Facebook commits to changes following critical Irish audit

Facebook will likely be in compliance with the law if it makes some changes, Ireland's Data Protection Commissioner said Wednesday

Facebook plans to change how it retains data and revamp some privacy controls following the release Wednesday of a critical audit from Ireland's data protection authority.

Ireland's Data Protection Commissioner, Billy Hawkes, said if Facebook follows the recommendations, it is unlikely that the social-networking site would be found in violation of Irish data protection laws, which are based on European Union laws.

The agency had more than a dozen recommendations for how Facebook can improve privacy protections and data-handling practices.

Facebook has agreed to the recommendations, and a review on the company's progress is scheduled for next July. Facebook said it would make the changes even in instances where it believes existing practices are in legal compliance.

"Meeting these commitments will require intense work over the next six months," Facebook said in a statement published on its blog.

Facebook said some of the changes will be implemented worldwide, while others will only be visible to European users or to users in areas with local laws that the company is seeking to comply. Facebook Ireland operations have a contractual obligation only to users outside the U.S. and Canada.

Last month, Facebook agreed to implement a comprehensive privacy program after the U.S. Federal Trade Commission found it made deceptive claims over how it shared people's personal data.

Whether the extensive Irish audit forces Facebook to implement better privacy practices in the long term will depend on whether the company makes the changes in "spirit rather than just in the letter," said Kathryn Wynn, a data protection expert with the law firm Pinsent Masons.

"Regulators will find it difficult to keep up with the innovative nature of Facebook developments, so it is possible that Facebook could use technological workarounds in order to overcome changes the ODPC [Office of the Data Protection Commissioner] has called for," she said.

The Irish audit covers many of the issues raised in more than 180 complaints on data retention and disclosure filed with the DPC, although those complaints did not specifically trigger the audit. The results of the audit will be communicated to the complainants, Hawkes said.

Twenty-two of those complaints were filed Europe v. Facebook, a group run by Max Schrems, a law student at the University of Vienna. The group contends -- among many other complaints -- that Facebook does not disclose all of the data it holds on users on request, which it and other data controllers are required to do under E.U. law.

As part of the audit, Facebook has agreed to add new user data to the download tool it provides to let users see the data it holds. The download tool, however, at present downloads information from a person's profile.

Facebook's new timeline feature combined with other data such as a user's activity log will "present a more comprehensive set of access controls" for users to see their data than other comparable services, said Richard Allan, Facebook's director of policy for Europe.

Facebook has also agreed to changes around the use of its "Like," button, a widely used social plug-in used to share content from external websites on Facebook profiles.

Much controversy has surrounded what data the Like button collects and how it is used. The button collects IP addresses for users who are not even members of Facebook, reporting the key identifier back to the company. It will also do that for people who are Facebook members but are logged out of the service.

As a result of the audit, Facebook said it will now remove the last octet of an IP addresses it logs from a social plug-in within 10 days. For all users, whether logged in or logged out or not even a member, Facebook said it will delete its logs collected by a social plug-in after 90 days.

Ireland's DPC found that Facebook does not use information collected by the Like button for targeted advertising.

The DPC did rebuke Facebook over its facial recognition feature, which stores biometric information on users' faces in order to enable an automatic photo tagging feature.

The DPC said Facebook "should have handled the implementation of this feature in a more appropriate manner." Facebook has agreed to quickly change how it is presented by the end of the first week in January. Facebook will notify users a total of three times about the feature.

"We think that’s a very reasonable approach by Facebook on that issue," said Gary Davis, deputy data protection commissioner for Ireland, during a conference call.

The DPC said it confirmed that if a person that does not want to use the feature -- called "tag suggestions" -- their facial profile data will be deleted.

The complete report is available on the DPC website.

Send news tips and comments to jeremy_kirk@idg.com

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags social mediaregulationinternetFacebookInternet-based applications and servicesIreland Data Protection Commissioner

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers


This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang


It really doesn’t get more “gaming laptop” than this.

Jack Jeffries


As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr


The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?