{"id":16380,"date":"2022-03-31T11:28:10","date_gmt":"2022-03-31T11:28:10","guid":{"rendered":"https:\/\/www.webgains.com\/public\/?p=16380"},"modified":"2022-03-31T14:05:21","modified_gmt":"2022-03-31T14:05:21","slug":"iab-tcf-2-0-illegal-the-age-of-consent-for-affiliate-marketers","status":"publish","type":"post","link":"https:\/\/www.webgains.com\/public\/en\/iab-tcf-2-0-illegal-the-age-of-consent-for-affiliate-marketers\/","title":{"rendered":"IAB TCF 2.0 \u201cillegal\u201d: The Age of Consent for Affiliate Marketers"},"content":{"rendered":"\n<div class=\"wp-block-uagb-testimonial uagb-testomonial__outer-wrap uagb-slick-carousel uagb-tm__arrow-outside uagb-block-06766a98\"><div class=\"is-carousel uagb-tm__columns-1 uagb-tm__items\"><div class=\"uagb-testimonial__wrap  uagb-tm__imgicon-style-circle uagb-tm__image-position-bottom uagb-tm__bg-type-undefined \"><div class=\"uagb-tm__content\"><div class=\"uagb-tm__overlay\"><\/div><div class=\"uagb-tm__text-wrap\"><div class=\"uagb-testinomial-text-wrap\"><div class=\"uagb-tm__desc\"><em>\u201cThere is a general ambivalence of the Affiliate Industry to how personal data is collected. Perhaps it\u2019s because despite all the scare stories since GDPR was brought into play in 2018, nothing much has changed in practice. Yes, we now have pop-up consent boxes where there were previously none, but the players in the market are playing the same game. With recent updates concerning TCF and rulings against legitimate interest instead of consent as a legal basis for processing personal data, maybe now times are (finally) changing. \u201c<\/em>\u202f\u00a0<\/div><\/div><div class=\"uagb-tm__meta\"><div class=\"uagb-tm__meta-inner\"><div class=\"uagb-tm__image-content\"><div class=\"uagb-tm__image\"><img class=\"uagb-tm-img-src\" src=\"https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2019\/10\/Richard-Dennys-CEO-Webgains-150x150.jpg\" alt=\"\"\/><\/div><\/div><div class=\"uagb-testimonial-details\"><span class=\"uagb-tm__author-name\">Richard Dennys<\/span><span class=\"uagb-tm__company\">CEO of Webgains Ltd<\/span><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\n\n\n\n<div style=\"height:48px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2><strong>The Context<\/strong><\/h2>\n\n\n\n<div style=\"height:29px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4>What is GDPR?&nbsp;<\/h4>\n\n\n\n<p>General Data Protection Regulation (<a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR<\/a>) is the toughest and most stringent set of data protection rules to impose limits on how organisations target or collect data related to people in the EU. The regulation was put into effect on May 25, 2018. Though it relates specifically to EU countries and its individuals, it can apply to organisations anywhere, so long as they target or collect data from people within the EU.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The regulation was created to harmonise data privacy laws across EU countries, as well as providing greater protection and rights to individuals. Should businesses not comply with the set of standards, there is potential for large fines and reputational damage.&nbsp;&nbsp;<\/p>\n\n\n\n<h4>Who\/What is the Belgian ADP&nbsp;&nbsp;<\/h4>\n\n\n\n<p>The Belgian ADP stands for the Belgium Data Protection Authority (<a href=\"https:\/\/www.dataprotectionauthority.be\/citizen\" target=\"_blank\" rel=\"noreferrer noopener\">BE ADP<\/a>). This independent body ensures that businesses comply with the fundamental principles of data protection.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<h4>Who\/What is the IAB Europe?&nbsp;<\/h4>\n\n\n\n<p>The International Advertising Bureau (<a href=\"https:\/\/iabeurope.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">IAB Europe<\/a>) is a global association for digital marketing and advertising. Through collaborative efforts, the IAB works to deliver frameworks, standards and industry programmes that allow businesses to thrive in the European Market.&nbsp;&nbsp;<\/p>\n\n\n\n<h4>What is the Transparency and Consent Framework?&nbsp;<\/h4>\n\n\n\n<p>The Transparency and Consent Framework (<a href=\"https:\/\/iabeurope.eu\/transparency-consent-framework\/\" target=\"_blank\" rel=\"noreferrer noopener\">TCF<\/a>) was created by IAB Europe in collaboration with organisations and professionals within the advertising industry. It was introduced to help primarily publishers, technology vendors meet the transparency and user choice requirements under GDPR. [explanation: agencies and advertisers are not really covered by TCF 2.0; this will be the case with a new version (TCF 3.0) which is discussed at IAB]&nbsp;&nbsp;<\/p>\n\n\n\n<h4>What is a Data Controller?