TYGlobe

STUDY

TYGlobe Insight | Invisible Personal Information: IP Address, Cookie, BSSID and TC String (Part I)

Release time:2024-07-18 14:16:51

Nowadays, people's awareness of information security in China is increasingly strong. In daily life, we will exercise caution when using information including names, resident identity card numbers, mobile phone numbers, fingerprints, bank account numbers and other similar information. However, there are certain contents that do not seem to be personal information on the surface, but are actually also categorized as personal information and require our special attention. Today, we will discuss these invisible types of personal information and the methods for identifying them.

dynamic IP address

An IP address refers to a string of numbers assigned to Internet-connected computers for communication between such computers. IP addresses can be divided into static IP addresses and dynamic IP addresses. There was once a dispute over whether dynamic IP addresses constitute personal information, which has now been explicitly clarified: all IP addresses, whether static or dynamic, constitute personal information.

In 2007, the Article 29 Data Protection Working Party of the European Union (a data protection working body established on 24 October 1995 by the European Parliament and the Council of the European Union pursuant to Article 29 of the EU Data Protection Directive) submitted a consultation report entitled *OPINION 4/2007 on the concept of personal data*. In the said report, the Working Party held that Internet access service providers and administrators are the entities assigning IP addresses to Internet users. They also record log information including Internet users' login dates, login durations and dynamic addresses, and hold HTTP server logs. Therefore, Internet access service providers and administrators can identify the identity of users to whom dynamic IP addresses are allocated through certain methods. Accordingly, it is beyond doubt that IP addresses fall into the category of personal information as defined under Article 2(a) of the European Data Protection Directive (Directive 95/46).

The Working Party has considered IP addresses as data relating to an identifiable person. It has stated that "Internet access providers and managers of local area networks can, using reasonable means, identify Internet users to whom they have attributed IP addresses as they normally systematically 'log' in a file the date, time, duration and dynamic IP address given to the Internet user. The same can be said about Internet Service Providers that keep a logbook on the HTTP server. In these cases there is no doubt about the fact that one can talk about personal data in the sense of Article 2 (a) of the Directive …"

In the Patrick Breyer Case, the Court of Justice of the European Union Confirms That Dynamic IP Addresses Constitute Personal Information

In 2016, the Court of Justice of the European Union (CJEU) rendered a ruling on the consultation request submitted in the case of Patrick Breyer v. Federal Republic of Germany, holding that dynamic IP addresses constitute personal information.nnThe plaintiff Breyer instituted legal proceedings against the Federal Government of Germany, alleging that the defendant collected his IP address when he visited the government website. After two tiers of trial in Germany, the domestic court found it difficult to determine whether dynamic IP addresses qualify as personal information, and therefore filed a consultation request with the CJEU.nnAfter hearing the case, the CJEU held that, given that Internet service providers can identify the identity of the information subject corresponding to a dynamic IP address by combining such address with other information, dynamic IP addresses fall within the scope of personal information as defined in the EU Data Protection Directive (Directive 95/46).

Having regard to all the foregoing considerations, the answer to the first question is that Article 2(a) of Directive 95/46 must be interpreted as meaning that a dynamic IP address registered by an online media services provider when a person accesses a website that the provider makes accessible to the public constitutes personal data within the meaning of that provision, in relation to that provider,  the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person.

Cookie

It is a text file stored in a computer, which is associated with a specific web page file and records the information generated when the computer accesses the said web page. Accordingly, when the computer accesses the web page again, the information stored in the cookies may be invoked for association.nnA Cookie generally consists of two parts: one is the name, which refers to the URL of the web page accessed by the user; the other is the content, including the specific date of web page access, duration of such access, among others.

Around 2015, Google Inc. faced lawsuits worldwide for collecting personal information via cookies in violation of relevant laws and regulations. In these lawsuits, the trial courts made a judicial finding on the personal information attribute of cookies.

Case of Google v. Judith Vidal-Hall

The background of the case is as follows: From the summer of 2011 to February 17, 2012, Google illegally installed Cookie files in the Safari browser (the web browser provided by Apple to its users) of iPhone users, and bypassed the reset function of the Safari browser. Consequently, even if mobile users explicitly refused the installation, they were unable to delete the Cookie files installed by Google in the Safari browser. Through the aforesaid Cookie files, Google covertly collected the online browsing information of iPhone users, which is referred to as BGI (Browser-Generated Information) in the UK case. No such definition was adopted in the parallel U.S. case, where the term "Cookie" was directly used. Google provided the collected information to advertisers for targeted advertising marketing. In this case, Google contended that Cookies do not constitute personal information, but this contention was not upheld by the UK Court of Appeal. The UK Court of Appeal ruled that, given the BGI information involved in this case covers users' browsing URLs, dates, time, virtual addresses, physical addresses and other content, BGI falls within the scope of personal information as defined in Section 1(1) of the UK Data Protection Act (DPA):

The BGI singles them out and therefore directly identifies them for the purposes of section 1(1)(a) of the DPAhaving regard to the following:

(i) BGI information comprises two relevant elements: (a) detailed browsing histories comprising a number of elements such as the website visited, and dates and times when websites are visited; and (b) information derived from use of the "oubleclick" cookie, which amounts to a unique identifier, enabling the browsing histories to be linked to an individual device/user; and the Defendant (This refers to Google Inc) to recognise when and  the user is online, so advertisements can be targeted at them, based on an analysis of their browsing history.

