On June 6, 2024, the activist group NOYB filed 11 complaints against Meta with various EU data protection authorities. These complaints were in response to Meta’s recent privacy policy changes regarding the use of users’ data to train AI.

Changes in Meta’s privacy policy that prompted the complaints

In early June, Meta informed European users that changes to their privacy policy would take effect on June 26, 2024. These changes outlined Meta’s plan to use images, posts, online tracking data, and third-party information to train AI models. Instead of seeking user consent, Meta claimed a legitimate interest in using this data to develop its generative AI models. Users could object to this processing by filling out an objection form and providing a reason for opting out.

NYOB’s complaints

NOYB filed 11 complaints against Meta with several European data protection authorities due to its privacy policy changes. NOYB requested an urgency procedure under Article 66 of the General Data Protection Regulation (GDPR). This procedure allows DPAs to issue preliminary halts and the European Data Protection Board (EDPB) to make an EU-wide decision. NOYB’s complaints listed violations of at least 13 Articles of the GDPR.

Who should care about NYOB’s complaints against Meta?

  • Users of Meta in the EU. Meta’s privacy policy change is relevant for users as their user data may be utilised and processed to train Meta’s AI. Users should be aware of changes in organisation’s privacy policies that may affect their rights.
  • Developers of AI models. The complaints can set a precedent for how these models must be designed and trained to comply with data protection regulations.

The outcome of the complaints

Following the complaints against Meta, several data protection authorities announced that Meta had agreed to pause the project in the EU. Meta confirmed that it would not process EU user data for its artificial intelligence systems. On 14 June 2024, data protection authorities from the UK, Ireland and Norway released statements that Meta had agreed to review its plans to use Facebook and Instagram user data to train generative AI.

Generative AI’s potential to process personal data creates many privacy concerns. There are real risks of breaching privacy regulations and jeopardising data when it’s used to train generative AI models like Meta’s. Individuals using platforms like Meta must continue to remain informed on their data privacy rights.

Actions to take next

  • Understand your rights as a user of Meta’s platforms by joining our Trustworthy AI Programme and working through the module on Managing the data protection risks of AI projects.
  • Improve your understanding of the complaints against Meta by reading their privacy policy.
  • Stay updated on privacy matters by subscribing to our newsletter, where we speak about AI and data protection.