Privacy Policy for Facebook Business Pages

- Companies are liable for data protection violations on their Facebook business pages.
- A GDPR-compliant privacy policy and legal notice are mandatory.
- Joint data protection responsibility between Meta and the company.
- Tracking and data processing require user information and consent.
- Regular review and adjustment to Facebook's terms of use are necessary.
Ensuring strict data protection compliance on your own Facebook business page is no easy task. Companies face a number of challenges. When it comes to the correct implementation of the GDPR, you should by no means rely solely on Facebook.
Typical data protection hurdles for your Facebook business page
Setting up and running a Facebook fan page presents companies with significant data protection challenges. Companies have little to no influence over the framework conditions that Facebook provides for business pages.
For example: The Facebook Insights and the associated tracking of page visitors cannot be deactivated. Nevertheless, the law requires you, as the operator, to take action. If additional tracking tools are used, you are obligated to inform visitors separately in a dedicated social media privacy policy and, if necessary, obtain their consent.
Furthermore, if you wish to use photos of employees or include their names, job titles, or positions on your company page, you must obtain the appropriate consent.
Background: Meta and data protection
For over five years, there have been ongoing discussions regarding data protection at Meta.
- It all started 2018: Back then, the European Court of Justice (ECJ) ruled that the Facebook parent company Meta is not solely responsible for compliance with GDPR requirements, but that there is joint data protection responsibility between Meta and the companies represented on platforms like Facebook.
- 2021 Meta once again came into the focus of data protection advocates when the Federal Commissioner for Data Protection, Ulrich Kelber, called on the federal government and the supreme federal authorities to shut down their Facebook pages. In his assessment, they cannot be operated in compliance with data protection laws.
- This statement was reaffirmed 2022 by the independent Data Protection Conference (DSK) of the federal and state governments in a brief report by the "Facebook Fanpages Task Force." Following this, Dagmar Hartge, the Brandenburg Data Protection Commissioner, called on the supreme state authorities to shut down their Facebook pages immediately.
- Early 2023 the Federal Press Office (BPA) filed a lawsuit against the order after it was decided that Kelber's decision should be reviewed by the courts.
- In May 2023, the Irish Data Protection Commission (DPC) imposed a record fine of 1.2 billion euros on the Facebook parent company Meta. The reason is the transfer of Facebook user data from the EU to US servers, which constitutes a violation of the GDPR.
For years, data protection advocates have feared that US intelligence agencies have access to the information of European users due to this data transfer. The fine is an indication that Meta is not acting in compliance with the law . For companies, this means they are at risk of also committing data protection violations within the scope of joint controllership.
Data protection on Facebook: What is the problem?
Facebook thrives on user data. You pay for the use of the platform consciously and unconsciously with your data. There are two types of digital footprints you leave behind on Facebook:
- Active digital footprint: Personal data that is provided voluntarily
- Passive digital footprint: Data that Facebook collects automatically, for example through tracking
In its privacy policy, Meta states that it primarily uses voluntarily provided data for personalization purposes. But this personalization has two sides: On one hand, users are suggested relevant friends or groups, but on the other, this data is primarily used for tailored advertising.
Furthermore, Facebook sells or shares analytical data about users with third parties. This is where criticism regarding Facebook's data privacy begins—driven in no small part by recurring data privacy scandals.
What personal data is collected on Facebook?
To allow Facebook users to create a personal profile and connect with other users, Meta collects personal data during registration, such as
- First and last name
- Age
- Gender
- Occupation
- Email address
- Phone number
To verify their identity, some users are asked to scan their ID or other official documents, as Facebook's terms of service require users to register with their real name.
Usage data
After registering, users can customize their profile with photos, videos, personal posts, or stories. Through these features alone—and the users' willingness to voluntarily share personal information as well as details about their private and professional lives—a Facebook profile can be used to create a comprehensive personality profile of the individual.
Facebook combines this information across different devices. For example, Facebook uses information you have disclosed through your smartphone usage to better personalize the content (including advertisements) shown to you.
Metadata
In addition, Facebook collects and analyzes further technical data, known as metadata. This is essentially information about voluntarily provided data, such as
- IP address
- Browser
- Operating system
- User location
According to ECJ case law, this information also constitutes personal data that is subject to data protection.