(ii) Taking those two elements together, the BGI enables the defendant (This refers to Google Inc) to single out users because it tells the defendant(i) the unique ISP address of the device the user is using i.e. a virtual postal address; (ii) what websites the user is visiting; (iii) when the user is visiting them; (iv) and, if geo location is possible, the location of the user when they are visiting the website; (v) the browser’s complete browsing history; (vi) when the user is online undertaking browser activities. The defendant therefore not only knows the user’s (virtual) address; it knows when the user is at his or her (virtual) home.

FTC v. Google Case (Case No. CN 12-04177 SI)

In 2012, Google was subject to regulation by the U.S. Federal Trade Commission (hereinafter abbreviated as FTC) in the United States for the same reason. The two parties entered into a regulatory agreement, which was confirmed by a ruling of the U.S. District Court. The court did not conduct a trial on the substantive merits of the case. However, in this case, Google was also ordered to pay USD 22.5 million in compensation for illegally collecting users' cookies to provide targeted advertising and marketing services for advertising companies. It can be seen that U.S. regulatory authorities have also given a negative assessment of the act of collecting cookies.

BSSID

During the use of mobile phones (including those running the Android system and Apple iOS system), real-time communication with mobile phone base stations, BeiDou satellites, GPS satellites and other entities is required to exchange data on the longitude and latitude of the mobile phone's location.nBSSID (Basic Service Set Identifier) is the document that records the precise longitude and latitude of the mobile phone, which shall generally be provided to a third party only upon user consent. To put it in simple terms, BSSID is the physical address of a mobile phone.nIn a case heard in the United States, an advertising operation company was regulated by the United States Federal Trade Commission for obtaining BSSID information stored in users' mobile phones without user consent.

FTC v. OpenX (Case No. 2:21-cv-09693)

OpenX is a company that provides targeted advertising delivery support for advertisers. In 2018, the FTC found that OpenX illegally collected BSSID information from users' mobile phones without users' consent. The FTC did not directly hold that BSSID constitutes personal information, but ruled that OpenX's act of collecting BSSID information from users' mobile phones without users' consent constitutes an illegal act, and imposed regulatory measures on OpenX.

OpenX collected and transferred the BSSID even if the consumer had not provided consent or had expressly denied permission to collect location data. Therefore, the representations referred to in Paragraph 57 were false or misleading, and constitute a deceptive act or practice in violation of Section 5(a) of the FTC Act, 15 U.S.C. § 45(a).

TC String

A string (String) is a sequence of characters composed of numbers, letters and underscores. It is a data type used to represent text in programming languages. In the ruling delivered by the Court of Justice of the European Union in March 2024, it is held that TC strings constitute personal information.

IAB Europe v. Dutch Data Protection Authority (Case C-604/22)

Gegevensbeschermingsautoriteit is the data protection authority of Belgium (hereinafter referred to as DPA). IAB Europe is a non-profit organization engaged in advertising intermediation and online bidding. Starting from 2019, the DPA received successive complaints against IAB Europe, alleging that it illegally transmitted personal information via TC strings.nnTC strings are string data used by IAB Europe's advertising bidding platform, which contain the declaration of intent of Internet users or mobile application users to consent to the processing of their personal information, namely the consent to the processing of their information by application providers, data brokers and advertisers, as well as users' preference and behavior information generated during web browsing, among others.nnIAB Europe has established a set of data processing rules on its own platform, which stipulate how TC strings are generated, stored and transmitted. IAB Europe adopts a membership system, where only registered members of IAB Europe are eligible to obtain the aforesaid string data. Members shall also comply with the above-mentioned data processing rules formulated by IAB Europe, and carry out targeted advertising delivery after obtaining the Internet user information contained in the TC strings.

The key issue in dispute in the present case is whether the TC character string constitutes personal information. Unable to determine the aforesaid issue, the Court of Appeal of Brussels, Belgium has submitted an application for consultation to the Court of Justice of the European Union.

The Court of Justice of the European Union (CJEU) holds, in light of the provisions of Article 4(1) of the EU General Data Protection Regulation (GDPR), that although TC strings cannot directly identify the identity of a natural person, they are capable of identifying a natural person when combined with other data such as IP addresses, and therefore still constitute personal data as defined under Article 4(1).

The GDPR must be interpreted as meaning that a string composed of a combination of letters and characters,such as the TC String,containing the preferences of a user of the internet or of an application relating to that users consent to the processing of personal data concerning him or her by website or application provider as well as by brokers of such data and by advertising platforms constitutes personal data within the meaning of that provision in so far as, those data may,by reason means, be associated with an identifier, as, inter alias, the IP address of the user’s device, they allow the data subjects to be identified.