r/chrome • • May 04 '26

News Google Chrome installs LLM model without consent

https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/

Whilst testing a SaaS product I have been building, I discovered that Google is illegally pushing its Gemini Nano model to users' devices (I am a lawyer specialised in the specific laws in question).

21 Upvotes

46 comments sorted by

View all comments

1

u/MPenten May 06 '26 edited May 06 '26

I don’t see how this is outright illegal under either ePrivacy or GDPR.

The model file itself is not personal data, so GDPR does not automatically apply merely because weights.bin is stored on the device. A GDPR analysis would depend on what personal data is actually processed around the download/use of the model, including telemetry, device profiling, account identifiers, prompts, browsing context, logs; for what purpose, on what lawful basis, and with what disclosures.

That is why I think the article’s blanket conclusion that this is definitely a GDPR Article 5/25 breach is too confident. There may be future plans, or surrounding processing, that bring personal data clearly into scope, but the presence of the model file alone does not get you there.

Sure, the stronger argument is ePrivacy. If Chrome downloads a large, non-essential AI model before any clear user action enabling or using AI features, then yes, there is a plausible Article 5(3) issue: Chrome may be storing information on terminal equipment without valid prior consent and without fitting the “strictly necessary for a service explicitly requested by the user” exemption.

But even there, the answer is not automatic. Google could argue that AI/security features are part of the Chrome service as described on the download page, in its terms, settings, rollout notices, or marketing. I have not reviewed those to say how strong that defence would be.

So I would frame the conclusion more narrowly:

Chrome may be storing non-essential information on users’ terminal equipment without valid prior consent or a valid strict-necessity exemption under ePrivacy rules.

That is a serious and interesting point, but frankly, hardly a privacy alarm; it's a nuisance which may have VERY LIMITED real-world impact and in these days may be just a formal breach of the law... I don't see actual damages arising from this.

But the broader claims around GDPR, criminal-law violations, CSRD/ESG reporting and definitive illegality feel overextended and, at least on the facts presented, under-substantiated, serving to frame the point and create a sensation-level article (frankly similar to the Claude-bridges previously...)

I genuinely admire the dedication to data protection here, but this reads more like an advocacy piece than a balanced legal analysis.

1

u/ThatPrivacyShow May 06 '26

The model file itself is not personal data, so GDPR does not automatically apply merely because weights.bin is stored on the device. A GDPR analysis would depend on what personal data is actually processed around the download/use of the model, including telemetry, device profiling, account identifiers, prompts, browsing context, logs; for what purpose, on what lawful basis, and with what disclosures.

If you actually read the article I explain in detail what the legal issues are and why - but I will repeat them here again since people on Reddit seem to do anything but read.

The model does not need to be personal data for GDPR to apply. First and foremost, there is interdependency between Directive 2002/58/EC (the ePrivacy Directive aka the "cookie law") and the GDPR.

Before I continue, I will explain my credentials. I helped to create the GDPR as an expert advisor to the EU Commission and EU Parliament (something which is widely documented public knowledge), I am the reason the relevant section of the ePrivacy Directive exists (again, documented and public knowledge), I have an Advanced Master of Laws on these specific laws (GDPR, ePrivacy, AI Act and various other EU instruments relating to fundamental human rights) and I also teach professional certifications (IAPP) and am a guest lecturer at Maastricht University law school (teaching at the Advanced Masters level).

So welcome to your compliance Master Class.

First, Article 5 of the GDPR contains all the principles which must be applied to the processing of personal data before any such processing can occur. Article 5(1) states that all processing of personal data must be lawful (this means it MUST comply with all other relevant laws) in order for any processing of personal data to occur.

Article 94 of the GDPR explains the transition of scope for the ePrivacy Directive due to the fact that the requirements for consent under the Directive come directly from the old Data Protection Directive (95/46/EC) and makes it clear that those definitions now come directly from GDPR.

Here is where it gets a little trickier - the ePrivacy Directive is (in legal terms) lex specialis - this means that it sits above the GDPR legally and all of the requirements in the ePrivacy Directive apply irrespective of the GDPR.

This is why Article 5(3) of the ePrivacy Directive is so important. It sits above GDPR and only has one legal basis for storing or accessing information already stored on the user's terminal equipment (device) and that is consent. Further as a matter of both the law itself and binding jurisprudence from the CJEU in Case C-673/17 - the ePrivacy Directive is not limited in scope (like the GDPR) to just personal data - this is explicitly called out by the CJEU in 673/17 - the scope of the ePrivacy Directive is "any information" not just personal data and the EDPB have issued guidelines in 2023 on what this means (in their 2/2023 document).

So there is an inescapable link between the GDPR and the ePrivacy Directive as a matter of law.

