Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

EU Court Rules Adding Facebook 'Like' Button Triggers GDPR Data Collection Obligation

By Caroline Spiezio
August 01, 2019

Websites with embedded Facebook “like” buttons must inform users their data will be collected and processed by the social media giant, the Court of Justice of the European Union ruled on July 29.

Many sites — including German online clothing retailer Fashion ID, the focus of the ruling — use Facebook's embedded “like” button as a tool to promote their business, allowing users to easily share site reviews or items for sale on social media.

But the button also sends users' personal data to Facebook “without that visitor being aware of it,” the court said. Data was allegedly collected and transmitted from site users who did not use Facebook or click the “like” button.

The court said Fashion ID and other sites “can be considered to be a controller jointly with Facebook Ireland” over the initial data collected from users on their site sent to Facebook because both parties determine “jointly the means and purposes” of that data collection.

Data controllers violating the EU's General Data Protection Regulation could face fines up to 20 million euros or 4% of annual global turnover, “whichever is greater.” Sites are not liable for what Facebook does with the data after it is consensually collected from their users.

To comply with GDPR, sites with a “like” button embed must now provide “at the time of [users' personal data] collection, certain information to those visitors such as, for example, its identity and the purposes of the processing.”

The processing and transmission of personal data through Facebook embeds “can be considered lawful” if sites prove legitimate interest or obtain user consent, which under GDPR must be “freely given, specific, informed and unambiguous.”

Sites that don't feature Facebook's “like” button could still be impacted by the decision, which may apply to plugins leading to other social media sites, such as Twitter or Pinterest.

But of all the U.S.-based social media platforms, Facebook's business has drawn the most ire from European regulators. The company is currently under investigation from the Irish Data Protection Commission over potential GDPR violations and faces an antitrust probe from the European Commission.

In a statement, Facebook associate general counsel Jack Gilbert said website plugins, such as the “like” button, are “common and important features of the modern Internet.”

“We welcome the clarity that today's decision brings to both websites and providers of plugins and similar tools,” Gilbert said. “We are carefully reviewing the court's decision and will work closely with our partners to ensure they can continue to benefit from our social plugins and other business tools in full compliance with the law.”

Fashion ID did not immediately respond to request for comment.

*****

Caroline Spiezio covers the intersection of tech and law for Corporate Counsel, an ALM sibling of Cybersecurity Law & Strategy. She's based in San Francisco. Find her on Twitter @CarolineSpiezio.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Strategy vs. Tactics: Two Sides of a Difficult Coin Image

With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.

'Huguenot LLC v. Megalith Capital Group Fund I, L.P.': A Tutorial On Contract Liability for Real Estate Purchasers Image

In June 2024, the First Department decided Huguenot LLC v. Megalith Capital Group Fund I, L.P., which resolved a question of liability for a group of condominium apartment buyers and in so doing, touched on a wide range of issues about how contracts can obligate purchasers of real property.

CoStar Wins Injunction for Breach-of-Contract Damages In CRE Database Access Lawsuit Image

Latham & Watkins helped the largest U.S. commercial real estate research company prevail in a breach-of-contract dispute in District of Columbia federal court.

The Article 8 Opt In Image

The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.

Fresh Filings Image

Notable recent court filings in entertainment law.