Skip to content
Annuaire
Sections
Communication

The administrator of a Facebook "Fan" page is jointly responsible for the processing

The administrator of a Facebook "Fan" page is jointly responsible for the processing
L’essentiel

The Court of Justice of the European Union has ruled that administrators of Facebook Fan pages are joint controllers regarding data processing obligations.

À retenir

The Court of Justice of the European Union has ruled that administrators of Facebook Fan pages are joint controllers regarding data processing obligations.

The Court of Justice of the European Union has just ruled that an administrator of a “Fan” page on the social network Facebook is jointly responsible for the processing[1]. The administrator is therefore subject to a set of obligations.

Let us recall that a fan page is a user account configurable on Facebook by any type of user. Anyone with a Facebook account can create a fan page to present a service offering or a product to other users.

In this case, a German company offered training courses on a “Fan” page hosted on Facebook. It was forced to deactivate its Facebook fan page by the local data protection authority on the grounds that the company had not informed visitors that their personal data were being collected via cookies.

For the Court of Justice, the Facebook platform collects the personal data of visitors via storage files that remain active for two years unless they are expressly deleted before.

These data, processed by Facebook, are used to fuel the audience statistics database (Facebook Insights). All these statistics allow for the determination of an audience based on gender, age, location, relationship status and interests; an audience that will refine targeted advertising.

According to the Court, “this setting action (…) influences the processing of personal data for the purpose of establishing statistics based on visits to the fan page”.

Thus, the administrator “contributes to the processing of the personal data of the visitors to its page”, even if the audience statistics are anonymized. There is prior collection and the data processing is carried out through the installation of cookies.

The administrator, therefore, has the obligation to protect the personal data of its subscribers.

The CJEU has thus ruled on the role of the page administrator with regard to the provisions of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

Recall that according to the provisions of Article 2(d) of Directive 95/46, a data controller is: “the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by national or Community laws or regulations, the controller or the specific criteria for his nomination may be provided for by national or Community law“.

In reality, the CJEU considers that the company in question must be qualified as a joint controller from the moment the “fan” page administrator can obtain statistics from visits to a page, that the creation of this type of page allows Facebook to place cookies on the computer or smartphone and that the configuration allows for defining a targeted audience.

Thus, the administrator indirectly participates in the collection of data and can be qualified as a joint controller even if it only uses the means provided by Facebook.

Note that Article 4(7) of the GDPR[2] takes up the definition of the data controller given by Directive 95/46[3]. This solution has been transposable to the state of the law since 25 May 2018.

Concretely, what will happen for page administrators?

If we refer to this judgment, we can understand that administrators must now inform visitors to their page that personal data may be collected and processed and specify the purpose of this collection.

This information should be mentioned on the “fan” page.

It remains to be determined what the responsibility of each actor in the collection will be.

A parallel should also be made with the Facebook social “like” module inserted on each page, allowing a transmission of personal data from a website user’s computer to the external provider (Fashion ID case, C-40/17). Will we be able to qualify this company as a “data controller” nonetheless?

We will soon know what to expect.

[1] CJEU Grand Chamber 5 June 2018, Wirtschaftsakademie Schleswig-Holstein GmbH.

[2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

[3] Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi

Free, no spam, one-click unsubscribe.