Thread · 7 tweets · 11 Sept 2020

I'm seeing a few people saying that Apple's IDFA change is somehow a problem under the GDPR. Often the argument is that it conflicts with the IAB TCF. I actually think it's the exact opposite: under the GDPR, they have no other option than to make this opt in.
↺ 6
(As always: you take legal advice from a random person on Twitter at your own risk. If in doubt, ask a lawyer, or even just anyone with some kind of education.)
Managing the IDFA is not something that Apple does at the user's direction, it is in no way necessary in order to support anything that the user is asking for. Put differently, Apple determines (on its) the means and purposes of IDFA processing: it is a data controller for that.
When Apple chooses to provide the IDFA to another controller (and how it is provided), they need a legal basis to do so. Others may disagree, but I see no legal basis for this (knowing that this isn't Apple's direct marketing) other than consent.
↺ 2
Rather than resisting this change and trying to save a broken system (especially the TCF), this is a great occasion to look at what other platforms are doing with identifiers - especially for their own purposes - without solid legal bases.
↺ 1
I'm thinking of Google of course (not just Android) but also for instance Facebook, notably in its in-app browser. Overall, the responsibilities of user agents under the GDPR have been largely ignored and looking at them could have great benefits for users (and publishers).
↺ 1