Facebook widgets on the website under scrutiny by the Austrian counterpart of the Polish Data Protection Authority

23 March 2023

There is no longer any doubt. If you use Facebook widgets on your website, you may find yourself under the scrutiny of the supervisory authority. Industry experts have long indicated that the use of plugins from American giants such as Facebook or Google may involve the transfer of personal data to the USA, which could consequently lead to proceedings initiated by European state institutions.

Within a month of the ruling by the Court of Justice of the European Union in the "Schrems II" case (CJEU - C-311/18 - Schrems II), the non-governmental organization "noyb" filed 101 complaints regarding the transfer of data by websites outside the EEA, namely to Google LLC and Facebook Inc. in the USA (see here and here).

To coordinate the work of all involved supervisory authorities, the EDPB established a special task force. The decision of the Austrian supervisory authority mentioned below was issued as a result of one of the complaints filed.

Transmission of information to Facebook (Meta Platforms Inc.) while visiting websites

On August 12, 2020, the data subject visited a website hosted on a server of an Austrian media company. This individual was simultaneously logged into their Facebook account. The Austrian company utilized the Facebook Login tool, which facilitates user access to services without the need to create additional accounts. The Austrian company also employed the Facebook Pixel tool, allowing it to track user activity on its website.

According to the aforementioned individual (represented by noyb), mere access to the website of the Austrian company resulted in the unlawful transfer of personal data to the USA, consequently violating Chapter V of the GDPR. In this regard, on August 18, 2020, a complaint was filed against the Austrian entity in question, indicating the use of tracking tools, the utilization of which violates Article 44 of the GDPR and subsequent provisions. Furthermore, the complainant alleged that Meta violated Articles 5(2), 28, and 29 of the GDPR.

The investigation conducted by the Austrian supervisory authority lasted several months. During the proceedings, the contested data controller claimed that it had deactivated the Facebook tools after the complaint was filed. Additionally, it argued that its direct contractor and the party to the agreement it entered into with Facebook is Meta Platforms Ireland Limited. Consequently, subsequent transfers, including transfers outside the EU, were beyond its scope of competence. The Austrian company also asserted that transfers outside the EEA were justified in light of specific principles applicable in Austria to media companies due to journalistic activities. Meta Platforms Inc. claimed that it was merely a subcontractor processing data on behalf of Meta Platforms Ireland Limited, and therefore the GDPR did not apply.

The complainant disagreed with the above positions, arguing that the deactivation of tools after the complaint was submitted is irrelevant, as the violation had already occurred. Furthermore, the complainant emphasized that the data controller could not invoke exceptions related to journalistic activities, considering the nature and circumstances of the data transfer. Finally, the complainant argued that Chapter V of the GDPR applies to all data transfers, regardless of the subjective qualification of the parties involved.

Austrian Supervisory Authority on the Actions of Meta Platforms Inc.

According to the Austrian supervisory authority, Meta Platforms Inc. did not violate Article 44 of the GDPR and subsequent provisions, as it was merely a data importer, and with such status, it was not burdened with obligations arising from Chapter V of the GDPR. In this transfer, Meta did not disclose data but only received it. Meta was also not liable under Article 5(2) of the GDPR, as this provision imposes obligations on the data controller, which Meta is not. The Austrian authority did not elaborate extensively on the qualification of Meta Platforms Inc. in light of the GDPR, merely acknowledging that there is insufficient evidence in this case to classify Meta as a data controller. As for Articles 28 and 29 of the GDPR, they pertain to the relationship between the data controller and the data processor, and therefore do not grant subjective rights to the data subjects (which would allow for the filing of a complaint).

Position of the Supervisory Authority Regarding the Austrian Company

However, the supervisory authority considered the complaint against the Austrian media company (the data controller). First and foremost, the mere fact that the company deactivated Facebook tools after the complaint was submitted was not sufficient to exclude a violation of Article 44 of the GDPR and subsequent provisions, as the violation had already occurred.

Moreover, the authority clarified the scope of the exception related to journalistic activities, as provided for in Austrian law (in accordance with Article 85 of the GDPR). In light of the CJEU ruling C-73/07, “personal data is processed for the purpose of carrying out journalistic activities if the processing is aimed solely at the public dissemination of information, opinions, or thoughts.” In this case, the Facebook tools available on the administrator's website were implemented for other purposes: tracking the user and facilitating the login procedure. Furthermore, after the data was transferred to Meta Ireland, it could have been used for further purposes. For this reason, the aforementioned exception clearly did not apply in this case.

When was the last time you conducted a risk assessment?

Furthermore, the Austrian supervisory authority examined whether there was an international data transfer within the meaning of Chapter V of the GDPR and whether this transfer was compliant with the regulations. In light of the ruling in the "Schrems II" case, Article 44 of the GDPR grants individuals a subjective right that can be enforced by filing a complaint under Article 77(1) of the GDPR. The data transferred to the USA via Facebook tools constituted personal data, as Meta Platforms Ireland Limited - the data processor - could link the data transmitted from the website with the data of the individual available through their Facebook account. The rulings of the CJEU indicate that it was not necessary for all information required to identify the person to be processed (see C-434/16 and C-582/14). The Austrian supervisory authority dismissed as irrelevant the argument that after the data was transferred to Meta, the data controller would no longer have control over further processing. The authority concluded that the data controller had consented, under Article 28(2), to the data processor (Meta Platforms Ireland Limited) further entrusting the data to a subcontractor based outside the EEA (Meta Platforms Inc.). As a result, an international data transfer did indeed occur.

Regarding compliance with data transfer regulations, the Austrian supervisory authority found no legal basis that would be in accordance with the GDPR. The EU Commission's adequacy decision regarding the transfer of data from the EU to the USA was invalidated by the "Schrems II" ruling. Consequently, the data importer and exporter could not invoke Article 45 of the GDPR. Furthermore, Meta implemented standard contractual clauses in accordance with Article 46 of the GDPR only after the disputed factual situation arose. This means that the data controller unlawfully transferred personal data to an entity based in the USA and consequently violated Chapter V of the GDPR.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.