Facebook allows advertisers to target users based on sensitive data

GDPR prohibits the processing of 'special category' data under Article 9

Facebook lets advertisers target users based on what it believes they are interested in, regardless of their religious beliefs or sexuality, something that's considered to be in breach of upcoming data protection laws.

A joint investigation between The Guardian newspaper and the Danish Broadcasting Corporation found that companies are allowed to deliver tailored adverts to Facebook users on subjects such as homosexuality, liberalism, or Islam, despite a provision under the General Data Protection Regulations (GDPR) that marks such data as sensitive.

While Facebook also uses fairly innocuous data to inform advertising, such as favourite football teams or towns or cities they've visited, data on political beliefs or sexuality are considered to be so sensitive that they require special treatment under law.

Religion, sex life, ethnicity, and race are also marked out by Article 9 of GDPR as 'special categories', data that would constitute a significant breach on an individual's human rights should they be disclosed. Processing of this data is therefore prohibited unless explicit consent is given by users.

The Information Commissioner's Office, the data watchdog responsible for enforcing data protection laws in the UK, states that "this type of data could create more significant risks to a person's fundamental rights and freedoms".

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Under Article 9, organisations processing such data are required to meet one of 10 provisions in order for it to be considered legal, such as protecting legal rights and vital interests, or if there's a demonstrable public interest.

The report found that around 68,000 UK citizens were identified by Facebook's advertising tools as being interested in homosexuality and Hinduism, data which can then be used by companies for targeted ads.

Facebook revealed in April it would be rolling out changes to its privacy policies in line with GDPR, adding that it would be going "beyond our obligations" to ensure compliance. As part of these changes, the company required every user to confirm whether 'special category' data should be stored or displayed on their profile.

However, Facebook has yet to gain explicit consent to process information it had inferred about its users based on activity, according to the report, something that is required under GDPR.

In response to the report, Facebook told The Guardian: "Like other internet companies, Facebook shows ads based on topics we think people might be interested in, but without using sensitive personal data."

Advertisement - Article continues below

"This means that someone could have an ad interest listed as gay pride because they have liked a Pride-associated page or clicked a Pride ad, but it does not reflect any personal characteristics such as gender or sexuality."

The company added that its advertising "complies with relevant EU law" and that it was "preparing for the GDPR to ensure we are compliant when it comes into force".

Facebook has worked to reform the way it handles data following the Cambridge Analytica scandal, which saw the information on some 87 million users inappropriately shared with a third-party.

Image: Shutterstock

  • General Data Protection Regulation (GDPR)
Featured Resources

How inkjet can transform your business

Get more out of your business by investing in the right printing technology

Download now

Journey to a modern workplace with Office 365: which tools and when?

A guide to how Office 365 builds a modern workplace

Download now

Modernise and transform your sales organisation

Learn how a modernised sales process can drive your business

Download now

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now
Advertisement

Most Popular

Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn
cloud computing

Google Cloud snaps up multi-cloud analytics platform for $2.6bn

13 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020
Visit/security/34616/the-top-ten-password-cracking-techniques-used-by-hackers
Security

The top ten password-cracking techniques used by hackers

10 Feb 2020