The DCD explicitly states that personal data is a fundamental right and therefore cannot be considered as a commodity. However, as mentioned above, the DCD will apply to a contract where the consumer has provided personal data as consideration for the Digital Content, except in situations where the personal data provided by the consumer are (i) exclusively processed by the trader for the purpose of supplying the Digital Content; or (ii) provided in order to allow the trader to comply with legal obligations to which the trader is subject. Digital Content is often supplied in exchange for the consumer's personal data, and this business model is used in a considerable portion of the market, so it is right that the DCD will apply to such contracts in order to ensure that consumers are entitled to contractual remedies.
EU Regulation 2016/679 (the "GDPR") is also concerned with the processing of personal data. The preamble of the DCD states the GDPR will prevail in the event of a conflict between the DCD and the GDPR. The GDPR requires a legal basis for processing of personal data. For traders, the most common bases are (i) that the processing is necessary for the fulfilment of a contract, (ii) a legitimate interest, (iii) to comply with a legal obligation that the trader is subject to, or (iv) that the trader has the individual's consent to the processing.
The DCD may therefore be applicable to contracts pursuant to which a consumer gives the trader personal data as consideration for the Digital Content and the trader processes that personal data on the legal basis of consent or legitimate interest. Processing the personal data for the purpose of supplying the Digital Content under the CDC would be in line with the fulfilment of contract basis under the GDPR, while processing the data for the purpose of allowing the for the trader to comply with legal obligations under the CDC would be in line with the legal obligation basis under the GDPR.
Processing of personal data based on consent in relation to the DCD
If the processing of personal data provided in exchange for the Digital Content is based on consent, the question arises as to what will happen to the contract if a consumer were to withdraw their consent in accordance with their rights under the GDPR. The DCD lacks detail on the consequences of a consent being withdrawn. As such, the question has been left to the national legislators.
In Sweden, withdrawal of consent is not a breach contract but may be cause for termination on other grounds. For example, the Swedish legislator provides the following examples in its preparatory work for transposal of the DCD into Swedish law: the withdrawal of the consent may be seen as a notice of termination from the consumer or as a new basis for the agreement that may permit the trader to terminate the contract based on general principle of a new basis for the agreement enabling termination (as opposed to the consumers breach of contract).
The Swedish government states that the consequences of a withdrawn consent may vary depending on the circumstances in the individual case. To maintain flexibility, the new Swedish legislation should avoid defining the effects of a withdrawn consent and instead let courts assess it on a case-by-case basis. As such, it remains unclear what the effects of a withdrawn consent may mean for a contract under hand governed by Swedish law.
These issues have been discussed by the Norwegian Ministry in its preparatory work for transposing the DCD into Norwegian law but that no precise guidance has yet been given. However, it is stated in the proposed NDSA that there is nothing that prevents the consumer from using personal data as payment, and that withdrawal of payment may mean that the supplier's obligations to deliver would cease in accordance with general contract law principles, including the mutual performance principle. The Norwegian Ministry is nonetheless uncertain as to whether these kinds of issues are likely to occur, partly because the consumer in any case has a right to terminate standing agreements pursuant to the proposed NDSA § 33. In addition, the Ministry has noted that the consumer's right to withdraw consent is something the supplier should consider when preparing agreements and assessing the contractual value.
Processing of personal data based on legitimate interest in relation to the DCD
In a commercial context, it may be difficult to find a legitimate interest that prevails over the rights and freedoms of the data subject, as the legitimate interest of the trader will generally be an economic interest (see EDPS opinion 4/2017 on the proposal of the DCD: link). However, the legitimate interest basis should still be considered, together with an assessment of potential risks to the individual's rights and freedoms when processing their personal data.