Re: [Pearg] draft-irtf-pearg-safe-internet-measurement review, implied consent

Mallory Knodel <mknodel@cdt.org> Tue, 11 July 2023 14:06 UTC

Return-Path: <mknodel@cdt.org>
X-Original-To: pearg@ietfa.amsl.com
Delivered-To: pearg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17D0FC151092 for <pearg@ietfa.amsl.com>; Tue, 11 Jul 2023 07:06:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cdt.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lsYVgWjGD11F for <pearg@ietfa.amsl.com>; Tue, 11 Jul 2023 07:06:05 -0700 (PDT)
Received: from mail-pj1-x102c.google.com (mail-pj1-x102c.google.com [IPv6:2607:f8b0:4864:20::102c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A84E8C15106A for <pearg@irtf.org>; Tue, 11 Jul 2023 07:06:05 -0700 (PDT)
Received: by mail-pj1-x102c.google.com with SMTP id 98e67ed59e1d1-262dc1ced40so4191594a91.3 for <pearg@irtf.org>; Tue, 11 Jul 2023 07:06:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cdt.org; s=google; t=1689084365; x=1691676365; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=iLj8e9RTelhtkJqtZXp/2m3uZeoZnTdvu2bbS8o/Lvo=; b=LZbkaKHG9mC+O/6vJiQB5C/zoo3FSQkcKqWQf1NLvPM1qn9fWvdKmS6d9bMTfe0R1i o2ySefkk5+31e6jAJuQej3x17kpnnFjMUwGF97vSCO0RsBzdtUpRxsZlDgIttmpxtRzZ 7lDRFhcUu6QDrbe5bP9M/Cpj5K/AguQ77IBio=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1689084365; x=1691676365; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=iLj8e9RTelhtkJqtZXp/2m3uZeoZnTdvu2bbS8o/Lvo=; b=ifOyGrC9TxdBYg9pSIOCaXhN3oly259b4jKu2z1otYbEgUhnnzTViVmffGiqiVsaUz xZbYI9hUZPbuTcKuaV5LGhgWGZ1JW8POJZqZ0pQb+EDD6yO9GdPTRTW9OSQZdZ2+dhCf uMEq+/iwZ3wEQGRFFgEY6pSclm67Cb/ujDoJAd4wdpBYCRAK7nDLH5ou+nmU6L/cwaw3 Vnokrq634Qz8+dX81LSEmNlZn9RaF1AIfiLn+dleiWVCi2np9RBLIwj4wVgV4adJ677H EEWyQc8DvJqzUFTaME9wiyZYLtQm4Le9+tDtpszy/tlu/ATFO2PDJ/P4ZaVbRGgKSELP 9ajA==
X-Gm-Message-State: ABy/qLbxULNKcQ93wJZqECkuusz2lqlnwHLDFiGtoOUh+N+tjK+GCmHV mApmDixHBzaqakQcAtpnD2AuPqm6mVKaNBtT7GbvIJaykQuYSTCI
X-Google-Smtp-Source: APBJJlFnyKgAhRDDwqqhnKNmeqrdkXTEEvPQjjUVKl1gHOhZcUBo+XacOgilBmHUl6fkpo/7qQA3JSCy4jj/X0eZLyI=
X-Received: by 2002:a17:90b:1e0f:b0:263:1d18:886a with SMTP id pg15-20020a17090b1e0f00b002631d18886amr16940169pjb.1.1689084365073; Tue, 11 Jul 2023 07:06:05 -0700 (PDT)
MIME-Version: 1.0
References: <CA+tYtvHQF7s3e-740jqjB0XEJp8OKin3xav6kheag00b1p6w1g@mail.gmail.com> <bc85c30c6799454a89c424f8550f0ab3@huawei.com>
In-Reply-To: <bc85c30c6799454a89c424f8550f0ab3@huawei.com>
From: Mallory Knodel <mknodel@cdt.org>
Date: Tue, 11 Jul 2023 10:05:53 -0400
Message-ID: <CAGVFjMLpBg1ijuyjUMUZufwgX=Q=X+8CmRT9LgPOdXAiO0RgXg@mail.gmail.com>
To: Antoine FRESSANCOURT <antoine.fressancourt=40huawei.com@dmarc.ietf.org>
Cc: Nick Doty <ndoty=40cdt.org@dmarc.ietf.org>, "pearg@irtf.org" <pearg@irtf.org>
Content-Type: multipart/alternative; boundary="0000000000009386f506003699d7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/pearg/mGzt2OOedyg1ra_NUm2C_gWXX18>
Subject: Re: [Pearg] draft-irtf-pearg-safe-internet-measurement review, implied consent
X-BeenThere: pearg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Privacy Enhancements and Assessment Proposed RG <pearg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/pearg>, <mailto:pearg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pearg/>
List-Post: <mailto:pearg@irtf.org>
List-Help: <mailto:pearg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/pearg>, <mailto:pearg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Jul 2023 14:06:10 -0000

Thanks Antoine,

For the purposes of internet measurements (and I’m happy to cite some
examples) do you have a sense of how GDPR compliance is achieved when
informed consent may not be possible?

Others have thoughts on this?

I think we should add a sentence or two to the implied consent section, or
perhaps create a new sections, depending on your understanding of best
current practice.

Thanks,
-Mallory

On Tue, 11 Jul 2023 at 09:41, Antoine FRESSANCOURT <antoine.fressancourt=
40huawei.com@dmarc.ietf.org> wrote:

> Hello,
>
> Just a quick remark:
>
> ## implied consent
>
> [...]
> Similarly, under European and similar data protection law, consent isn't
> universal, it's not that every data processing takes place with some kind
> of consent, but rather that you need informed consent when something of a
> particular weight is happening and there isn't another justification and in
> other cases it's reasonable for you to do the processing without getting
> consent (because it's not personal data, say), not that you did have some
> implied consent.
> [...]
>
> Under the GDPR, the implicit answer to the collection or use of data
> generated by the user is "Not consent". There is no such a thing as
> implicit consent. Either you explicitly consent, or you don't (see
> https://gdpr.eu/article-7-how-to-get-consent-to-collect-personal-data/).
> Article 6 of the GDPR gives some cases in which consent is not required,
> but you need to demonstrate that you fall under one of those cases.
>
> Best regards,
>
> Antoine Fressancourt
>
> --
> Pearg mailing list
> Pearg@irtf.org
> https://www.irtf.org/mailman/listinfo/pearg
>
-- 
Mallory Knodel
CTO, Center for Democracy and Technology
gpg fingerprint :: E3EB 63E0 65A3 B240 BCD9 B071 0C32 A271 BD3C C780