- 24/04/2018
- Category: Commentaries
INTRODUCTION
For most internet users, it may no longer be a secret that social media corporations collect data from its users’ social media usage for a number of purposes, also known as big data. One social media corporation that does this is the world-renowned Facebook, Inc., who not only owns Facebook and Messenger but also Instagram and WhatsApp—and all four platforms are widely used on a global scale.[i]
Recent events in the EU have generated a question on whether Facebook, Inc.’s default settings are privacy-friendly to its users and in accordance with the EU’s data privacy regulations. Facebook, Inc. was accused of violating German, Belgium, French, Dutch and Spanish laws. Their privacy settings and the EU’s response will be discussed further in this two-part article.
Q1. How does Facebook, Inc. currently regulate the data privacy of their users?
When we use any of the services owned by Facebook, Inc., the types of information collected are:[ii]
- User activity (e.g., the frequency and duration of activities),
- Content information (e.g., the date and location of when a photo or a file was created),
- User network (e.g., an address book that has been uploaded),
- Network activity (e.g., when information about you is shared by another user),
- Payment information (e.g., credit/debit card numbers and shipping details),
- Device information (e.g., the devices where Facebook, Inc. services are installed or accessed, as well as its attributes such as operating system, GPS location, time zone, IP address, mobile operator and mobile number),
- Information from third-party partners (e.g., apps and websites that use Facebook, Inc. services) and
- Information from other Facebook, Inc. companies (e.g., WhatsApp).
These collected data is then used to “provide, improve and develop services,” communicate with users, measure advertising services to show relevant and personalized advertisements and “promote safety and security.” Facebook, Inc. states how cookies and similar technologies are used to obtain and utilize these data. Facebook, Inc. also claims that only non-identifiable information are shared to third-party services.[iii] Users can choose not to have their data mined into personalized advertisements. However, they will still see advertisement while using any of Facebook, Inc.’s services.[iv] Users can also manage or delete their information in their profile settings. User information is stored for “as long as it is necessary to provide products and services to you and others” until the profile is deleted (not deactivated) or Facebook, Inc. no longer needs the data. However, information about us that other users have shared will not be deleted if we delete our account.
There are several exceptions regardingdata privacy Facebook, Inc. policy for storing or accessing identifiable data: (1) if there was a legal request (such as a subpoena); (2) if the account is suspected of violating Facebook, Inc.’s terms or policies; (3) if the account is suspected to be involved in illegal activity; (4) or to “prevent death or imminent bodily harm”.[v] In such cases, personal information may be retained for an extended period of time. For accounts that have been disabled for violating the terms or policies, the information may be retained for at least one year to prevent the violation being repeated.
Facebook, Inc. claims to “utilize standard contract clauses approved by the European Commission, adopt other means under European Union law, and obtain your consent to legitimize data transfers from the EEA to the United States and other countries,” yet the last date of revision for their data policy is 29 September 2016.[vi]
Q2. How has Facebook, Inc. breached The EU’s data privacy regulations?
In Germany, Facebook, Inc. violated German consumer law by collecting and using personal data without providing sufficient information of its privacy settings during account registration, thus making this collection and usage of user data invalid. Ruled by the Berlin Regional Court, the lawsuit was brought by the Federation of German Consumer Organization, Der Verbraucherzentrale Bundesverband (VZBV), on 16 January 2018.[vii]
Facebook, Inc. has been in conflict with VZBV since 2015. VZBV argued that Facebook, Inc. infringe user privacy in numerous ways, such as through automated activation of location services during registration[viii] and its ‘real name policy’ which doesn’t allow users to register on Facebook with pseudonyms.[ix] VZBV also argued that Facebook transfers users’ data from European users to the United States for commercial purposes, merging user data to third-party applications,[x] and being anti-competition by monopolizing the digital advertising domain.[xi] [xii]
In Belgium, the battle of unlawful user data collection between Facebook, Inc. and Belgium Commission for the Protection of Privacy (CPP) has also been ongoing since 2015.[xiii] On 16 May 2017, Belgium ordered Facebook, Inc. to delete all data from Belgian citizens that have been gathered illegally. CPP stated Facebook, Inc. gathers data from online users—including individuals without Facebook accounts—using special cookies, invisible pixels and social plug-ins on third party websites.[xiv] Facebook, Inc. also didn’t comply with the Belgian law that dictates digital terms—such as ‘cookie’ and ‘browser’—must be translated to Dutch, French or German. At this stage, ‘browser’ translates to ‘webbrowser’ in Dutch, and ‘browser’ to ‘navigateur’ in French—whereas ‘cookie’ translates to ‘cookie’ in all three languages. These translations may not be clear enough to users who are not literate in computing terms.[xv]
In France, Facebook, Inc. has been reprimanded for sharing data between WhatsApp and Facebook, its parent company, for ‘business intelligence’ purposes—which is “targeted advertising, security and the evaluation and improvement of services.” The French Data Protection Agency, Commission Nationale de l’Informatique et des Libertés (CNIL), ordered WhatsApp to stop sharing personal data to Facebook on 18 December 2017. Again, consent is deemed invalid, as during account registration users must agree to their data being used by the parent company.[xvi] [xvii]
In the Netherlands, the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, deemed Facebook, Inc. to violate data privacy laws by providing insufficient information about user data usage on 16 May 2017, such as using sensitive information such as sexual preferences as targeted advertising.[xviii] The Spanish Agency for Data Protection, Agencia Española de Protección de Datos (AEPD), sanctioned Facebook, Inc. for the same data privacy violation on 11 September 2017.[xix] [xx]
Editors: Atin Prabandari MA(IR), Diah Ratna Pratiwi, M.Dev & Nabeel Khawarizmy Muna, S.IP
Picture: Unsplash
[i] Kottasova, I. (2014). Zuckerberg goes shopping: Facebook’s top 10 purchases. [online]. CNN. Available at: https://edition.cnn.com/2014/03/26/business/facebook-acquisitions/index.html [Accessed at: 5 Mar. 2018].
