EDPB Guidelines on Targeting of Social Media Users

Published July 9, 2021
Author

Maria Khan

Data Privacy Legal Manager at Securiti

FIP, CIPT, CIPM, CIPP/E

Listen to the content

In today’s online world, social media providers offer targeting services making it possible for individuals and businesses to communicate specific messages to social media users in order to advance their commercial, political, or other interests. Such targeting may impact social media users and impose several privacy risks to them. To address the risks posed by targeting social media users and protect their rights and freedoms, the European Data Protection Board released its updated guidelines (Guidelines) on 13 April 2021.

This article provides an overview of the Guidelines that can help social media providers and targeters to comply with data protection requirements.

First of all, let’s look into various types of risks posed to social media users in the context of targeting.

Risks to social media users:

The EDPB points out that risks to social media users can be of the following four types:

  1. Risk of data being used beyond the reasonable expectations of users and its intended purposes.
  2. The possibility of discrimination and exclusion against certain individuals.
  3. The possibility of manipulation of users so as to undermine individual autonomy and freedom.
  4. The potential adverse impacts to vulnerable categories of users such as children.

Targeting Mechanisms:

Now, let’s look into three different targeting mechanisms explained by the EDPB.

  1. Targeting on the basis of provided data:
    Provided data refers to information actively provided by the social media user to the social media provider and/or the targeter. Social media users actively disclose information about themselves when opening a social media account or profile. Such information may include name, date of birth, gender, place of residence, language, relationship status, interests, and even current employment. This information is then used by the social media provider to develop parameters or criteria, which enable the targeter to address specific messages to the specific set of social media users. Targeter can be any natural or legal person that can direct specific messages to a set of social media users on the basis of specific parameters or criteria. List-based targeting is one example where a targeter uploads pre-existing lists of personal data (such as email addresses or phone numbers) for the social media provider to match against the information on the platform.
    As joint controllers, both the social media provider and the targeter must be able to demonstrate the existence of a legal basis to justify the processing of personal data. The two legal bases which could justify the processing that supports the targeting of social media users are the data subject’s consent and legitimate interests of the controller.
  2. Targeting on the basis of observed data:
    Observed data refers to data provided by the social media user by using a service or device. Social media providers may be able to observe the behaviour of social media users via pixel-based targeting, geo-targeting, and similar techniques. Pixel-based targeting, for example, occurs when an online retailer places a tracking pixel on its website so it can retarget social media visitors who have not made a purchase. Geotargeting, on the other hand, occurs when a social media network collects the GPS (location) from its users on an ongoing basis which the social media network uses to help advertisers better target advertising.
    Since such targeting normally involves the use of cookies, data controllers must obtain users’ consent. The EDPB reminds organizations of their obligation under Article 5(3) of the ePrivacy Directive that requires users to provide clear and comprehensive information about the purposes of the processing prior to obtaining users’ consent. Such consent needs to be freely given, specific, informed and unambiguous. The EDPB emphasizes that both the website operator for the transmission of personal data triggered by its website and the social media provider should obtain consent as they both act as joint controllers as far as targeting on the basis of observed data is concerned.
  3. Targeting on the basis of inferred data:
    Inferred data (derived data) is the data created by the data controller on the basis of the data provided by the social media user, regardless of whether these data were observed or actively provided by the user, or a combination thereof. Inferences about social media users can be made both by the social media provider and the targeter.
    The targeting of social media users on the basis of inferred data typically involves profiling - automated processing of personal data which aims at evaluating personal aspects, in particular, to analyse or make predictions about individuals. Where the profiling is likely to have a similarly significant effect on a user, Article 22 of the GDPR will be applicable. Accordingly, data controllers will have to ensure the following:

    • Case-by-case assessment as to whether targeting will similarly significantly affect social media users in each instance concerning the specific facts of the targeting.
    • Principles of fairness, necessity, proportionality and data quality.
    • Explicit consent of the user in the case of the use of tracking techniques or targeting of vulnerable categories of persons having the potential to significantly and adversely affect them.