&nbsp;<\/h4>\n\n\n\n<p>The data controller determines the purpose for processing personal data and the means by which it is processed.&nbsp;&nbsp;<\/p>\n\n\n\n<h4>What is a Joint Controller?&nbsp;<\/h4>\n\n\n\n<p>Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers according to Art. 26 GDRP.&nbsp;&nbsp;<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2><strong>The Lowdown<\/strong><\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.dataguidance.com\/news\/belgium-belgian-dpa-imposes-250000-fine-iab-europe-tcf\" target=\"_blank\" rel=\"noreferrer noopener\">decision<\/a> made by the Belgian ADP in February 2022 found that the IAB Europe was a (Joint) Controller, and therefore can be held responsible for the processing of data in-line with GDPR. This decision follows an investigation into the Transparency and Consent Framework (TCF), where it was revealed that the IAB Europe did not meet several of the requirements derived from GDPR.&nbsp;&nbsp;<\/p>\n\n\n\n<p>First, the Belgian ADP found that IAB Europe has no legal basis for processing the Consent String created when using a Consent Management Platform based on TCF 2.0. Also a sufficient legal basis for a transfer of this consent string to subsequent adtech vendors is missing:&nbsp;<\/p>\n\n\n\n<p><em>\u201cThe IAB Europe [has] failed to establish a legal basis for the processing of the TC String and offered inadequate legal grounds for the subsequent processing by adtech vendors.\u201d<\/em><\/p>\n\n\n\n<p>Second, the IAB were found not to be following the range of requirements by the GDPR set out for a Data Controller such as:&nbsp;<\/p>\n\n\n\n<ul><li>Data Protection by design&nbsp;<\/li><li>No processing registers&nbsp;<\/li><li>No appointment of a data protection officer&nbsp;<\/li><li>Data Protection impact assessments&nbsp;<\/li><\/ul>\n\n\n\n<p>The phrase \u201c..the prohibition of the use of legitimate interest as a basis for the processing of personal data within the context of the TCF..\u201d is key to the changes outlined in TCF 2.0. Up to now the ADP decision is not binding as IAB Europe has filed an appeal against this administrative ruling and asked for a suspension.&nbsp;<\/p>\n\n\n\n<h4>So, what does this mean for the Webgains Network?&nbsp;<\/h4>\n\n\n\n<p>First and foremost, unlike other affiliate networks, we strongly advocate for and implement the use of \u2018<a href=\"https:\/\/www.webgains.com\/public\/en\/gdpr-webgains-and-you\/\" target=\"_blank\" rel=\"noreferrer noopener\">Consent<\/a>\u2019 as a legal basis for storing cookies on end-user\u2019s device. It is the responsibility of our advertising merchants to collect consent during the live session on the ecommerce store hosted by the brand advertiser. If consent is not obtained, the tracked session is discarded, and no commission is payable to our affiliates. To make the terms clear, the advertising merchant is classed as the Data Controller and Webgains is classed as the Data Processor. The merchant is obliged to collect consent when dropping cookies, therefore we only act when processing the data in the context of user tracking.&nbsp;<\/p>\n\n\n\n<p>The <em>only<\/em> time we process personal data based on the use of \u2018Legitimate Interest\u2019 is when we act as <em>Joint Controllers <\/em>with certain publishers and advertising merchants. This happens when we process data to fulfil our contractual obligations towards publishers and to assess how the data transfer takes place between advertising merchant and Webgains, as well as Webgains and Publisher. As stated above, we predominantly work on the basis of \u2018Consent\u2019 and avoid the use of \u2018Legitimate Interest\u2019 where possible. Our dedication to the use of \u2018Consent\u2019 is further emphasised in the IAB Europe TCF list, where our entry in the \u201cLegIntPurposes\u201d field is marked \u201c[]\u201d to signify we do not use this basis. This means, should the IAB look to amend their TCF, Webgains already meets the criteria, as required by the Belgian DPA.