Burhan Doğuş Ayparlar

← All decisions

Brazil · 2 July 2024

Brazil’s data protection authority halts Meta’s use of personal data to train generative AI

Brazil’s ANPD ordered Meta to suspend the AI-training part of its new privacy policy and the related processing, on pain of a daily fine.

Court / authority
Brazilian National Data Protection Authority (ANPD), Board of Directors
Date
2 July 2024
Case / decision no.
Meta Platforms, Inc. (generative AI training), Despacho Decisório nº 20/2024/PR/ANPD; Processo nº 00261.004509/2024-36
Status
Interim ruling

Facts

Meta’s new privacy policy took effect, according to the company’s website, on 26 June 2024. Under it, content shared by users in Brazil on Facebook and Instagram, including information in photos, audio and images, would be used to train and improve its generative AI systems. The processing also reached people who do not use the platforms, where others had shared their images or recordings. The opt-out was hard to find and took several steps. The General Enforcement Coordination of the Brazilian National Data Protection Authority (ANPD) opened an inspection and asked the Board of Directors to adopt a preventive measure. Its technical note put Facebook’s active users in Brazil at around 102 million.

Question

The Board had to decide whether processing personal data to train Meta’s generative AI models created an imminent risk of serious and irreparable, or hard-to-repair, harm that justified a preventive measure before the inspection was complete. The ANPD identified four possible breaches of the General Data Protection Law (LGPD). The first was reliance on legitimate interest as the legal basis even though sensitive data could be involved. The others were a lack of transparency about the policy change, excessive obstacles to the exercise of data subjects’ rights, and the processing of children’s and adolescents’ data without adequate safeguards.

Decision

On 2 July 2024 the Board ordered, until further decision, the immediate suspension in Brazil of the part of Meta’s new privacy policy covering the use of personal data to train generative AI, and of the processing of personal data for that purpose across all Meta products, including data of non-users. Non-compliance carried a daily fine of R$ 50,000. Meta had five working days to file evidence that the relevant passage had been removed from the policy and a signed statement confirming that the processing had stopped. The Board stressed that its assessment was preliminary and that the conduct would be examined in full in the inspection proceedings.

Why it matters

The decision is an example of a data protection authority using an urgent preventive measure to halt a large platform’s use of personal data for AI training. The ANPD looked at the legal basis, the usability of the opt-out and the treatment of children’s data together. The ANPD later suspended the preventive measure after approving a compliance plan submitted by Meta, covering notices to users, an easier way to object and the exclusion of minors’ accounts from training, while the inspection continued.

Related stages

On 9 July 2024, on Meta’s request for reconsideration, the Board maintained the measure and gave Meta five more working days to file the signed statement confirming that the processing had stopped. In late August 2024 it approved Meta’s updated compliance plan and suspended the preventive measure on condition that the plan be implemented in full. Under the plan, data from accounts of users under 18 would not be used for training, and users would be notified at least thirty days before processing began.