Meta’s three main platforms – Facebook, Instagram, and WhatsApp – are under fire for potentially infringing data privacy under GDPR.
The European Data Protection Board (EDPB) has adopted three binding decisions addressing the legality of Meta’s platforms in Ireland under GDPR.
Draft decisions of Ireland’s Data Protection Commission (DPC) were passed onto the EU committee after it was decided further deliberation is required.
EDPB decisions will be binding on Ireland’s DPC, which will now have to reach its final decision in the next month. The EDPB will not publish their own decision until after the DPC reaches their conclusion.
The crux of the issue comes down to the way Meta functions – the company offers ‘forced consent’ to data sharing and use for personalisation.
The idea of ‘forced consent’ may be incompatible with GDPR regulations, which require companies to enable users to opt out of unessential cookies, data usage, and ad personalisation.
Meta’s terms of service, however, function off of this principle and it comes down again to a question of how GDPR is meant to function.
Can companies require users to consent to data sharing and use it for advertisement as part of their business models, or must they provide customers the option to opt out?
Meta has historically argued that their very business relies on the personalisation of their ads and the use of personal data to generate an individual’s experience.
However, when thinking of the functionality of Meta’s platforms, which are social platforms in the case of Facebook and Instagram, or a communications platform in the case of Whatsapp, what is essential to the functionality of the service consumers are using the platforms for?
Meta has their personalisation of ads moved into their terms of service and does not have a yes or no option as is legislated under GDPR rules.
In the UK, the company has come under fire for continuing to use user data to personalise ads even after these functionalities have been disbled by users.
In a high court lawsuit, Facebook is being sued for continuing to track and use a consumer’s data to personalise ads, even retaining sensitive information for the sake of advertising.
The EU’s decision has not been published, but The Wall Street Journal has found that Meta’s terms of service clause is not compatible with GDPR.
WhatsApp has already been found in failure of its transparency obligations to users in terms of how their data is used with other Meta platforms by the EUDP.
While we wait for the EU to publish its decision, if it does find Meta to be in breach of GDPR, it could spell disaster for the company’s business model which relies on personalisation of ads for much of its revenue, as well as collecting user data to share with third parties.
The social media conglomerate is a recognised monopoly, and this may explain why it has so far gotten away with dodging regulations of GDPR.
Recommended
- Apple reveals new security features
- Is time running out for Scotland to become a global tech force?
- Digital disparity: Glasgow sees widest broadband gap in UK
If users are able to opt out of this function, Meta will have to find new ways to effectively monetise their platforms in the EU.
The upcoming decision could also greatly influence how stringent the UK’s own data policies will be as it continues to draft its own legislation as it departs from EU regulations.
Currently, the Bill, which is yet to be introduced to parliament, says that it would allow customer data to be shared for personalised “market comparisons and account management.” It is yet unclear if this would include advertisements.
If the EU takes the massive step in forcing Meta to fundamentally change their data use and personalisation, then other regulatory bodies may feel empowered to do the same.
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





