advertising partners about data subjects in Norway through the Disqus widget, a comment plug-in for websites. The online newspaper Computerworld.no has also written about