Earlier quoted context omitted.
German law requires to use opt-in, i.e. the default setting of agreements to transfer data to other parties must be 'no' (or the checkbox must be empty). That way, it is very easy to make sure there is explicit consent to transfer of data, and the service provider can't hide it in the TOS. Of course, the service provider is also free to limit or close its services to users that do not consent. That is actually what t…
I don't think this is very useful in most cases. Suppose a service requires data transmission to operate, either intrinsically, or it just chooses to require it. It displays a checkbox, unchecked by default, and unless the user checks it, the service isn't going to work; checking the checkbox is functionally equivalent to the "I Agree" TOS button. I expect users will check the checkbox without reading any explanation…
- You can only take as much as you need
- You cannot ask for data for one thing and use it for another
- You have to clearly state what data you will use for what purpose
- The opt-in has to be distinct from other opt-ins (so, 100 pages of EULA and then a checkbox "I accept" doesn't cut it)
The only problem here is that the penalities for breaking the data protection laws aren't very high .. I'd like to see percentages of a companies revenue.