Social Media
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Social networking platforms and privacy considerations
Overview
16 sources · Jul 23, 2026Legal Framework
Social media platforms implicate multiple layers of EU data protection law. The primary governing instruments include Article 5(3) of Directive 2002/58 (ePrivacy Directive) governing access to terminal equipment, the GDPR's controller responsibility provisions, and the AI Act's treatment of biometric categorisation features embedded in social networks. Under the AI Act, certain biometric filters used on social platforms fall outside the scope of biometric categorisation rules when they function as ancillary features:
"Filters used on online social network services which categorise facial or body features to allow users to add or modify pictures or videos could also be considered to be ancillary feature as such filter cannot be used without the principal service of the social network services consisting in the sharing of content online."
— AI Act Recital 16
The rationale is that such filters cannot operate independently of the platform's core sharing function, and their integration does not circumvent the Regulation's safeguards. However, this ancillary exemption is narrow — it hinges on objective technical dependence on the principal service.
Key Developments
The CJEU's Wirtschaftsakademie ruling established a foundational principle: operators of Facebook fan pages are joint controllers alongside Facebook Ireland. The Court held that by defining audience parameters and promotional objectives, the page administrator participates in determining the purposes and means of processing visitors' personal data. Crucially, joint controller status attaches even where the administrator never directly accesses the personal data:
"Directive 95/46 does not, where several operators are jointly responsible for the same processing, require each of them to have access to the personal data concerned."
— Wirtschaftsakademie, ¶38
The Court was unambiguous that commercial benefit from the platform does not exempt an administrator from compliance obligations. In Fashion ID, the CJEU extended this analysis to social plugins, confirming that the question of whether a plugin provider gains access to information stored on a visitor's terminal equipment under Article 5(3) of the ePrivacy Directive is determinative of the lawfulness analysis. The Schrems II decision invalidated Privacy Shield, fundamentally reshaping how social media platforms transfer EU user data to third countries — particularly the United States — by requiring case-by-case assessment of whether third-country surveillance laws undermine adequate safeguards.
Status of the Debate
This topic is actively contested in court. The boundaries of joint controllerhip on social platforms remain in flux: Wirtschaftsakademie and Fashion ID established broad responsibility principles, but subsequent cases have tested where that responsibility ends. The ancillary biometric categorisation exemption under the AI Act is newly introduced and untested in litigation — no court has yet interpreted the "objective technical reasons" threshold for social media filters. Additionally, post-Schrems II transfer mechanisms for social media data remain subject to ongoing challenge, as the EU-US Data Privacy Framework faces its own anticipated legal test. What would resolve the open questions: a CJEU reference on the outer limits of joint controller status for passive social media presence, and a ruling interpreting the AI Act's ancillary feature exemption in the context of platform-integrated biometric tools.
Practical Guidance
- Conduct a joint controller assessment for any social media presence your organisation operates. Under Wirtschaftsakademie, defining audience parameters or promotional objectives on a platform like Facebook makes you a joint controller — document this determination and execute a joint controller arrangement under Article 26 GDPR.
- Audit social plugins (e.g., "Like" buttons, share widgets) for compliance with Article 5(3) of the ePrivacy Directive. Fashion ID confirms that plugin providers' access to terminal equipment data triggers consent requirements — ensure lawful basis and transparency notices cover this.
- Map third-country transfer routes for all data flows involving social media platforms. Post-Schrems II, verify that Standard Contractual Clauses are supplemented by transfer impact assessments addressing surveillance laws in the recipient country.
- Evaluate biometric filters against the AI Act's ancillary feature test. If a filter cannot function without the platform's core sharing service and is not designed to circumvent the Regulation, document the technical rationale supporting the exemption.
- Do not assume anonymity of analytics absolves responsibility. Wirtschaftsakademie confirms that even where platform-provided statistics are anonymised, the underlying collection and processing of visitors' personal data remains subject to joint controller obligations.