Facebook Ireland has violated the law when processing personal data of Dutch Facebook users in the period from April 1, 2010 to January 1, 2020. The court of Amsterdam ruled on March 15, 2023. Personal data of users were processed for advertising purposes, while this was not allowed in this case . Personal data was also given to third parties without Facebook users being properly informed about this and without there being a basis for this in legislation and regulations.
The Data Privacy Foundation, a collective action organization, had brought the case against three companies from the Facebook group. The court limited the conviction to the actions of Facebook Ireland, because it alone is responsible for the processing of personal data of Dutch Facebook users.
No legal basis and not properly informed
Facebook Ireland processed personal data for advertising purposes without a legal basis – such as consent – for this. This legal basis was also lacking for the processing of special personal data for advertising purposes, such as sexual preference or religion. This concerned both personal data provided by users themselves and special personal data obtained by Facebook Ireland by following the surfing behavior of Facebook users outside the Facebook service.
Furthermore, Facebook Ireland has not adequately informed Facebook users about the sharing of their personal data with a number of third parties. Not only personal data of the Facebook users themselves has been shared, but also personal data of their Facebook friends.
“Cookies” on third-party sites are lawful
The court ruled that placing “cookies” on third-party websites was not unlawful. Facebook Ireland transferred the obligation to inform users about the placement of cookies and to request permission to the relevant website operator, which was allowed according to the court.
See more at rechtspraak.nl