Meta will be fined £344 million by the Irish Data Protection Commission for its use of ‘forced consent’ for personalised advertising.
The fine and decision comes after two lengthy legal battles that originated in 2018, after GDPR was first introduced to the EU.
Each case, one against Instagram and one against Facebook, dealt with the way Meta obtained a legal basis for using consumer data to generate personal advertisements.
Under GDPR, companies can get user permission to collect and use personal data for advertisements under a number of legal bases, and Meta used contractual consent.
The complainants in both cases alleged that the contractual consent, which required users to accept their personal data was being used for personalised or behavioural advertising, was actually ‘forced consent’, as users could not use the service without agreeing to these terms.
The new ruling, which was finalised by the DPC after guidance from the European Data Protection Board (EDPB), agreed with the original complainants.
Essentially, Meta can no longer use their terms of service contract to secure user consent for personalised advertising.
Facebook and Instagram will have to fundamentally change their terms of service and potentially their platform models to stay GDPR compliant.
Furthermore, Meta was fined for a lack of transparency in how they used personal data.
Tracking the Case
Originally the DPC had found that Meta’s business model would allow it to use contract consent as personalised and behavioural services central to the company’s offerings would include advertising.
This ruling, however, was not supported by the Concerned Supervisory Authority (CSA), a higher EU regulatory body which would supervise these draft decisions.
The CSA found that Meta could not rely on the contract legal basis, as personalised advertising was not part of the core services offered. The DPC maintained that advertising was part of the platforms’ services and could therefore be consented to in the terms of service.
After no conclusion could be reached, the EDPB took the case.
The landmark decision puts to rest the two major case filings, finding that Meta cannot use contract legal basis to gain consent for personalised advertising.
The company will be given three months to comply to GDPR regulations.
What this Means for Meta
Meta is planning on appealing the case, making a statement assuring users and stakeholders that this does not mean an end to personalised advertising.
Instead, Meta will likely face the same regulations as other businesses and online platforms, where users must click to opt in to non-essential services like personalised advertising.
This will level the playing field for other companies using personalised advertising, but will no doubt lead to major losses in Meta’s revenue – which relies heavily on ads.
The Future of Data Regulation
Regulators and data watchdogs have been waiting on this decision since 2018, when GDPR first came into effect.
The way Meta complies in the EU may greatly affect how other regulatory bodies, including in the UK, set up their data protection regulations.
The UK’s current draft legislation would “allow for the sharing of customer data, through smart data schemes, to provide services such as personalised market comparisons and account management.”
Essentially, this would allow use of consumer data for personalised advertisement, but is unclear on what consent would be required or what ‘smart data schemes’ would mean for businesses and consumers.
Recommended
- Free cyber assessments available for Scots businesses
- Cabinet Office launches consultation on Gov data sharing
- New advisory committee to boost Scotland’s space ambitions
Campaigner’s Reactions
Max Schrems, co-founder of NYOB European Centre for Digital Rights and privacy campaigner, fought hard for the win but had lambasted the DPC for its original protection of Meta’s non-compliance.
The Irish data regulator is responsible for many American-based company’s European outfits, largely due to its business-friendly tax model, and is therefore the first authority on any EU regulations concerning Meta.
“Getting overturned by the EDPB is a major blow to the DPC, now they seem to try to influence the public perception of this case,” he explained on the NYOB coverage of the case.
The DPC has been called upon by the EDPB to further investigate all of Facebook and Instagram data processing operations, but the DPC is calling this a major overstep by the EU-wide regulator.
The EDPB’s major decision is in direct dispute with the DPC’s original ruling about ‘forced consent,’ making the DPC seem rather lenient on the social media conglomerate.
As well, the fine is set to go directly to Ireland, the country that Schrems says has allowed Meta to bypass GDPR for far too long.
Schrems also called Meta’s non-compliance “not just unfair but clearly illegal”.
“We are not aware of any other company that has tried to ignore the GDPR in such an arrogant way,” Schrems added
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