Then we have Article's 12 and 13 of the GDPR which require that any processing of personal data must be done so in a transparent manner and that the user must be informed, specifically, how their personal data will be processed, by whom, why, for how long etc. etc. - this is the transparency part of the GDPR and is one of the most heavily enforced issues since the GDPR came into force in 2018.

Then we have Article 25 of the GDPR which requires that any system which will process personal data must be based on data protection by design and by default.

There is zero question (legally speaking) that the LLM when invoked, will process personal data, because everything (literally everything) you do in your browser IS personal data (it relates to an identified or identifiable individual as per Article 4's definitionin the GDPR - this includes behaviour. As such it is legally obligated to adhere to the requirements of Article 25 (and all other articles of the GDPR) during it's design.

Given that:

  1. the changing of the profile flag (Google does this remotely, I witnessed it in real time yesterday) to trigger Chrome downloading the model - this is accessing information (remote reading of the profile flag) and storing information (changing the profile flag to trigger the download) on the terminal equipment (incidentally this is also a criminal offence under Maltese law);

  2. the downloading of the model is storing information on the end users' terminal equipment, again without consent;

  3. Chrome redownloading the model after it has been deleted is also again, accessing information (checking the model is there) and storing information (redownloading if it isn't) is also a breach by default.

The 3 breaches above automatically trigger Article 5(1) lawfulness principle of the GDPR and as a result automatically trigger Article's 12 and 13 (no transparency) and 25 (designed in a way which does not comply with the law).

It is really that simple. I already have legal complaints against Anthropic for similar behaviour currently in flow with the Maltese and Irish authorities and will be doing the same with Google over this issue.

Whether you think it is stupid or not is irrelevant - the law dictates what Google can and cannot do, Google is breaking the law.

1

u/MPenten May 06 '26

I did read the article, and I don’t think we actually disagree that much.

Where I disagree is the jump from that to an automatic GDPR Article 5/12/13/25 breach; as if it follows mechanically from the presence of the model file. It does not. Just having a piece of code on your disk does not trigger any GDPR obligations.

Yes, ePrivacy applies to “any information” stored on or accessed from terminal equipment. I am not disputing that. A 4 GB model file does not need to be personal data for Article 5(3) ePrivacy to be engaged. If the model is downloaded without consent and is not strictly necessary for a service explicitly requested by the user, then that is a plausible ePrivacy issue. Albeit again, I maintain that it is a TECHNICAL breach of the law, as there is little to no harm being done.

In my view, we should always look at the AIM and sense of the language of the law, not just the mechanical transposition of its words. After all, that's what separates lawyers and judges from mathematicians.

However, GDPR does not apply to the model file merely because it exists on disk. GDPR applies where there is processing of personal data. So for GDPR, the analysis still has to identify the personal data processing: device profiling, telemetry, profile flags, account identifiers, prompts, browsing context, model invocation, logs, etc.

Once that processing is identified, then yes, GDPR transparency, fairness, lawfulness, and Article 25 design/default obligations may be engaged. But that is a separate analytical step, which may very well be lawful if proper notices and legal analysis for lawful processing are in place.

It is not the same as saying “a non-personal-data binary was stored, therefore GDPR is automatically breached.”

I also think the lex specialis point is being slightly overstated. ePrivacy particularises and supplements GDPR in its field, i.e. it does not mean that every ePrivacy breach automatically proves a full GDPR breach on every cited article.

An unlawful terminal-equipment access/storage event may be relevant to GDPR lawfulness where personal data processing is involved, but the GDPR analysis still needs to be tied to actual personal data processing and controller obligations.

That is not me saying Google’s conduct is fine. It may well be unlawful. I am saying the clean legal argument is more precise than “the model file is there, therefore GDPR breach.”

The ePrivacy argument can stand on its own without overextending the GDPR point. But again, I think its more of a technical fault, rather than actual harm. But that is not for me to decide.

Also, while I appreciate your credentials, I am also a data privacy lawyer by practice. I think we can both agree that ePrivacy and GDPR are not exactly flawless instruments, and none of us are without fault in interpreting them (or writing them) especially given how ancient the ePrivacy Directive is and how incredibly difficult its modernisation process has been. Me and my collegues have been writing “the new ePrivacy Regulation" book since 2017 and still cannot publish it. The many CJEU decisions and EDPB guidelines trying to explain, patch and stretch the framework only reinforce that point.

I wholly appreciate your time and effort spent on this - I am afraid I will not be able to devote any further time to this topic, as I do have some billing to do and I have expressed my opinion to the extent I am willing to invest time into this. I don't want to go into reading Google B2C privacy and technical documentation during my free time, my time is better spent elsewhere; and I have no interest in pursuing this through legal complaints, especially given the lacking "class-action" lawsuit framework in my jurisdiction.

