메뉴
HN
Hacker News • 58일 전

클릭 한 번에 1,741개 제휴사 동의? GDPR 위반

IMP
8/10
핵심 요약

유럽 프라이버시 단체 noyb는 온라인 사전 dict.cc가 클릭 한 번으로 1,741개 제휴사에 개인정보 제공 동의를 받는 방식이 GDPR에서 요구하는 '명확하고 정보에 입각한 동의' 원칙을 위반했다며 오스트리아 당국에 고발했습니다. 사용자가 모든 제휴사의 개인정보 처리방침을 읽는 데 170시간이 걸리는 등 실질적인 동의가 불가능하여, 온라인 광고 업계의 만성적인 개인정보 남용 관행을 저지하기 위한 중요한 법적 테스트케이스가 될 것입니다.

번역된 본문

쿠키 배너 / 2026년 7월 30일

오늘 noyb는 인기 있는 온라인 사전 dict.cc에 대한 고발장을 제출했습니다. 일반 데이터 보호 규정(GDPR)은 동의가 자유롭고, 정보가 제공되며(informed), 구체적이고 명확해야 한다고 요구합니다. 그러나 dict.cc를 방문하면 사용자는 단 한 번의 클릭으로 무려 1,741개의 '파트너'에 대한 온라인 추적에 동의하도록 강요받습니다. 이로 인해 사용자는 자신의 데이터에 정확히 누가 접근할 수 있는지, 그리고 그것이 실제로 어떻게 사용되는지 알 수 없습니다. dict.cc는 극단적인 사례이지만, 수많은 제3자를 위해 사용자의 프라이버시 권리를 맹목적으로 포기하도록 요청하는 것은 GDPR이 시행된 지 8년이 지난 현재에도 온라인 광고에 의존하는 웹사이트와 앱에서 불행하게도 흔히 발생하는 문제입니다.

dict.cc에 대한 고발 (영어 - 자동 번역) dict.cc에 대한 고발 (독일어 - 원문)

배경. 온라인 광고 회사들은 개인화된 광고를 표시하기 위해 사람들의 브라우징 습관, 관심사, 상호 작용 및 위치를 추적하는 데 크게 의존합니다. 그러나 EU 프라이버시법에 따르면 온라인 추적은 기본적으로 불법입니다. 따라서 기업이 사용자를 추적하려면 사용자의 프라이버시 권리를 '포기'하는 데 대한 동의를 요청해야 합니다. 그것이 바로 모든 곳에서 동의 배너를 보게 되는 이유입니다. 그러나 문제는 이러한 배너 대부분이 서로 데이터를 공유하는 수백, 수천 개의 온라인 광고 회사에 대한 동의를 요청한다는 것입니다. 이것은 처음에는 침해적인 온라인 광고를 위해 수행되지만, 데이터는 종종 다른 목적을 위해 데이터 브로커에 의해 공유 및 판매되기도 합니다. 민주주의 및 권위주의 정부의 법 집행 기관조차 감시 목적으로 이러한 데이터를 구매합니다.

정보에 입각하지 않은 동의. dict.cc의 동의 요청에는 현재 사용자의 기기 및 개인 데이터에 대한 액세스 권한이 부여될 1,741개의 '파트너' 회사가 언급되어 있습니다. 이들의 모든 개인정보 처리방침을 읽으려면 (각 정책을 6분 동안 빠르게 훑어보기만 해도) 최소 170시간이 걸립니다. 이는 단일 동의 요청에 대해 1주일이 넘는 시간입니다. 또한 이러한 '파트너'들은 사용자의 데이터를 더욱 전달한다고 말하는 경우가 많습니다. 고발인과 다른 웹사이트 사용자들에게 이것은 자신들의 '동의' 결과를 이해하는 것을 사실상 불가능하게 만듭니다. 이러한 일반적인 관행(예: www.repubblica.it, www.bergfex.de, www.fifa.com 참조)은 GDPR에서 요구하는 '정보에 입각한 동의(informed consent)'를 얻는 것을 본질적으로 불가능하게 만듭니다.

noyb의 데이터 보호 변호사 펠릭스 미콜라쉬(Felix Mikolasch)는 "1,741개 회사의 개인정보 처리방침을 제대로 읽고 이해하는 데는 며칠 또는 몇 주가 걸릴 것입니다. 이것이 정보에 입각한 결정을 내릴 수 있게 해줄 것이라고 가정하는 것은 터무니없습니다."라고 말했습니다.

오스트리아에서 제출된 고발. dict.cc는 고발인의 데이터를 처리할 유효한 법적 근거가 없기 때문에 noyb는 오스트리아 데이터 보호 당국에 고발장을 제출했습니다. 우리는 오스트리아 데이터 보호 당국이 온라인 사전에게 불법적으로 처리된 데이터를 삭제하도록 명령하고, 고발인 데이터의 모든 수신자에게 삭제 사실을 통지하도록 요청하고 있습니다. 또한 noyb는 향후 유사한 위반을 방지하기 위해 벌금이 부과되어야 한다고 제안하고 있습니다. 이 사건은 일반적인 중요성을 고려할 때 당국이 더 광범위한 금지령을 발부하거나 유럽 데이터 보호 이사회(EDPB)에 의견을 구하기 위해 회부할 수도 있습니다.

noyb의 데이터 보호 변호사 마틴 바우만(Martin Baumann)은 "수천 개의 '파트너' 회사가 내 개인 데이터를 사용하는 데 동의하는 것은 잘못된 느낌이 들 뿐만 아니라 실제로 잘못된 것입니다. 데이터 보호 당국은 마침내 이 관행에 종지부를 찍어야 합니다."라고 말했습니다.

원문 보기
원문 보기 (영어)
Cookie Banners / 30 July 2026 Today, noyb has filed a complaint against the popular online dictionary dict.cc. The GDPR requires that consent is freely given, informed, specific and unambiguous. However, when visiting dict.c c , users are nudged into consenting to online tracking by a staggering 1,741 (!) “partners” with a single click. This makes it impossible for users to know exactly who has access to their data and how it is actually used. While dict.cc is an extreme example, requests to blindly waive your right to privacy for countless third parties is unfortunately a common issue with websites and apps relying on online advertising, even 8 years after the GDPR came into force. Complaint against dict.cc (EN - auto-translation) Complaint against dict.cc (DE - original) Background. Online advertising companies heavily rely on tracking people ’s browsing habits, their interests, interactions and whereabouts to show them personalised ads. However, according to EU privacy law, online tracking is illegal by default. Companies must therefore ask for your consent to “waive” your right to privacy if they want to follow you around. That’s why you see consent banners everywhere. The problem is, however, that most of these banners request your consent for hundreds, if not thousands, of online advertising companies that share your data among each other. While this is initially done for invasive online advertising, data is often also shared and sold by data brokers for other purposes . Even law enforcement agencies from both democratic and authoritarian governments buy such data for surveillance purposes. Uninformed consent. dict.cc ’s consent request currently mentions 1,741 “partner” companies that would be granted access to the device and the personal data of users. Reading all of their privacy policies would at least take 170 hours (even if you just scan each policy for 6 minutes ) . That is more than an entire week for one single consent request. In addition, these “partners” often say that they forward your data even further . For the complainant, as well as for other website users, this makes it practically impossible to understand the consequences of their “consent”. This common practice (see e.g. www.repubblica.it , www.bergfex.de , www.fifa.com ) makes obtaining an “informed consent”, as required by the GDPR, essentially inconceivable. Felix Mikolasch, data protection lawyer at noyb : “ It would take days or even weeks to properly read and understand the data protection policies of 1,741 companies. It is ridiculous to assume that this would allow for an informed decision. ” Complaint filed in Austria. noyb has now filed a complaint with the Austrian Data Protection Authority, as dict.cc lacks a valid legal basis for processing the complainant ’s data . We request the Austrian DPA to order the online dictionary to delete the unlawfully processed data – and to inform all recipients of the complainant ’s data about the deletion. Furthermore, noyb is proposing that a fine be imposed to prevent similar breaches in the future. The Authority may also issue a wider ban or refer the matter to the European Data Protection Board for an opinion, given its general significance. Martin Baumann, data protection lawyer at noyb: “Consenting to thousands of ‘ partner ’ companies using your personal data does not only feel wrong, it indeed is. The data protection authority must finally put an end to this practice. ”