Data Protection Principles:

Now, let’s look into data protection principles emphasized by the EDPB in its Guidelines, that are relevant in the context of targeting:

  1. Transparency:
    The EDPB recalls that the mere use of the word “advertising” would not be enough to inform the users that their activity is being monitored for targeted advertising. In fact, it should be made clear to users what types of processing activities are carried out and what this means in practice.
  2. Data subjects’ right to access:
    As joint controllers, the social media provider and targeter can designate a single point of contact for users to exercise their rights. However, this will not exclude the possibility for users to exercise their rights against each data controller.
  3. Data protection impact assessments:
    A DPIA is necessary if targeting is likely to result in a high risk to users. If a DPIA is necessary, the joint arrangement/agreement between the social media provider and targeter should address the question of how the controllers should carry it.
  4. Special categories of data:
    The processing of special categories of data can take place only if it meets one of the conditions set out in Article 9(2) of the GDPR, such as having obtained the user’s explicit consent or the data have been manifestly made public by the social media user.

Takeaways:

To summarize, here are the key takeaways of EDPB’s Guidelines on targeting of social media users:

  • Targeting of social media users presents many risks to users and such targeting can be via provided data, observed data and inferred data. There are various scenarios and techniques through which targeting of social media users is done.
  • Targeters and social media providers act as joint controllers where they both determine the means and purposes of data collection. This happens when a social media service provider or targeter identifies the audience to be targeted, sets the targeting criteria, and shows advertisements to the targeted audience.
  • As joint controllers, targeters and social media providers must determine their respective data processing operations via joint agreement. The agreement must cover details of all processing operations for which both parties are jointly responsible.
  • Both joint controllers must have a legal basis to process personal data. For most targeting of social media users, the likely legal bases to apply are data subjects’ consent and the legitimate interests of the controller or a third-party.
  • For consent to be valid, it must be freely given, specific, informed, and unambiguous. Moreover, social media users should be allowed to withdraw their consent at any time without any detriment.
  • To rely on legitimate interest as a legal basis to process personal data, three cumulative conditions must be met:<
    1. Necessity test: the pursuit of a legitimate interest by the data controller or by the third party to whom the data are disclosed,
    2. Purpose test: the need to process personal data for the legitimate interests pursued, and
    3. Balancing test: the legitimate interest of the controller or third-party must be balanced against the fundamental rights and freedoms of the data subject.
  • In addition to having a legal basis for data processing, controllers must comply with data protection principles, in particular the principles of transparency, necessity, proportionality, and data quality. Moreover, they must adequately respond to data subject’s access requests.

Businesses are now required to assess their roles as social media providers or targeters and determine their respective data protection obligations via joint agreement. They must ensure the processing of personal data only on lawful grounds. As pointed out by the EDPB, those legal bases may be the data subject’s consent or legitimate interests of the data controller or third-party.

Securiti offers automated data mapping, DSR rights fulfillment, and consent management to help you comply with the applicable legal requirements. Ask for a DEMO today to understand how Securiti can help you comply with GDPR, EDPB Guidelines, and global data privacy laws and regulations with ease.

Your DataAI Command Platform

Enable Safe Use of Data and AI

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
A Complete DSPM Needs Classification and Context
Classification is one of the core functions a DSPM program handles, and it usually runs in tandem with discovery, since together they form the...
What is Access Control? Definition, Types, & Components View More
What is Access Control? Definition, Types, & Components
Discover what access control is, how it works, types, components, importance in ensuring regulatory compliance, and much more.
What is Data Integrity? Complete Guide View More
What is Data Integrity? Complete Guide
Learn what data integrity is, why it matters for security, compliance, and AI, the different types of data integrity, common threats, best practices to...
The Context Layer for Data+AI Security View More
The Context Layer for Data+AI Security
Discover how Securiti’s DataAI Command Graph connects data, identity, cloud, and AI findings to uncover contextual risk and toxic combinations.
View More
Privacy RFP Buyer’s Guide: 120+ Questions to Evaluate Privacy Automation Platforms
Download the Privacy RFP Buyer’s Guide with 120+ practical questions to evaluate privacy automation platforms across compliance, security, integrations, governance, and scalability.
The Toxic Combination Problem in DataAI Risks View More
The Toxic Combination Problem in DataAI Risks
Discover how siloed security alerts create hidden toxic risk combinations and how correlated context helps reduce alert fatigue and uncover compound risks faster.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New