Facts
Meta’s new privacy policy took effect, according to the company’s website, on 26 June 2024. Under it, content shared by users in Brazil on Facebook and Instagram, including information in photos, audio and images, would be used to train and improve its generative AI systems. The processing also reached people who do not use the platforms, where others had shared their images or recordings. The opt-out was hard to find and took several steps. The General Enforcement Coordination of the Brazilian National Data Protection Authority (ANPD) opened an inspection and asked the Board of Directors to adopt a preventive measure. Its technical note put Facebook’s active users in Brazil at around 102 million.
Question
The Board had to decide whether processing personal data to train Meta’s generative AI models created an imminent risk of serious and irreparable, or hard-to-repair, harm that justified a preventive measure before the inspection was complete. The ANPD identified four possible breaches of the General Data Protection Law (LGPD). The first was reliance on legitimate interest as the legal basis even though sensitive data could be involved. The others were a lack of transparency about the policy change, excessive obstacles to the exercise of data subjects’ rights, and the processing of children’s and adolescents’ data without adequate safeguards.
Decision
On 2 July 2024 the Board ordered, until further decision, the immediate suspension in Brazil of the part of Meta’s new privacy policy covering the use of personal data to train generative AI, and of the processing of personal data for that purpose across all Meta products, including data of non-users. Non-compliance carried a daily fine of R$ 50,000. Meta had five working days to file evidence that the relevant passage had been removed from the policy and a signed statement confirming that the processing had stopped. The Board stressed that its assessment was preliminary and that the conduct would be examined in full in the inspection proceedings.
Why it matters
The decision is an example of a data protection authority using an urgent preventive measure to halt a large platform’s use of personal data for AI training. The ANPD looked at the legal basis, the usability of the opt-out and the treatment of children’s data together. The ANPD later suspended the preventive measure after approving a compliance plan submitted by Meta, covering notices to users, an easier way to object and the exclusion of minors’ accounts from training, while the inspection continued.
Related stages
On 9 July 2024, on Meta’s request for reconsideration, the Board maintained the measure and gave Meta five more working days to file the signed statement confirming that the processing had stopped. In late August 2024 it approved Meta’s updated compliance plan and suspended the preventive measure on condition that the plan be implemented in full. Under the plan, data from accounts of users under 18 would not be used for training, and users would be notified at least thirty days before processing began.