Home Privacy Here’s How Facebook Is Getting Ready For GDPR

Here’s How Facebook Is Getting Ready For GDPR

SHARE:

With Europe’s General Data Protection Regulation taking effect May 25, Facebook must alter some of its business practices regardless of any fallout due to the Cambridge Analytica debacle.

The Cambridge Analytica revelations merely behoove Facebook to move faster and fix things in light of macro privacy changes hitting the EU.

The most recent example is a tool Facebook is developing for advertisers to prove they have consent before uploading email addresses through Custom Audiences. Facebook confirmed to TechCrunch that this is in the works.

Mark Zuckerberg told Reuters on Tuesday that Facebook isn’t planning to apply the changes it’s making specifically to comply with GDPR outside of its EU business. Although Facebook can plausibly accomplish this – users are logged in, which gives Facebook deterministic knowledge of who they are and where they’re located – privacy advocates have been pushing Facebook and other technology company to implement a consistent privacy policy across the geographic board.

GDPR’s scope extends to any company collecting or processing an EU citizen’s data.

Here’s how Facebook is laying the groundwork for GDPR compliance with less than two months to go until the deadline. [Click here to read about what Google’s cooking up in the GDPR lab.]

Controller or processor?

When Facebook has the first-party relationship, it is the controller, meaning it decides what, how and why the data is being collected. In those cases, Facebook also bears the responsibility to provide a transparent privacy notice and establish a legal basis for processing, such as consent.

Facebook is a controller for any data that EU users share about themselves on Facebook, any data generated when users interact with Facebook and the data Facebook gets when a site or an app uses Facebook’s pixel or integrates its software development kit.

What’s perhaps more relevant for advertisers, however, are the instances in which Facebook claims processor status, which include when working with brands that use Custom Audiences or Facebook’s measurement and analytics tools.

Much like a mar tech provider a la Salesforce or Marketo, Facebook leaves it to its clients to obtain consent for any data they upload to the system.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Custom Audiences

Using Custom Audiences, advertisers can match their email list against Facebook’s database to find and target their existing customers on the platform.

But Facebook has no easy way to guarantee that the data being uploaded to Custom Audiences was rightfully collected. If the Cambridge Analytica episode revealed anything, it was how little control Facebook has over data once it leaves its walled garden.

In order to guard against the opposite problem – unauthorized data being piped into its platform – Facebook reportedly is working on a certification tool to ensure advertisers only upload email addresses collected in the proper way.

GDPR makes it illegal for any business to use an EU citizen’s data without consent or some other legal basis.

Advertisers will also no longer be allowed to share Custom Audiences created on Facebook between business accounts. Under GDPR, controllers are required to get “unambiguous” consent for each purpose they plan to use the data for. Opting in to share an email address with one business doesn’t imply consent to be contacted by another.

It’s unclear how Facebook’s certification tool will work – and it doesn’t absolve Facebook of responsibility in the case of a breach or improper collection – but requiring advertisers to guarantee that user data was gathered with consent at least demonstrates to regulators that Facebook is making an effort on both sides of the Atlantic.

Measurement and analytics

Facebook is also a processor when it provides analytics on its platform, such as campaign measurement and reporting on reach and performance.

For its part, Google also classifies itself as a processor for users of tools like Google Analytics, DoubleClick Bid Manager and Ads Data Hub.

Privacy tweaks

In late March, Facebook announced updates to its privacy tools that give users more control over their data on the platform, including the ability to access, manage and delete all the information Facebook has on them from a single place.

Sheryl Sandberg first announced these changes were on the way in January, speaking at a Facebook event in Brussels.

A new feature in Facebook’s privacy hub will provide a way for users to see all their information, including posts, reactions, comments and search history. They’ll be able to remove anything from their profile or timeline that they no longer want to exist on Facebook and be able to more easily download their personal data and port it to another service – all of which are requirements under GDPR.

Facebook is also planning to update its privacy policy to be clearer about its data collection practices. GDPR requires privacy notices be written in clear, concise and understandable language.

Third-party data partnerships

Not everything Facebook is doing to shore up its privacy shortcomings is explicitly GDPR-related.

Last week, Facebook announced a plan to phase out third-party data for ad targeting on its platform through partners such as Experian, Acxiom and Oracle. Facebook confirmed to AdExchanger that the move was triggered by the Cambridge Analytica fallout.

But discontinuing access to third-party data has a GDPR halo effect. GDPR raises the bar on permission. Businesses that use third-party data are required to have a legal basis for doing so just as much as first-party data.

By distancing itself from targeting data it hasn’t collected itself, Facebook kills three birds with one stone: appearing to react with alacrity to the Cambridge Analytica scandal, culling possibly unpermitted targeting data from its platform in advance of GDPR and encouraging advertisers to use Facebook’s own targeting tools, including Custom Audiences.

Although some data brokers will feel the burn from this change – Acxiom has said the removal of partner categories will hurt its 2019 revenue – the fact is life won’t change very much for any advertiser with its own direct consumer relationship and CRM files that it can upload to Facebook.

It’s also status quo, at least for the moment, for third-party measurement through Facebook’s marketing measurement partner ecosystem. Facebook has said it’s “working with” its measurement partners and FMPs to ensure compliance, but that it expects “the vast majority of our partnerships will continue uninterrupted.”

Must Read

A comic depicting people in suits setting money on fire as a reference to incrementality: as in, don't set your money on fire!

How Incrementality Tests Helped Newton Baby Ditch Branded Search

In the past year, Baby product and mattress brand Newton Baby has put all its media channels through a new testing regime for incrementality. It was a revelatory experience.

Colgate-Palmolive redesigned all of its consumer-facing sites and apps to serve as information hubs about its brands and make it easier to collect email addresses and other opted-in user data.

Colgate-Palmolive’s First-Party Data Strategy Is A Study In Quality Over Quantity

Colgate-Palmolive redesigned all of its consumer-facing sites and apps to make it easier to collect opted-in first-party user data.

Can E.L.F. Cosmetics Become A Consumer Destination, Not Just A Brand?

History can be a burden for a brand, if it means that company is too set in its ways to pivot and try new things. Just consider e.l.f. Cosmetics, the digitial-first, social-native brand that made good.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Digital-native brands need to figure out how to win in retail shelves. They're finding it difficult, to say the least.

DTC Brands Are Learning The Hard Way That Winning In Retail Can Be A Losing Bet

Digital-native brands need to figure out how to win in retail shelves. They’re finding it difficult, to say the least.

Browser Extension Developers Say Google And Apple Need CMA Oversight

A group of 20 web app developers sent a letter to the CMA claiming the regulator’s proposed remedies for increasing competition among mobile browsers do not address barriers to entry for mobile web extensions on iOS and Android.

A comic depicting people walking past digital billboard screens in a city

TikTok Wants To Win All The Screens, Not Just Your Smartphone

“There are billions of additional screens outside of mobile phones,” says Dan Page, TikTok’s global head of partnerships and new screens. “We want to be in all of them.”