cookies), and the GDPR which requires that consent for data processing be given
“freely”, a term which many—such as the EU Data protection Supervisor—interpret
as “without economic incentives”.
24
2.8 New Fields: Commodification of Data
There is a growing conflict (also in Italy) between data protection laws and contract
law. The bone of contention is the conflicting notion of “consent” as expressed in
data protection laws and in decisions by the Italian Garante
25 and “consent” as it has
historically been developed in contractual theory. The former is construed in a very
strict and formalistic way, significantly limiting the possibilities to use and transfer
data legitimately collected. The latter sees data as a commodity that can be legitimately be transferred to third parties, normally on the basis of an adequate consideration represented by the services one receives when using on-line services.
This interpretative clash might lead to a “tragedy of the anti-commons” by which
fragmentation of rights over data could determine a paralysis in their exploitation,
particularly necessary in a “Big Data” environment.
26
2.9 Damages
Directive 1995/46, and with it ensuing Italian legislation, establishes strict liability
for unlawful protection, in the sense that the burden of proof of lawful treatment is
upon the data holder. This has brought to considerable amount of litigation
concerning not the existence of an unlawful treatment, generally considered in res
ipsa, but on the liquidation of damages arising from the tortious act.
Flooded by trivial litigation, mostly raised in front of justices of the peace, the
Cassazione (decision of 16 July 2014, n. 16133
27 ) first set on the plaintiff the burden
24 EDPS, Opinion on the Proposal for a Directive on certain aspects concerning contracts for the
supply of digital content, n. 4/2017, p. 9. See also EDPS, Privacy and competitiveness in the age of
big data: The interplay between data protection, competition law and consumer protection in the
digital economy (2014), Brussels, p. 8ff. A much more firm position has been taken by the EU
Article 29 Data Protection Working Part, Guidelines on consent under Regulation 2016/679
(28.11.2017–10.4.2018): “As data protection law is aiming at the protection of fundamental rights,
an individual’s control over their personal data is essential and there is a strong presumption that
consent to the processing of personal data that is unnecessary, cannot be seen as a mandatory
consideration in exchange for the performance of a contract or the provision of a service” (at para.
3.1.2).
25 See Thobani S (2016) I requisiti del consenso al trattamento dei dati personali, Rimini.
26 See Resta G, Zeno-Zencovich V (2018) Volontà e consenso nella fruizione dei servizi in rete, in
Rivista trimestrale diritto e procedura civile, p. 351.
27 Published in Foro italiano (2015) I, c. 120.
250
V. Zeno-Zencovich
“freely”, a term which many—such as the EU Data protection Supervisor—interpret
as “without economic incentives”.
24
2.8 New Fields: Commodification of Data
There is a growing conflict (also in Italy) between data protection laws and contract
law. The bone of contention is the conflicting notion of “consent” as expressed in
data protection laws and in decisions by the Italian Garante
25 and “consent” as it has
historically been developed in contractual theory. The former is construed in a very
strict and formalistic way, significantly limiting the possibilities to use and transfer
data legitimately collected. The latter sees data as a commodity that can be legitimately be transferred to third parties, normally on the basis of an adequate consideration represented by the services one receives when using on-line services.
This interpretative clash might lead to a “tragedy of the anti-commons” by which
fragmentation of rights over data could determine a paralysis in their exploitation,
particularly necessary in a “Big Data” environment.
26
2.9 Damages
Directive 1995/46, and with it ensuing Italian legislation, establishes strict liability
for unlawful protection, in the sense that the burden of proof of lawful treatment is
upon the data holder. This has brought to considerable amount of litigation
concerning not the existence of an unlawful treatment, generally considered in res
ipsa, but on the liquidation of damages arising from the tortious act.
Flooded by trivial litigation, mostly raised in front of justices of the peace, the
Cassazione (decision of 16 July 2014, n. 16133
27 ) first set on the plaintiff the burden
24 EDPS, Opinion on the Proposal for a Directive on certain aspects concerning contracts for the
supply of digital content, n. 4/2017, p. 9. See also EDPS, Privacy and competitiveness in the age of
big data: The interplay between data protection, competition law and consumer protection in the
digital economy (2014), Brussels, p. 8ff. A much more firm position has been taken by the EU
Article 29 Data Protection Working Part, Guidelines on consent under Regulation 2016/679
(28.11.2017–10.4.2018): “As data protection law is aiming at the protection of fundamental rights,
an individual’s control over their personal data is essential and there is a strong presumption that
consent to the processing of personal data that is unnecessary, cannot be seen as a mandatory
consideration in exchange for the performance of a contract or the provision of a service” (at para.
3.1.2).
25 See Thobani S (2016) I requisiti del consenso al trattamento dei dati personali, Rimini.
26 See Resta G, Zeno-Zencovich V (2018) Volontà e consenso nella fruizione dei servizi in rete, in
Rivista trimestrale diritto e procedura civile, p. 351.
27 Published in Foro italiano (2015) I, c. 120.
250
V. Zeno-Zencovich
