CIPP/E Study Guide
Ch 17.6.1–17.6.3 - SMPs & joint control

Social media: roles, joint controllership, transparency

Social media platforms (SMPs) collect data users provide, observe, and infer/predict. The SMP is a controller. The pivotal case is Wirtschaftsakademie (the 'Facebook Fan Page' case): a fan-page administrator was a joint controller with the SMP for visitor data - even though it never processed the data itself. The EDPB extends this to advertisers and other targeters. Joint responsibility need not be equal. Transparency: 'advertising' alone is not enough - users must be told what profiling happens.

Controllership on social media
ActorLikely role
SMP providerController (communications platform + advertising use)
Third party offering services via the SMPMay also be a controller
Fan-page administrator / targeterJoint controller with the SMP (Wirtschaftsakademie)
SMP user posting for personal reasonsExempt under the household exemption
SMP user acting for an organisation / sharing too widelyController - household exemption does NOT apply
Wirtschaftsakademie

A fan-page administrator was a joint controller with the SMP for visitor data, even though it did not itself process the data - because it set parameters and gave the SMP the chance to place cookies. But joint responsibility does not imply equal responsibility; the SMP likely has primary responsibility.

  • Saying merely 'advertising' is not enough - explain the processing and its practical meaning
  • Tell users if a profile will be built and used for targeting by third parties, and what data feeds it
  • Provide info directly on screen, interactively, with layered notices where appropriate
  • The essence of a joint-controller arrangement must be made available (Art 26(2))

Key terms - quick answers

What is “Social media platform”?
An online platform for interaction, networking and sharing; the provider is a controller of users' personal data.
What is “Wirtschaftsakademie”?
CJEU 'Facebook Fan Page' case (C-210/16): a fan-page administrator was a joint controller with the SMP, despite not processing the data itself.
What is “Targeter”?
An advertiser or entity that uses an SMP to target its users; often a joint controller with the SMP per EDPB guidance.
What is “Household exemption”?
Exemption where an individual processes personal data purely for personal or household reasons; disapplied in business or over-broad sharing.