[ii] Facebook, Inc. (2016). Data policy. [online]. Facebook. Available at: https://www.facebook.com/about/privacy/ [Accessed at: 12 Mar. 2018
[iii] Facebook, Inc. (2016). Data policy. [online]. Facebook. Available at: https://www.facebook.com/about/privacy/ [Accessed at: 12 Mar. 2018].
[iv] Facebook, Inc. (2018). How does Facebook decide which ads to show me and how can I control the ads I see? [online]. Facebook. Available at: https://www.facebook.com/help/562973647153813/ [Accessed at: 12 Mar. 2018].
[v] Facebook, Inc. (2016). Data policy.
[vi] Ibid.
[vii] Der Verbraucherzentrale Bundesverbands. (2018). Facebook verstößt gegen deutsches Datenschutzrecht. [online]. VZBV. Available at: https://www.vzbv.de/pressemitteilung/facebook-verstoesst-gegen-deutsches-datenschutzrecht [Accessed at: 5 Mar. 2018].
[viii] Murphy, M. (2018). German court finds Facebook’s data collection was illegal. [online]. The Telegraph UK. Available at: https://www.telegraph.co.uk/technology/2018/02/12/german-court-says-facebook-data-collection-illegal/ [Accessed at: 5 Mar. 2018].
[ix] Kastrenakes, K. (2018). German court says Facebook’s real name policy is illegal. [online]. The Verge. Available at:https://www.theverge.com/2018/2/12/17005746/facebook-real-name-policy-illegal-german-court-rules [Accessed at: 5 Mar. 2018].
[x] Oltermann, P and Gibbs, S. (2017). Facebook use of third-party apps ‘violates data protection principles’. [online]. The Guardian. Available at:https://www.theguardian.com/technology/2017/dec/19/facebook-use-of-third-party-apps-violates-data-protection-principles [Accessed at: 5 Mar. 2018].
[xi] Gibbs, S. (2016). Facebook facing German cartel probe over suspected data protection abuses. [online]. The Guardian. Available at: https://www.theguardian.com/technology/2016/mar/02/facebook-german-cartel-probe-suspected-data-protection-abuses [Accessed at: 5 Mar. 2018].
[xii] Chazan, G. (2018). Germany threatens curbs on Facebook’s data use. [online]. Financial Times. Available at: https://www.ft.com/content/9376eece-00e4-11e8-9650-9c0ad2d7c5b5 [Accessed at: 5 Mar. 2018].
[xiii] Gibbs, S. (2018). Facebook ordered to stop collecting user data by Belgian court. [online]. The Guardian. Available at: https://www.theguardian.com/technology/2018/feb/16/facebook-ordered-stop-collecting-user-data-fines-belgian-court [Accessed at: 5 Mar. 2018].
[xiv] Belgian Commission for the Protection of Privacy. (2017). The Belgian Privacy Commission publishes new recommendation relating to the processing of personal data by Facebook through cookies, social plug-ins and pixels. [online]. Belgian CPP. Available at: https://www.privacycommission.be/en/news/belgian-privacy-commission-publishes-new-recommendation-relating-processing-personal-data [Accessed at: 5 Mar. 2018].
[xv] Gibbs, S. (2016). Facebook disputes Belgian tracking order over use of English in court ruling. [online]. The Guardian. Available at: https://www.theguardian.com/technology/2016/jan/29/facebook-belgian-tracking-english-court-ruling-cookie-browser [Accessed at: 5 Mar. 2018].
[xvi] Commission Nationale de l’Informatique et des Libertés. (2017). Transmission de données de WHATSAPP à FACEBOOK : mise en demeure publique pour absence de base légale. [online]. CNIL. Available at: https://www.cnil.fr/fr/transmission-de-donnees-de-whatsapp-facebook-mise-en-demeure-publique-pour-absence-de-base-legale [Accessed at: 5 Mar. 2018].
[xvii] Gibbs, S. (2016). France orders WhatsApp to stop sharing user data with Facebook without consent. [online]. The Guardian. Available at: https://www.theguardian.com/technology/2017/dec/19/france-orders-whatsapp-stop-sharing-user-data-facebook-without-consent [Accessed at: 5 Mar. 2018].
[xviii] Autoriteit Persoonsgegevens. (2017). Dutch data protection authority: Facebook violates privacy law. [online]. DPA. Available at: https://autoriteitpersoonsgegevens.nl/en/news/dutch-data-protection-authority-facebook-violates-privacy-law [Accessed at: 5 Mar. 2018].
[xix] Agencia Española de Protección de Datos. (2017). La AEPD sanciona a Facebook por vulnerar la normativa de protección de datos. [online]. AEPD. Available at: http://www.agpd.es/portalwebAGPD/revista_prensa/revista_prensa/2017/notas_prensa/news/2017_09_11-ides-idphp.php [Accessed at: 5 Mar. 2018].
[xx] McGoogan, C. (2017). Facebook hit with €1.2m fine in Spain for breaking privacy laws. [online]. The Telegraph UK. Available at: https://www.telegraph.co.uk/technology/2017/09/11/facebook-hit-12m-fine-spain-breaking-privacy-laws/ [Accessed at: 5 Mar. 2018].