&nbsp;<\/p>\n\n\n\n<p>In comparison, other affiliate networks use a different method of dropping cookies. Typically, a cookie is already dropped when a user visits the publisher\u2019s page. Either the publisher drops the cookie, or the affiliate network does acting in the interest of the advertising merchant. This regularly leads to a Joint Controllership according to Art. 26 GDPR which is in practice ignored widely by a lot of affiliate networks. . Ultimately, the advertising merchant will need to thoroughly check that the consent collected by Publishers is in-line with GDPR even when the affiliate marketing network is deemed to be a controller and not processor. This is practically impossible for advertising merchants to organise. Since such networks regularly exclude liability for the activities of the publishers, this leads to a shift in liability towards the advertising merchant.&nbsp;<\/p>\n\n\n\n<p>All in all, this means that current advertisers and affiliates on the Webgains network can continue working with us without needing to change anything at all.&nbsp;<\/p>\n\n\n\n<h4>How to Discover if a Network is using Legitimate Interest&nbsp;<\/h4>\n\n\n\n<p>Unlike Webgains\u2019 legal basis for data processing, not all AdTech providers, affiliate networks or platforms are following the same steps. To discover an affiliate player\u2019s legal basis, follow the steps below:&nbsp;<\/p>\n\n\n\n<ol><li>Access the TCF vendor list <a href=\"https:\/\/vendor-list.consensu.org\/v2\/vendor-list.json\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a> in a web browser\u202f&nbsp;<\/li><\/ol>\n\n\n\n<ol start=\"2\"><li>Use CTRL-F to open the browser window search function\u202f&nbsp;<\/li><\/ol>\n\n\n\n<ol start=\"3\"><li>Type in the name or part name of the company you wish to search. In the case of Webgains you will find:\u202f\u202f&nbsp;<br><\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image size-full is-style-default\"><img width=\"600\" height=\"200\" src=\"https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/Untitled-design-70.png\" alt=\"\" class=\"wp-image-16421\" srcset=\"https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/Untitled-design-70.png 600w, https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/Untitled-design-70-300x100.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<ol start=\"4\"><li>Check the entry next to the parameter marked \u201clegIntPurposes\u201d\u202f&nbsp;<\/li><\/ol>\n\n\n\n<ol start=\"5\"><li>If the box is simply \u201c[]\u201d \u2013 as it is for Webgains &#8211; then Legitimate Interest is not being used as a DP basis\u202f&nbsp;<\/li><\/ol>\n\n\n\n<ol start=\"6\"><li>If the box has a number in it (i.e. \u201c[7]\u201d) then Legitimate Interest is being used, so is therefore in technical breach of the GDPR ruling by the recent Belgian DPA. In order to continue to use the TCF, this company will either need to change their processing basis or stop using the TCF.\u202f&nbsp;<\/li><\/ol>\n\n\n\n<p>If you discover that the company you are working with or searching for are using Legitimate Interest as a basis for data processing, then follow these actions:&nbsp;<\/p>\n\n\n\n<ul><li>Speak to your relevant account manager. Ask them where the consent for data processing is being given during the ecommerce session and whether legitimate interest is being used on your behalf to process personal data.&nbsp;&nbsp;<\/li><li>Speak to your legal department as soon as possible for their opinion on the risk assessment given the increasing numbers of legal judgements and fines being imposed.\u202f\u202f<\/li><\/ul>\n\n\n\n<p>Alternatively, if you cannot find the legal basis in which they are collecting data, you can simply go to their privacy policy, which needs to be legally available at any time and look for yourself.\u202f\u202f&nbsp;<\/p>\n\n\n\n<p><strong><em>Please note<\/em><\/strong>: The TCF vendor list is relevant when a publisher collects consent or wants to rely on \u2018legitimate Interest\u2019 as a way to process data as legal basis. It is important to remember that a merchant can implement a Consent Management Platform (CMP) to collect consent for storing cookies and implement the TCF 2.0, but this is at their own discretion. To reinforce what is already stated, in Webgains\u2019 case, it is the merchant who will collect consent for storing cookies on an end-user\u2019s device as he is the controller and Webgains is acting as a processor. <\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2><strong>Key Takeaways<\/strong><\/h2>\n\n\n\n<ul><li>Data controllers are liable for <a href=\"https:\/\/gdpr-info.eu\/issues\/fines-penalties\/\" target=\"_blank\" rel=\"noreferrer noopener\">the bulk of the fines and sanctions<\/a> under the GDPR.\u202f\u202f&nbsp;<\/li><li>Webgains has never and will never use Legitimate Interest as a basis for collecting personal data regarding the tracking taking place. Advertisers and Publishers on the Webgains network can continue as they are.&nbsp;<\/li><li>You can discover which network or player is using Legitimate Interest as a basis for consent by accessing the TCF vendor list.&nbsp;&nbsp;<\/li><li>If you discover a company is using Legitimate Interest to process data (or unable to find out the information) speak to the relevant account manager, check their privacy policy and\/or speak to your legal department.&nbsp;&nbsp;&nbsp;<\/li><li>When looking at the APD decision, Webgains has developed a safe affiliate marketing platform to avoid uncertainties within various frameworks, especially when third-party consent is concerned.&nbsp;&nbsp;<\/li><\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4>Further Reading<\/h4>\n\n\n\n<p>The TTDSG Act In Germany: What It Means For You, Webgains And The Affiliate Marketing Industry. <a href=\"https:\/\/www.webgains.com\/public\/en\/the-ttdsg-act-in-germany-what-it-means-for-webgains-and-affiliate-marketing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read now<\/a> to stay abreast of the recent changes.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Context What is GDPR?&nbsp; General Data Protection Regulation (GDPR) is the toughest and most stringent set of data protection rules to impose limits on how organisations target or collect data related to people in the EU. The regulation was put into effect on May 25, 2018. Though it relates specifically to EU countries and [&#8230;]<\/p>\n<p><a class=\"btn btn-secondary understrap-read-more-link\" href=\"https:\/\/www.webgains.com\/public\/en\/iab-tcf-2-0-illegal-the-age-of-consent-for-affiliate-marketers\/\">Read More&#8230;<\/a><\/p>\n","protected":false},"author":45,"featured_media":16412,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":""},"categories":[431,341,435],"tags":[],"acf":[],"uagb_featured_image_src":{"full":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"thumbnail":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3-150x150.png",150,150,true],"medium":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3-300x150.png",300,150,true],"medium_large":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3-768x384.png",640,320,true],"large":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",640,320,false],"xl":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"xxl":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"xxxl":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"xxxxl":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"xxxxxl":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"1536x1536":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false],"2048x2048":["https:\/\/www.webgains.com\/public\/wp-content\/uploads\/2022\/03\/3.png",1000,500,false]},"uagb_author_info":{"display_name":"Rob Atkinson","author_link":"https:\/\/www.webgains.com\/public\/author\/ratkinsonwebgains-com\/"},"uagb_comment_info":0,"uagb_excerpt":"The Context What is GDPR?&nbsp; General Data Protection Regulation (GDPR) is the toughest and most stringent set of data protection rules to impose limits on how organisations target or collect data related to people in the EU. The regulation was put into effect on May 25, 2018. Though it relates specifically to EU countries and&hellip;","_links":{"self":[{"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/posts\/16380"}],"collection":[{"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/users\/45"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/comments?post=16380"}],"version-history":[{"count":0,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/posts\/16380\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/media\/16412"}],"wp:attachment":[{"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/media?parent=16380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/categories?post=16380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webgains.com\/public\/wp-json\/wp\/v2\/tags?post=16380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}