[ad_1]
The European Union privacy regulator has proposed a fine of more than $425 million against Amazon.com Inc. , AMZN 1.33% is part of an operation that could yield the largest penalty yet under the bloc’s privacy law, people familiar with the matter said.
The people said Luxembourg’s data protection commission, the CNPD, has circulated a draft resolution penalizing Amazon’s privacy practices and proposing the fine among 26 other national authorities in the bloc. The CNPD is Amazon’s main privacy regulator in the European Union because Amazon is headquartered in the European Union in the Grand Duchy.
The Luxembourg case relates to alleged violations of Europe’s General Data Protection Regulation, or GDPR, linked to Amazon’s collection and use of personal data, and is not related to its cloud computing business, Amazon Web Services, one of the people familiar with the matter said. The person declined to go into detail about the specific allegations against Amazon.
An Amazon spokesperson declined to comment. The company previously said that the privacy of its customers is a priority and that it complies with the law in all the countries in which it operates. A CNPD spokesperson said the regulator was not allowed to comment on individual cases.
Before the draft decision becomes final, it must be effectively agreed upon by other EU privacy regulators, a process that could take months and lead to fundamental changes, including a higher or lower fine.
The fine proposed by Luxembourg would represent roughly 2% of Amazon’s $21.3 billion net income for 2020, and 0.1% of its $386 billion in sales. Under the General Data Protection Regulation (GDPR), regulators can impose a fine of up to 4% of a company’s annual revenue.
The Luxembourg regulator has received a handful of objections to its draft decision, including at least one that said the fine should be higher, another person familiar with the matter said. Luxembourg can either resolve objections amicably, or reject them and spark discussion and vote among all EU privacy regulators at the European Data Protection Council.
The European Union’s new data privacy law, known as GDPR, has created the first charter of rights for consumer privacy. Here’s what you need to know. (Originally published August 8, 2018)
The draft decision, along with the size of the fine, signals a new wave of privacy enforcement against big tech companies in Europe, when Silicon Valley giants come under increasing global scrutiny.
Ireland’s privacy regulator, which leads the implementation of the General Data Protection Regulation for Facebook Inc. And Google and Alphabet Inc’s Apple Inc. Because they are headquartered in the European Union in the country, they expect to make draft decisions in nearly half a dozen privacy issues involving big tech companies. companies this year.
An Irish draft of the decision circulated to other regulators alleges GDPR violations related to the sharing of Facebook data between its social network and WhatsApp chat app. This draft resolution recommends paying a fine of between 30 million euros and 50 million euros, according to people familiar with the matter, equivalent to about $37 million to $61 million.
Subscribe to newsletters
Technique
Weekly summary of tech reviews, headlines, columns, and your questions answered by WSJ’s personal tech experts.
Facebook representatives did not immediately respond to requests for comment. Asked about the case in the past, a spokesperson declined to comment.
Increased privacy enforcement in the EU comes hand in hand with increased antitrust enforcement, with European and US regulators launching multiple cases against big tech companies. Last week, major law enforcement agencies in the United Kingdom and the European Union announced formal antitrust investigations into the Facebook dating service and the Marketplace classifieds ad service.
A Facebook spokesperson said last week that Marketplace and the dating services “operate in a very competitive environment with many large established companies. We will continue to cooperate fully with investigations to establish that they are unfounded.”
When it comes to privacy, activists have complained about the slow pace of law enforcement in Europe. Since the General Data Protection Regulation came into force in 2018, the largest penalty under the law has been a €50 million fine against Google from France’s privacy regulator, according to law firm DLA Piper.
Ireland, which leads enforcement in the European Union for many of the largest US tech companies, has come under fire especially from activists and politicians for not issuing more decisions. So far, the authority has made a final decision in a major tech case, fined Twitter 450 thousand euros in December.
In response to the criticism, Helen Dixon, who leads Ireland’s privacy regulator, said technology issues are new and companies should be given due process rights to respond to substantively all allegations, or risk being brought later in court.
Write to Sam Schechner at [email protected]
Copyright © 2020 Dow Jones & Company, Inc. all rights are save. 87990cbe856818d5eddac44c7b1cdeb8
.
[ad_2]
Picture Credit!