ACCC’s increasing interest in privacy
The ACCC has taken an increasing interest in privacy over recent years. In the ACCC’s Digital Platforms Inquiry Report in 2019, the ACCC recommended a broad reform of Australian Privacy Law, including strengthening protections under the Privacy Act 1988 (Cth) (Privacy Act). A review of the Privacy Act is currently underway, with a discussion paper set to be released in 2021.
Ahead of any such reform, the ACCC has turned to existing legislation, such as the Australian Consumer Law (ACL) under sch 2 of the Competition and Consumer Act 2010 (Cth), to take action against what it alleges to be misleading and deceptive conduct in relation to the collection and use of personal information, even if such use is not a breach of the Privacy Act.
More recently, on 16 April 2021, the Federal Court of Australia found that Google had misled consumers in various representations regarding the collection and use of personal location data from Android mobile devices between January 2017 and December 2018. The ACCC was successful in respect of some (but not all) of its claims. The ACCC considers this decision a “world-first” in the area of privacy and data collection by big tech companies. The period for appeal is still open and so this decision may yet be appealed.
Other Australian consumer protection regulators are also taking an interest in the means by which suppliers of goods and services to Australian consumers explain privacy issues to those consumers. In NSW, Australia’s most populated state, the legislature has enacted a consumer protection measure that deems any term of supply of goods or services to a consumer that “permits the supplier to provide data about the consumer, or data provided by the consumer, to a third party in a form that may enable the third party to identify the consumer” to be a term that “may substantially prejudice the interests of the consumer”. The consequence of that statutory deeming provision is that a supplier “must, before supplying a consumer with goods or services, take reasonable steps to ensure the consumer is aware of the substance and effect of” the term. In other words, this requires affected suppliers to be more transparent about the substance and effect of the relevant contractual term of supply that permits the supplier to disclose identifiable consumer data to a third party prior to the consumer entering into the supply contract. This statute has been in force since 1 July 2020, and contravention of this provision attracts the same (substantial) pecuniary penalties as for a contravention of the ACL. We are not aware of any enforcement proceedings having been taken by NSW Fair Trading in relation to this issue, but that must only be a matter of time.
What was ACCC v Google LLC (No 2) case about?
The ACCC case centred around two particular settings on Android devices, the Location History and Web & App Activity settings. While the Location History setting was by default turned ‘off’, the Web & App Activity setting was defaulted to ‘on’. With the Web & App Activity setting turned ‘on’, Google could obtain, retain and use personal location data.
The ACCC claimed that in breach of ss 18, 29 and 33 or 34 of the ACL, users of Android devices between January 2017 and December 2018, were misled to believe that these default settings did not allow Google to obtain and use personally identifiable location data.
The ACCC ran its case by dividing Android users during the relevant time periods into three separate categories. The first involved users who set up their devices between certain dates and were shown particular ‘Privacy and Terms’ screens. The second related to users who had decided to turn their Location History setting ‘off’, whether during the set up of the device or at a later time. The third category concerned users who had decided to turn their Web & App Activity setting ‘off’ after the set up of the device. These categories were split into further classifications, according to the different screens users were shown at different dates and on different devices.
The factual description of the categories and the different claims is complex. The first category of claim provides a useful example of the claims and some of the interesting judicial commentary. We will limit our focus to that first category.
The set up claims
The first category of claims related to the set up of the Android devices in the applicable period. There were 3 layers of screens in question.
All users had to view the ‘Privacy and Terms’ screen, which gave the user the opportunity to click on one of 3 buttons – ‘Agree’, ‘Don’t create the account’ or ‘More Options’. The parties accepted that most users would “blow through” the Privacy and Terms screen and click ‘Agree’ without visiting any of the other nested screens. The ACCC’s case did not include these users. The ACCC’s case focused on a subset of users (that the parties agreed was “atypical”) who were interested in privacy related issues and clicked on the ‘More Options’ button. On the ‘More Options’ page, users were presented with a Location and a Web & Activity heading, both of which had an opportunity to click a ‘Learn More’ button to go to an additional screen with more information. Notably, the Web & App Activity heading under the ‘More Options’ screen did not include the word ‘location’, and instead referred to ‘activity’.
Thawley J considered that the degree of attention paid to the screens would have varied according to the user’s interest. Ultimately, his Honour held that some reasonable users in the first category, acting reasonably, would not have clicked on all the links necessary to gain a full understanding. As a result, these users “would have incorrectly concluded from Google’s conduct as a whole… that the Location History setting was the setting which therefore controlled whether Google would obtain personal data about the user’s location”. The ACCC was therefore successful in making its case for the first category of users.
Interesting commentary on how to apply the ACL
In reaching this conclusion Thawley J made a number of comments that will be useful in considering the application of the ACL to other scenarios.
- The Court must put itself in the position of the relevant consumer setting up their device.
In this case, Thawley J commented that Google’s arguments were more attractive the longer one looks at the screens. However, he concluded that that is not the appropriate approach. “The screens were read by users setting up the device. Such users, even ones with heightened privacy concerns, would not re-read screens with the kind of careful attention that has been necessary in considering the various arguments put by the parties”.
- While the relevant materials must be read as a whole, they must be read in the way the consumers would have read them.
- It is enough to demonstrate that some ‘reasonable users’ have been misled or were likely to have been misled.
It was necessary to consider ordinary or reasonable members of the class excluding extreme or fanciful responses. The court rejected the submission that this required the court to determine a single response from a single hypothetical ‘reasonable user’. “The number or proportion of reasonable users who were misled, or were likely to have been misled, does not matter for the purposes of establishing contravention”. The fact that some people were not misled, is not the point. It was accepted by the parties there is no “not insignificant number test”. As a result, it is a question of whether some reasonable users had been misled or were likely to have been misled, but it is not necessary to demonstrate any particular portion of reasonable users were misled or likely to be misled.
- A range of factors may be relevant in determining whether conduct gives rise to a representation that may be misleading or deceptive.
- Representations may be express or implied from words or conduct;
- Conduct must be considered as a whole, and must be assessed in context – it is wrong to simply analyse the separate effect of multiple representations; and
- Where there are conflicting statements in consumer materials, the prominence of those conflicting statements and the likelihood of the consumer reading and absorbing neutralising materials.
What are the key takeaways from this decision?
Care must be taken in summarising or paraphrasing. In summarising data collection and usage practices it is not just what is said, but what is not said, that contributes to the overall representation.
Put yourself in the shoes of the consumer. Review your customer collateral from the customers’ perspective, taking into account the context of when a customer will be reading those materials. You cannot assume a customer will carefully and meticulously pore over the legal terms. How you use headings and what information is emphasised will go to the overall representations made to customers.
Increasing focus on privacy. This is another (albeit partial) success for the ACCC in using the ACL in the context of privacy and personal information. We expect the ACCC and other regulators to continue to look closely at privacy related issues through their regulatory lens while the privacy review is underway.