MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Yes. If, as an entrepreneur, you manage a business Facebook page or place social plug-ins (such as the 'Like' button) on your website, in most cases you are jointly responsible with the platform under the GDPR. This means that you must inform visitors in advance, request valid consent where necessary, and document the division of roles with the platform. The European Court of Justice confirmed this in two important rulings. In this article, you will read what this shared responsibility concretely entails, what risks you face, and what steps you can take now.
What does data processing responsibility mean on social media?
a data controller is the person who determines the purpose and means of data processing. With social media, the situation is more nuanced than many entrepreneurs think. As soon as you manage a business Facebook page or place a social plug-in on your site, you generally bear co-responsibility for the personal data collected in the process. You are then not merely an innocent user of the platform.
The core: by consciously choosing the platform or button, you help enable data collection. In doing so, you determine part of the 'purpose and the means', and come within the scope of the GDPR.
Joint responsibility is not equal responsibility
Important to remember: joint controllership does not automatically mean that you and the platform bear exactly the same obligations or liability. Responsibility is generally limited to that part of the processing over which you actually have influence. Furthermore, under the GDPR, joint controllers must record their mutual tasks in a mutual agreement.
Your Facebook page: shared responsibility confirmed
In the case concerning a so-called fan page (Wirtschaftsakademie Schleswig-Holstein, ruling of 5 June 2018), the Court of Justice of the European Union had to determine whether the administrator of such a page is a controller, alongside the platform itself. Facebook places cookies to collect information about visitors to the page, regardless of whether they have an account. That information is subsequently made available to the page administrator via statistics functions (such as Facebook Insights), while visitors are not always informed of this.
The Court ruled that both the platform and the page administrator bear responsibility for processing. After all, by choosing the platform, you enable it to collect data via cookies. The fact that your page also attracts visitors who have no prior connection with the platform weighs in on this assessment.
Social plugins on your website: you are also jointly responsible
You are familiar with the 'like'button: the thumbs-up icon that visitors use to connect with your page from your website. It is a tricky thumbs-up, because even without anyone clicking on it, the visitor's IP address and browser data can already be transmitted to the platform.
In the Fashion ID (judgment of 29 July 2019), the Court of Justice ruled that a website operator who embeds such a social plug-in is a controller together with the platform. However, that responsibility is limited: it applies to the phase of collecting and transmitting the data via the button, over which the website operator actually has influence. In principle, you are not responsible for what the platform does with the data thereafter. The Court also emphasized that it does not matter that you, as an entrepreneur, do not have access to that data yourself.
In concrete terms, this means that you must inform visitors in advance and that any consent must have been given before the data is forwarded via the plug-in.
What are the consequences for you as an entrepreneur?
It follows from these rulings that administrators of business pages and websites with social plug-ins must also comply with the GDPR. In practice, this amounts to a number of recurring obligations:
- Inform: explain in a clear privacy statement which data is collected via your page and plugins and for what purpose.
- Consent: where necessary, request valid, prior consent, for example via a correct cookie banner, before data is transmitted.
- Document agreements: record the mutual division of roles with the platform and with other parties in writing.
- Document what you do: keep track of which processing activities take place, so that you can demonstrate that you take your obligations seriously.
Failure to comply can lead to complaints from visitors and to action by the supervisory authority, the Dutch Data Protection Authority. Reputational damage and enforcement are real risks, especially now that the subject of privacy is becoming increasingly visible.
What can you practically do now?
- Map out which social plugins and tracking scripts are on your website.
- Check whether your cookie banner only forwards data after consent, and not before.
- Update your privacy statement and cookie statement so that they describe the current situation.
- Record the agreements with your processors and collaboration partners in a data processing agreement.
- Keep track of your processing activities in a GDPR processing register.
Frequently Asked Questions
Am I responsible for the cookies that Facebook places on my page?
According to the Court of Justice, as the administrator of a business page, you bear co-processing responsibility for the data collected via that page. However, your responsibility is limited to the part over which you have influence; the supervisory authority looks at the factual situation.
Am I allowed to still place the 'like' button on my website?
That is allowed, but you must inform the visitor in advance and, where necessary, ask for permission before data is transmitted via the button. A commonly used solution is to load the plug-in only after the visitor has given permission.
What is the difference between a controller and a processor?
A controller determines the purpose and means of processing. A processor processes data exclusively on behalf of another. In the case of social plug-ins and business pages, this concerns joint responsibility for processing, not a processor relationship.
What documents do I need at a minimum to comply with the GDPR?
For most entrepreneurs, this involves a privacy statement, a cookie statement, and, where applicable, a data processing agreement and a processing register. Exactly which documents are required depends on your situation.
Does this also apply to platforms other than Facebook?
The principle extends beyond Facebook alone. You can also be a co-controller for business pages and plugins of other social media platforms that collect visitor data in a similar manner. The precise division of roles may vary per platform and per situation.
Can the Dutch Data Protection Authority take action against my company?
Yes. The Dutch Data Protection Authority monitors compliance with the GDPR and can take enforcement action. Demonstrably doing your best to meet your obligations significantly reduces that risk.
Time for action: have your GDPR position checked
Do you use social plug-ins or manage business pages and are unsure whether you comply with the GDPR? Then it is wise to have your situation assessed. View our expertise in privacy and data protection, or arrange the appropriate documents, such as a data processing agreement and a cookie declaration.
Do you want to know where you stand? Schedule a no-obligation intake and discuss your situation with one of our legal experts.