Privacy

Website administrator is responsible for the like button

Yes, as a website administrator, you are jointly responsible for the personal data collected and forwarded via a Facebook Like button. The European Court of Justice ruled in the Fashion ID case (July 29, 2019, case C-40/17) that you together...

Published on August 14, 2019 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Yes, as a website administrator, you are jointly responsible for the personal data collected and transmitted via a Facebook Like button. The European Court of Justice ruled in the Fashion ID case (July 29, 2019, case C-40/17) that you, together with Facebook, qualify as a joint controller for the collection and transmission of visitor data. If you place such a button, specific obligations rest upon you: you must inform visitors in advance and, in many cases, ask for their consent. If you fail to do so, you run a privacy risk under the GDPR.

What exactly does a like button do?

A Facebook Like button looks innocent, but technically speaking, it is a piece of code (a so-called social plugin) from Facebook. As soon as a visitor opens your page, the browser loads that code directly from Facebook. In doing so, data is already being exchanged—such as the IP address and information about the browser— even before the visitor clicks on anything.

Moreover, this happens regardless of whether the visitor has a Facebook account, is logged in, or has given consent. Data collection therefore starts when the page loads, not just at the click. It is precisely this automatic nature that makes the button legally sensitive.

Why are you jointly responsible as a website administrator?

The core lies in a free choice: you decide for yourself whether to place the button on your website. By doing so, you enable Facebook to receive visitor data. In doing so, you help determine why and how that data is collected and forwarded.

The European Court of Justice confirmed this in the Fashion IDjudgment (Case C-40/17, ruling of 29 July 2019). The key points of that ruling:

  • The website operator is jointly responsible with Facebook for the collection and transmission of the data.
  • That joint responsibility does not mean that both parties are equally responsible for everything. Your responsibility is limited to the part of the processing over which you actually have influence: the collection on your site and the transmission to Facebook.
  • What Facebook does with the data afterwards is beyond your responsibility – but that does not relieve you of your own obligations.

So you cannot hide behind “Facebook will take care of that”. For the part that happens on your website, it is up to you.

Obligation 1: be transparent

As a website administrator, you must clearly inform visitors about the collection, processing, and transfer of their personal data. The Court emphasized that you must provide this information at the moment the data is collected – and for a social plugin, that is the moment the page loads.

This transparency obligation applies only to the part of the processing for which you are responsible, not to subsequent processing by Facebook. In practice, this means that you clearly explain in your privacy and cookie statement which data is collected via the button and to whom it is forwarded.

Obligation 2: ask for permission in advance

In addition to informing, you must as a rule also ask the visitor for permission in advance. The Court refers again to your free choice to place the button: because you make that decision, the question of consent rests with you. As with the duty of transparency, that consent need only relate to the part you manage, not to Facebook's subsequent processing.

Important: consent must be free, specific, and informed, and preferably given before the button loads. A pre-checked box or a button that loads immediately is generally not sufficient.

The practical challenge: the button loads automatically

This is where the problem lies. The information and consent must be in place from the moment the data is collected, but a standard 'like' button loads automatically when the page is opened. So, you need to adjust the technology.

The common solution is to load the button only after the visitor has given permission. A widely used approach:

  1. First show a neutral placeholder or a consent button instead of the actual Facebook plugin.
  2. Only load the Facebook code once the visitor actively clicks on “agree” or “load button”.
  3. Specify in your cookie and privacy statement what happens in that case and which data is shared.

For a webshop with sufficient turnover, such a technical adjustment is perfectly manageable. For a small business owner or a hobbyist site, it can be a relatively large amount of work. Sometimes the fairest conclusion is then: weigh whether the button is worth the privacy risk and the effort.

What are the risks if you do nothing?

If you disregard these obligations, you are processing personal data without a valid legal basis. This is contrary to the GDPR. The consequences may include:

  • Complaints and enforcement by the Dutch Data Protection Authority, resulting in possible measures or fines.
  • Reputational damage when visitors or customers notice that their data is being shared without their consent.
  • Liability for the part of the processing that falls under your responsibility.

Incidentally, the same principle applies not only to the Facebook button. Other social plugins, embedded videos, share buttons, and third-party tracking pixels can collect data in the same way. The reasoning from the Fashion ID judgment is often correspondingly applicable to them.

Step-by-step plan: how to set up your website properly

  1. Inventory which third-party buttons, plugins, and pixels are on your site.
  2. Delay loading until after permission, or remove the button if it is not essential.
  3. Update your privacy and cookie statement so that it aligns with what actually happens.
  4. Document consent demonstrably, so that you can show that visitors have agreed in advance.
  5. Have it legally and technically screened if in doubt, so you know it is correct.

Unsure whether your statements are still up to date? A privacy audit quickly identifies where the risks lie and what you specifically need to adjust.

Frequently Asked Questions

May I still place a Facebook Like button on my website?

Yes, that is allowed, but under conditions. You must inform visitors in advance and, as a rule, ask for permission before the button sends visitor data to Facebook. In practice, you arrange this by only loading the button after the visitor has agreed.

Am I liable for what Facebook does with the data afterwards?

No. According to the Fashion ID ruling, your responsibility is limited to collecting the data on your website and transmitting it. What Facebook does with it afterwards falls outside your responsibility – but your own obligations to inform and ask for consent still apply.

Does this only apply to the Facebook button?

No. The same reasoning often applies to other social plugins, share buttons, embedded content, and third-party tracking pixels. Whenever an element from an external party automatically collects data from your visitors, it is wise to apply the approach from this ruling.

Is a cookie banner sufficient to comply with this obligation?

Not automatically. A cookie banner only works if it actually blocks the social plugin until the visitor gives consent, and if your statements align with what happens. A banner that asks for consent but allows the button to load immediately does not solve the problem.

What risks do I run if I don't arrange anything?

In that case, you are processing personal data without a valid legal basis, which is contrary to the GDPR. This can lead to complaints, enforcement by the Dutch Data Protection Authority, potential fines, and reputational damage. You can be held accountable for the part that falls under your responsibility.

Have your website legally screened

Do you want to be sure that your like button, cookie banner, and statements are GDPR-compliant? MKB Juristen screens your site and provides concrete recommendations to take to your web developer. We also draft your cookie statement and privacy statement so that they align with what actually happens on your website.

Want to know more about our approach to privacy and data protection? Or would you like to discuss it directly? Schedule a no-obligation intake and we will look together at where the risks lie and how to resolve them.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having general terms and conditions drafted for the website: costs and process

Having general terms and conditions for the website drafted by a lawyer: what does it cost, how does the process work, and when should you choose custom-made...

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation