Home Privacy Ad Tech Bristles At The CNIL’s Consent Recommendations – But ePrivacy Could Change Everything

Ad Tech Bristles At The CNIL’s Consent Recommendations – But ePrivacy Could Change Everything

SHARE:

It’s nearly le denouement pour le cookie consentement en France.

The Commission nationale de l’informatique et des libertés (the CNIL), France’s data protection authority, is on the cusp of finalizing its updated consent guidelines for cookies and other trackers – and the stakes are high.

“The question is not whether consent is applicable – of course it is – the question is: Will France be more strict about consent than elsewhere in Europe by giving data subjects the right to object along with every consent request?” said Etienne Drouard, a partner at Hogan Lovells, who’s also representing nine French trade organizations before the French Supreme Court in ongoing litigation against the CNIL’s recommendations.

One objective of the litigation – the final hearing is scheduled for mid-March – is to point out that some of the CNIL’s recommendations for collecting user consent go beyond what’s called for under the General Data Protection Regulation and the ePrivacy Directive.

Comments on the draft guidelines were due last week, and the final recs could be ready as soon as late March or early April. Enforcement would begin six months after a vote by the CNIL on the final recs.

The purpose of updating the guidelines, which hadn’t been revised since 2013, is to bring them in line with GDPR and give businesses clarity on how to properly gather consent. Until the recs are final, publishers and tech companies are still allowed to rely on scrolling or swiping as a form of consent gathering. After that, implied consent will be no longer be acceptable.

Beyond cookies

While cookies are already on their way out, the CNIL’s recommendations would apply to any identifier that reads, writes or stores information to a consumer’s device, including the IDFA and the Android advertising ID, said Thomas Adhumeau, general counsel at French mobile ad company S4M. The CNIL also doesn’t make a distinction between first-party cookies and third.

Although most types of identifiers fall into the tracker category, a few exceptions do exist. Authentication and session cookies don’t require consent and can be stored for up to 24 months.

CNIL vs. GDPR

Some of the CNIL’s draft recommendations are in line with GDPR, including doing away with tacit consent and requiring that consent be specific to the purpose.

But there are also additional requirements that some consider to be an overinterpretation of the law, and these have the potential to alter the user journey and dramatically reduce the volume of data that companies are able to obtain, said Drouard, who himself spent almost three years as a lawyer at the CNIL in the late ‘90s before moving into private practice.

One example is the need to provide perfect symmetry in the choices being offered to consumers, a notion that doesn’t exist under GDPR, said Adrien Thil, chief privacy officer at Paris-based ad server Smart. The CNIL’s suggested best practice is that if there’s an “Accept all” button, there also needs to be a “Refuse all” button of equal size and color right next to it.

The way in which one asks for consent impacts how likely someone is to give it, and this sort of design will likely have a “massive” dampening effect on the consent rate, said Romain Gauthier, CEO and founder of French consent management platform Didomi.

Another spot where the CNIL goes further than GDPR is in how often businesses are required to ask for consent. The GDPR doesn’t specify, but the CNIL advises that consent is only valid for six months at a time. Then you’ve got to ask again. And if at any point a consumer refuses to be tracked, a publisher must wait at least six months before asking for consent again. As the CNIL points out in its recs, repeatedly asking for consent might cause a user to accept simply “out of weariness.”

Although publishers obviously need to preserve the user experience, Thil argues that setting a blanket six-month waiting period doesn’t make sense.

“The period shouldn’t be the same for a daily newspaper consulted several times a day and a cooking recipe site that you check only for Thanksgiving,” he said.

Après-ski?

Drouard knows that his case against the CNIL is unlikely to succeed nearly by default. The Supreme Court in France almost always sides with independent regulators in order to dissuade reflexive litigation. And so there was nothing to lose, Drouard said.

If the CNIL wins, the recommendations will be codified, but at the very least, the ad industry is getting additional clarity on the CNIL’s stance from the defense it’s required to make before the court.

If his case is successful, however, the CNIL would have to redo its guidelines based on the conclusions of the court and the CNIL would be prohibited in the future from interpreting GDPR and ePrivacy in the same as they did in their guidelines.

But regardless of what happens with the CNIL’s cookie and tracker recommendations, there are potentially bigger changes afoot: ePrivacy.

After years of back and forth with no resolution, the Presidency of the Council of the European Union published a revised version of the proposed ePrivacy regulation in late February.

Previous drafts of the ePrivacy regulation did not include legitimate interest as a legal basis for processing non-sensitive personal information, including cookies, without consent – but this draft of ePrivacy does. If passed, this would align ePrivacy with the GDPR, which is something many people in the privacy profession weren’t sure if they’d actually live to see.

A committee within the council is set to discuss the changes at two separate meetings, one on March 5 and another on March 12.

“If the council buys into this on March 12, the ePrivacy regulation will agree with the rationales and balances set out under GDPR – which would mean no more need for a debate about this in France, as the EU regulation would define the law, not a local regulator,” Drouard said. “We’re at a moment where anything is possible on the regulatory front and on the political front.”

The CNIL responded to a request for comment but isn’t yet ready to talk publicly about the guidelines.

Must Read

New WBD Report Makes The Case For Getting The Measurement Basics Right

Warner Bros. Discovery has a new white paper analyzing the data and methodologies of five top video measurement providers: VideoAmp, iSpot, Comscore, Innovid and Samba.

Monopoly Man looks on at the DOJ vs. Google ad tech antitrust trial (comic).

Google And The DOJ Filed Their Proposed Final Judgments In The Ad Tech Case – Here’s What They’re Still Arguing About

Google and the Department of Justice filed the next round of paperwork that will determine what Google’s punishment will look like in the ad tech antitrust case.

T-Mobile Brings Its Mobile Data Exclusively To Vistar To Scale Up DOOH Targeting

Advertisers can now use Vistar to activate both off-the-shelf and custom audiences built on T-Mobile’s first-party location and app data.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS

Apple’s WebKit crackdown appears to extend well beyond The Trade Desk, putting hundreds of ad tech, data and identity vendors on a mysterious, dynamically updated block list.

Josh Reed, Zoom's VP of brand and content, speaking at AdExchanger's Programmatic IO event in New York City (September 28, 2006)

Zoom’s Marketing Challenge Is That It’s Too Well Known For Its Own Good

Zoom has 99% unaided brand awareness, which sounds great on paper. But there’s a catch: Most people still think it’s just a video-call app.

Why Agencies Think They Shouldn’t Own Agentic AI Tools Or The Data Used To Build Them

Agencies are differentiating their tech stacks by building custom agentic AI tools for their clients. And they’re rethinking owning those AI tools – particularly since licensing them creates new revenue streams.