Data outside of Facebook
In addition to usage behavior on the platform itself, usage data is also collected and linked to the Facebook profile via cookies and the integration of the so-called Like button on company websites outside the immediate application of Facebook. Through the Facebook Like button, which now requires active confirmation on external websites, Facebook also collects information about internet users who do not even have a profile on the social platform.
This creates comprehensive datasets about individual Facebook users that go far beyond what individual users voluntarily and consciously share in their own online profiles. The goal of these data collections is to build the most accurate picture possible of the users' interests, desires, and needs, and to sell the resulting datasets.
Companies then use this information to tailor website content—specifically Facebook advertising—to individual users, thereby acquiring more customers and strengthening customer loyalty.
Minimizing risks when using Facebook
The main point of contention when using Facebook in a business context is who collects sensitive user data under data protection law. On one hand, Facebook provides the technical infrastructure for setting up fan pages; on the other, the decision to create a fan page remains with the company itself.
One thing is certain: in the event of data protection breaches or violations, the operator of a Facebook business page is liable for the processing activities for which they are (jointly) responsible. Specifically, this could include data processing for market research and advertising, as well as for establishing contact.
Regardless of who is ultimately legally responsible for data protection compliance, it is advisable for both Facebook and its advertising partners to take appropriate measures to safeguard data privacy. We have summarized the most important steps for your company below.
Update your privacy policy
As a business owner, you have a privacy policy on your website that informs visitors about which data you process and which tools you use for this purpose—in short: it allows you to fulfill your information obligations.
It is necessary that you also inform visitors to your Facebook business page to the same extent about data protection. To do this, link from your Facebook presence either to a separate social media privacy policy or directly to the privacy policy on your website. There, you must include a separate section providing information about data processing on your Facebook business page.
We recommend including a separate Page Controller Addendum (terms regarding joint controllership between you and Meta) privacy policy on your Facebook page that clarifies the responsibilities for each processing activity. It should be added directly to your Facebook business page.
If you also use tracking tools on your website, such as the Facebook pixel, you must include a corresponding paragraph in your website's privacy policy.
Legal Notice for the Facebook Page
It is not just the privacy policy that needs to be updated. Section 5 of the German Telemedia Act (TMG) stipulates a mandatory legal notice requirement for Facebook as well, since a company does not operate the page for private or personal purposes, but rather to increase its own revenue.
Competitors, in particular, frequently check whether the legal notices and privacy policies of their rivals are legally compliant. Back in 2012, there was a nationwide wave of warning letters issued to Facebook pages lacking a sufficient legal notice. In the course of these warnings, it was once again confirmed by higher courts that a legal notice is mandatory on Facebook under Section 5 of the TMG.
What must be included is:
- Name and address of the company
- Contact information that allows for quick and easy communication (such as an email address)
Furthermore, the legal notice must be easy to find . The Higher Regional Court of Munich has ruled that a legal notice is only considered easily accessible if the user needs no more than two clicks to reach it. It is therefore recommended to include the legal notice in the "Page Info" section under "Imprint." The name of the website operator and the Facebook business page operator should match.
One unresolved issue remains the mobile version of the Facebook page, as the legal notice may not be displayed correctly there.
Important: Also, do not forget to include your data processing activities via the Facebook business page in your record of processing activities.
What do companies need to keep in mind when operating Facebook fan pages?
Developments in recent years, ongoing data protection discussions surrounding Facebook, and the record fine from May 2023 clearly show that companies must urgently address the topic of data protection if they want to continue using their Facebook profile to interact with customers in the future.
You should therefore urgently review your company's Facebook fan page and stay regularly informed about developments regarding Meta data protection in order to react quickly if necessary.
If you decide to continue operating your fan page, you should seek expert help to reduce risks such as warnings, fines, and loss of reputation. Facebook can change its terms of use at any time without page operators having any influence over it. It is essential to stay informed about any changes and use professional support to implement all measures that are within your control.
Companies should spare no effort to comprehensively secure data protection for Facebook business pages. A proper privacy policy not only protects against heavy fines but also strengthens the User trust in your company's data protection.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.












