Certix

Protect personal data with correct privacy settings on social media

Certix
Certix®
· 3 Jun 2024 · 4 min read

Informative article. It does not replace individualised professional advice.

Social media has become an indispensable communications channel for most businesses, but its use involves the constant processing of personal data that many organisations manage without adequate controls.

Every time a company publishes photographs of identifiable individuals, manages private messages from followers, uses tracking pixels, or runs advertising campaigns based on audience data, it is processing personal information. That processing requires a legal basis, a clear purpose, and appropriate security measures.

Why does privacy on social media directly affect your business?

Most corporate privacy policies make no mention of social media, employees lack specific training, and agreements with platforms are not reviewed from a regulatory perspective. This combination represents a significant risk of sanction by the AEPD.

"On social media, the line between communicating and exposing personal data is very thin. Knowing where that line is forms part of our work."

Mario P. Talamillo · Managing Partner, Certix®

The most frequent errors that compromise privacy on social media

Publishing images of individuals without consent

Photographing and publishing images of employees, clients, or event attendees without having first obtained their express consent is an infringement of the GDPR.

Using platforms as a customer service channel without a protocol

When clients send private messages containing complaints or personal data, that information is stored on servers outside the company's direct control. Without defined protocols, privacy is put at risk.

Failing to provide adequate information in prize draws and competitions

Prize draws on social media are a common way to attract followers, but they involve the collection of personal data that requires clear information notices and legal bases.

Delegating social media management to agencies without a data processing agreement

If an external agency or community manager manages social profiles and has access to messages and followers' data, they are a data processor and require a formal contract.

Activating analytics tools without disclosing them in the privacy policy

Using tools such as Meta Pixel or LinkedIn Insight Tag without reflecting this in the privacy policy and cookie notices constitutes an infringement that the AEPD has already sanctioned.

Specific obligations for managing social media as a business

  • The Record of Processing Activities must include processing activities associated with social media profiles
  • The privacy policy must provide information about tracking pixels and external tools
  • Procedures must exist for handling rights requests received via direct messages
  • The team must receive specific training in digital privacy

None of these obligations disappears because the platform has its own terms of use. The company remains the controller of the data it manages through the platform.

Privacy on social media as a competitive advantage

Businesses that manage privacy correctly avoid sanctions, communicate consistently, build trust, and reduce reputational risks. In environments where users are increasingly aware of their digital rights, demonstrating rigour in data processing provides a competitive advantage. This dimension forms part of a broader strategy: as we explain in how to improve your reputation with a corporate social responsibility plan, data protection is one of the most tangible pillars of any CSR policy.

This content is for informational purposes only and does not constitute legal advice. The application of regulations to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →