Mervinskiy 437

Page 62

to include a photograph). When all of these consequences are considered, it is clear that the right to receive information, even in the context of the limited processing envisaged by the Contact Feature, is inextricably connected with the right to exercise control over one’s personal data. 176. Considering, then, the burden that the finding set out above might place on WhatsApp, I note that the non-user data undergoing processing is very limited, as are the processing operations that are applied to the data concerned. Accordingly, I do not consider that the preparation of the required information will be particularly burdensome for WhatsApp. My view is that the role and utility of the right to be informed, as considered above, outweighs the limited burden that would be placed on WhatsApp, as regards the formulation of the required information. In relation to the burden that would result from the requirement for WhatsApp to deliver that information to the data subjects concerned, I note that WhatsApp could, if it wished, deliver the required information by way of its existing policies and procedures. I note, in this regard, that WhatsApp could, as part of its existing onboarding procedure through the app, inform any non-user, who is considering joining the Service, of the consequences of the processing of non-user mobile phone numbers pursuant to the Contact Feature. Further, I note that WhatsApp’s user-facing transparency information is already publicly available and, in the circumstances, the inclusion of the corresponding information required for nonusers should not be a particularly burdensome or onerous task (and certainly not so burdensome that it would outweigh the data subjects’ right to receive this information).

Finding: The extent to which WhatsApp complies with its obligations to non-users pursuant to Article 14 of the GDPR 177. Accordingly, for the reasons set out above, I find that WhatsApp has failed to comply with its obligation to provide non-users with the information prescribed by Article 14. For the avoidance of doubt, nothing in the above assessment should be interpreted as being an endorsement that the processing of non-user data, by WhatsApp, is conducted in reliance upon an appropriate legal basis. As already identified, the purpose of the within inquiry is to examine the extent to which WhatsApp complies with its transparency obligations pursuant to the GDPR and, in the circumstances, the assessment of the legal basis being relied upon to support any processing operation is outside of the scope of this inquiry.

Part 2: Transparency in the Context of Users Introduction 178. Under this heading, I will consider the extent to which WhatsApp complies with its obligations under Articles 13 and 12(1) of the GDPR, in the context of its processing of personal data relating to users of the Service. The issues that I will consider under this heading correspond to the matters covered by Conclusions 3 – 13 (inclusive) of the Final Report.

Relevant Provisions 179. Article 13 of the GDPR concerns transparency where the personal data in question “are collected from the data subject”. In such a case, Article 13 requires the data subject to be provided with the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative;

62


Turn static files into dynamic content formats.

Create a flipbook

Articles inside

The Decision-Making Stage

2hr
pages 143-220

Article 83(5) and the applicable fining “cap”

14min
pages 248-256

Decision: Whether to impose an administrative fine and, if so, the amount of the fine

18min
pages 225-237

Appendix C – Terms of Order to bring processing operations into compliance, made pursuant to Article 58(2)(d

3min
pages 264-265

Summary of Corrective Powers to be Exercised

0
pages 257-258

Article 83(2)(k): any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement

10min
pages 221-224

Assessment: Article 13(2)(a) – Retention Criteria/Retention Periods

2min
page 128

Assessment: Article 13(2)(b) – the existence of the data subject rights

2min
page 132

Assessment of Decision-Maker: What information has been provided?

2min
page 129

Identified Legal Basis 5: The vital interests of the data subject or those of another person

2min
page 110

Assessment of Decision-Maker: What information has been provided?

2min
page 124

Assessment: Article 13(1)(f) – Transfers of personal data to a third country

2min
page 123

Assessment of Decision-Maker: What information has been provided?

1min
page 120

Identified Legal Basis 6: Tasks carried out in the public interest

8min
pages 111-113

Identified Legal Basis 1: Contractual Necessity

17min
pages 94-99

Identified Legal Basis 2: Consent

5min
pages 100-101

Identified Legal Basis 4: Compliance with a Legal Obligation

11min
pages 106-109

Identified Legal Basis 3: Legitimate Interests

10min
pages 102-105

Preliminary Issue: What information must be provided pursuant to Article 13(1)(c)?

26min
pages 82-92

Assessment: Application of the Proposed Approach to Article 13(1)(c

2min
page 93

Review of the Materials being relied upon by WhatsApp

10min
pages 64-67

Assessment: Article 13(1)(c) – the purposes of the processing for which the personal data are intended as well as the legal basis for the processing

7min
pages 79-81

Assessment of Decision-Maker: What information has been provided?

1min
page 76

Methodology for Part 2: Assessment and Questions for Determination

19min
pages 68-74

Relevant Provisions

4min
pages 62-63

Assessment: Article 13(1)(a) – the identity and contact details of the controller

2min
page 75
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.