Background on the Key Players
NOYB, a privacy advocacy group based in Vienna, Austria, has taken legal action against TikTok, Grindr, and AppsFlyer for allegedly violating regional privacy laws. These companies are accused of tracking user activities across various applications without obtaining proper consent, thereby exposing sensitive data to potential risks.
TikTok, owned by the Chinese company ByteDance, is a popular social media platform known for its short-form video content. Grindr, an LGBTQ+ dating app, has faced scrutiny over user data privacy in the past. AppsFlyer, a mobile attribution and marketing analytics company, facilitated unauthorized data transfers between TikTok, Grindr, and users.
NOYB’s Allegations and Findings
NOYB claims that TikTok tracked a specific user’s activity on Grindr through AppsFlyer, raising concerns about non-compliance with the EU’s General Data Protection Regulation (GDPR).
- Data Sharing and Transfer: TikTok, Grindr, and AppsFlyer allegedly shared and transferred sensitive user data without legal grounds. This includes information about a user’s sexual orientation, which falls under special protection under GDPR to prevent discrimination.
- Unauthorized Data Access: A user discovered through a data access request that TikTok had accessed sensitive details from other apps, including Grindr and LinkedIn usage, as well as items in their shopping cart.
- Transparency Violations: TikTok only disclosed this information to the user after repeated inquiries, failing to meet GDPR transparency requirements.
NOYB asserts that neither AppsFlyer nor Grindr had legal justification for sharing user data with TikTok.
Regulatory Actions and Ongoing Concerns
In response to data transfer concerns, Ireland’s Data Protection Commission (DPC) imposed a €530 million fine on TikTok in May. Meanwhile, Grindr faces a massive lawsuit in London for allegedly sharing users’ HIV status with third parties without consent between 2018 and 2020.
Key Questions and Answers
- Who is NOYB? NOYB, or “No es asunto tuyo” in Spanish, is a privacy advocacy group based in Vienna, Austria.
- What are the main allegations against TikTok, Grindr, and AppsFlyer? These companies are accused of tracking user activities across various applications without obtaining proper consent, thereby exposing sensitive data to potential risks.
- What is the significance of GDPR in this case? The EU’s General Data Protection Regulation (GDPR) requires special protection for sensitive information, such as sexual orientation, to prevent discrimination.
- What regulatory actions have been taken so far? Ireland’s Data Protection Commission (DPC) fined TikTok €530 million for data transfer concerns, and Grindr faces a massive lawsuit in London for allegedly sharing users’ HIV status without consent.