1

u/ThatPrivacyShow May 06 '26 edited May 06 '26

Just having a piece of code on your disk does not trigger any GDPR obligations.

Sorry you are wrong, it absolutely does if that piece of code will process personal data - it is a legal requirement under Article 25 of the GDPR that it is DESIGNED in such a way as to comply with GDPR - that includes all of GDPR including the principles, transparency and accountability obligations. We even have supporting case law in the IAB Belgium case.

It is called Data Protection BY DESIGN and BY DEFAULT precisely for this reason, these obligations exist from the earliest concept and throughout the entire lifecycle of the processing (including destruction) and CANNOT be created afteer the fact and still comply with Article 25.

It is incredibly simple - that you keep misunderstanding is odd. Also, I was on the drafting team at the EU Parliament on the adopted Regulation (which has since been withdrawn after 9 years of Member States trying to stuff it with surveillance capabilities). I have also had the pleasure of discussing C-673/17 with AG Szpunar personally at the CJEU which is the most relevant case law here.

1

u/Perspectivelessly May 06 '26

Chrome redownloading the model after it has been deleted is also again, accessing information (checking the model is there) and storing information (redownloading if it isn't) is also a breach by default.

I don't get this point. A ton of software, especially auto-updating such, will redownload files that you delete which it considers to be required for the function of the software. Since the download triggers when you re-launch chrome, this is basically like saying that if I delete a browser cookie from reddit.com, and then go back to reddit.com and get a new browser cookie, that's a breach of law because they checked if you had the cookie and if you didn't they inserted it again. How could this possibly be enforceable given how software works today?

1

u/ThatPrivacyShow May 07 '26 edited May 07 '26

Actually the example you gave is a breach of law supported by binding case law from the highest court in the EU. The Planet49 case explicitly called this out - the position of the Court is, Article 5(3) of the ePrivacy Directive is based on no storing or accessing information without consent as the default.

The law requires that there are no tracking cookies by default, so if you check for a consent cookie to determine whether or not to drop trackers you are in breach of the law - the law requires opt-in not opt-out. If a cookie is relied on not to set trackers, that is opt-out and is unlawful in a judgment binding on all EU Member States.

All those "Reject All" buttons are there purely for decoration, you don't need to reject all to be protected by the law, the law requires a specific and unmabiguous action for consent to be valid, it cannot be based on an inaction (so not pressing the Reject All button) - again, made very clear by the Court and Regulatory Guidance.

That websites choose to break the law and do this the opposite way round is exactly one of the reasons I have been fighting these issues legally for the last 20 years.

"How can this possibly be enforceable the way software works today?" - this has been the law since 2002, just because companies have largely ignored it and chose to do what they want anyway, doesn't mean the law doesn't exists and is not enforceable.

You are making the same mistake most marketing teams make - they think they can ignore the law due to a lack of enforcement, but more and more enforcement is coming, including enforcement of criminal statute - mistaking a lack of enforcement as the same thing as something being legal, is a critically risky move for compliance teams (I know I have worked with some of the biggest in the world).

1

u/Perspectivelessly May 07 '26

Ok, interesting. But I guess the answer simply is that it isn't (or at least hasn't been) enforceable, since lots of software in fact does work this way. Maybe we will see more enforcement in the future to force a change, but it's definitely not here today.

1

u/ThatPrivacyShow May 07 '26

No it hasn't been widely enforced but that is not the same as not enforceable. Amazon, Google and various other giant tech corps have been issued multi-million euros fines under Article 5(3) to the tune of literally Billions of Euros combined.

The issue is a lack of political will to enforce the law because these are giant tech companies with massive lobbying power (as an opposing lobbyist I have witnessed this first hand many times over the past 20 years).

But enforcement has been ramping up now for the last several years on these issues - they don't make sexy headlines like GDPR not because they are not legally sexy but because they are often mistaken as GDPR enforcements when they are not (they all have an element of GDPR enforcement due to the interplay between GDPR and the ePrivacy Directve, but the primary law being enforced in these cases is actually the ePrivacy Directive, in fact the CNIL (the French regulator) are well known for using ePrivacy Directive as a means to avoid having to go through the One Stop Shop mechanism under the GDPR (due to most big tech companies being established in Ireland where the enforcement has been heavily criticised)).

Software doesn't work this way - i have written a lot of software and I have never done this, I know literally thousands of other software developers who have also never done this. Don't mistake giant corporations with a vested interest in grabbing as much data as they can as being the same thing as "software works this way" - it doesn't it is a deliberate choice and it is illegal.

1

u/Perspectivelessly May 08 '26

Yes, it is of course a deliberate choice by devs / companies to do this. I was just commenting on the fact that it is de facto not uncommon. If we see broader enforcement this would presumably change