Skip to content

menu

Open Legal Blog Archive logo
HomeAboutBlogsFAQsSubmit

Facebook Not “Liked” in Europe, Overhauls Its Privacy Settings

By Karin Retzer on November 29, 2011

Facebook’s “Like” button has been creating problems for Facebook in Europe. Thilo Weichert, the data protection commissioner for the German federal state of Schleswig-Holstein, has told all website owners based in the state to stop using web analytics associated with Facebook, including its “Like” button. “Facebook builds a broad individual and for members even a personal profile. Such a profiling infringes German and European data protection law. There is no sufficient [informing] of users and there is no choice,” reads the August 19, 2011 press release from the Schleswig-Holstein Commissioner. Website owners had until the end of September 2011 to discontinue the use of such analytics.

According to both the German Federal Data Protection Act and the Telemedia Act (German language version here), an individual must give his or her prior informed and explicit opt-in consent to the collection and transfer – including online transfers – of his or her data. In addition, individuals must be explicitly informed about their right to withdraw such consent at any point in time.

In November 2009, the Düsseldorfer Kreis, the consortium of German federal data protection authorities, published an Opinion stating that the use of web analytics is only legal where either prior opt-in consent has been obtained or IP addresses have been truncated. A number of EU Member States have also interpreted the recently amended European ePrivacy Directive as requiring informed and explicit (opt-in) user consent prior to the use of web analytics. But to date, Germany has not made any changes to its national legislation, because of existing provisions in the German Telemedia Act.

Commissioner Weichert is also conducting a wider investigation into Facebook’s privacy practices, citing the transfer of user data to the U.S. and the building of profiles without users’ consent or knowledge as infringing data protection laws. The action is a sideways swipe at the social networking service, aimed not directly at Facebook, but at other website owners.  Weichert has warned that those website owners cannot “shift their responsibility for data privacy upon the enterprise Facebook . . . and also not upon the users.”  Weichert also has expressed concern that Facebook’s offerings are “paid with the data of the users,” sometimes provided unwittingly via other websites. (He has also stated that Facebook fails to meet requirements for providing clear information to users in either privacy notices or its general terms and conditions.)

According to Commissioner Weichert’s recent November 5 press release, enforcement proceedings have been initiated against several undisclosed private and public sector operators for failure to remove and disable their Facebook fan pages, which allow users to show support for a service or product. The Commissioner stated that Facebook ought to amend its consent mechanism and also ensure that no data, including tracking data, are collected from nonmembers. The Commissioner also asked website operators to remove the “Like” button from their websites, according to the statement.

The press release stated that in August of this year, Commissioner Weichert had addressed fifteen organizations, including seven public sector and eight private sector entities, asking them to disable their Facebook fan pages and remove the “Like” button, and that so far, only three public sector and three private sector entities have responded to such request in writing and only a single entity – a public sector entity – has complied with the request. Weichert stated that the entities that failed to respond committed a “statutory violation,” because they have an obligation under German data protection law to provide information to the Commissioner when asked to do so. As a result, the Commissioner has issued injunctions against three private companies and threatened them with €5,000 fines if they do not respond and comply with the request.

Under German law, these private sector entities have one month from their receipt of the injunction to object, and can initiate court proceedings to challenge the injunction. Failure to comply may result in a fee of €5,000.  The Commissioner also initiated proceedings against the non-compliant public sector organizations, including ministries of the state of Schleswig-Holstein. And ultimately, website owners could face administrative proceedings and fines of up to €50,000 under Germany’s Telemedia Act.

Edgar Wagner, data protection commissioner for the German federal state of Rhineland-Pfalz, published a statement supporting Weichert and encouraging Facebook and websites to conform to data protection requirements.  Wagner pointed to other privacy issues, including that Facebook “undermines the statutory protection of minors.”

Facebook is also being scrutinized elsewhere in Germany:  Hamburg data protection commissioner Johannes Caspar has called on Facebook to “delete the stored biometric data of users it collects from its facial recognition software,” which the social networking site has been rolling out in an update of its Tag Suggestions feature. When a user uploads a photograph to his or her profile, the new feature uses facial recognition software to suggest names of people in the photo who can be “tagged,” which causes the photo to be accompanied by a link to the tagged person’s Facebook profile. The suggestions are based on other photos in which those individuals have been tagged. Part of the problem for the Hamburg data protection commission seems to be that the Tag Suggestions feature is enabled by default.  The Article 29 Working Party – Europe’s consortium of data protection authorities – is also examining the legality of this feature.

Meanwhile, Europe v. Facebook, an Austrian lobbying group founded by law student Max Schrems, has filed over 20 complaints against Facebook Ireland Ltd., the social networking site’s European headquarters, for a variety of issues including transparency, retention of user data, profiling, and the aforementioned Tag Suggestions feature. The office of the Irish Data Protection Commissioner has confirmed that it will conduct a “comprehensive audit” of Facebook’s Ireland operations amidst these complaints. Part of the audit will involve visits to Facebook’s Dublin offices, which a spokeswoman for the Data Protection Commissioner said will “take a number of days.” Officials expect to be finished with the audit by the end of 2011. “Facebook is cooperating fully with the audit and we would anticipate that it will implement any necessary changes to comply with any requirements identified,” she said.

It is worth nothing that Facebook has recently overhauled its privacy settings. In a proactive move, the leading social networking site has updated its privacy settings and controls in an effort to make them easier for users to understand and to give users more control. The new functions include an option for users to view their profiles as their Facebook friends or other users would see them.  Facebook users also now have more control over the “Tag” function:  they can accept or reject being Tagged by Facebook friends in photos or videos, and can even hold all Tags for approval.  On the other hand, the Tag function has been expanded so that a user can be Tagged by any other Facebook user – not just the user’s Facebook friends.

  • Posted in:
    Employment & Labor, Intellectual Property, Privacy & Data Security
  • Blog:
    Socially Aware Blog
  • Organization:
    Morrison & Foerster LLP
  • Article: View Original Source

Open Legal Blog Archive, Inc. logo
Seattle, Washington
Copyright © 2026, Open Legal Blog Archive, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo