Regulatory Watch  /  Ireland  /  Guidance
Moderate impactGuidancePublished

Irish DPC tried to embed Facebook consent bypass into EDPB Guidelines, but final 2019 guidelines omitted it

A letter shows the Irish DPC held ten meetings with Facebook and agreed on a GDPR bypass by moving consent into terms and conditions. The DPC then drafted EDPB guideline language to allow this approach, but other DPAs criticised it, calling it a circumvention of GDPR. The final EDPB Guidelines 2/2019 were published without any reference to the bypass.

Why it matters: The episode highlights regulator influence attempts on EU data‑protection guidance and the pushback from other authorities to protect GDPR integrity.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Second noyb "Advent Reading" from Facebook/DPC Documents
noyb · primary source · Dec 4, 2021
Second noyb "Advent Reading" from Facebook/DPC Documents
noyb · Dec 4, 2021
Details
JurisdictionIreland
RegulatorIrish Data Protection Commission (DPC)
LegislatureEuropean Data Protection Board (EDPB)
LawGeneral Data Protection Regulation
StatusPublished
PublishedDecember 4, 2021
Effectivenot stated
OrganisationsFacebook, Irish Data Protection Commission, European Data Protection Board
Topicsconsent, profiling, targeted advertising, tracking, data minimization, purpose limitation
Datapersonal