
...Milica Tošić
Artificial intelligence (hereinafter: AI) is becoming more and more accessible to citizens around the world, and large technology companies are actively fighting for dominance in this area. Microsoft, which is the majority owner of the company OpenAI, known for its generative chatbot "ChatGPT", is currently leading the race. It is undeniable that data is the main resource of this battle and that the company with the most user data has the best chance of winning. In order to obtain as much data as possible for training System VI, these companies often try to circumvent regulations related to the protection of personal data and are known for non-transparent business in this area. However, the way in which Meta currently processes the data of users from Serbia in order to improve its services on the basis of VI, is an open violation of our Personal Data Protection Act (hereinafter: the Act).
Namely, for users of Instagram and Facebook from Serbia, Meta started to apply the amended Privacy Policy from June 26, 2024, which states that the content published by users in our country on these platforms will be used for training and production of content for Meta's technologies. VI. In this way, Meta processes a wide range of user data, including: visible posts, likes, comments, geolocation, time of publication, type of devices used, data on interactions with displayed content, but also data collected by Meta's partners about user activities on the Internet outside of Instagram and Facebook.
HOW DOES THIS BUSINESS VIOLATE THE PERSONAL DATA PROTECTION LAW?
Although it announced the application of the amended Privacy Policy to its users from the member states of the European Union almost a month in advance by email and notification, Meta did not inform the users from Serbia about the new rules at all and did not give them the opportunity to be informed about the changes before the Privacy Policy began to take effect. is applied. This violated one of the basic principles of the Personal Data Protection Act, which states that data processing must be fair and transparent. In addition, the processing must also be lawful, which brings us to the next problematic aspect.
Legality means that there must be a valid legal basis for any processing, and the Law prescribes six legal bases, of which the operator is obliged to choose the one that is most suitable for the situation and to apply it adequately. In this situation, the logical choice would be the user's informed consent. However, Meta opted for another basis - legitimate interest, and thus prevented users from deciding for themselves whether the data they have been entering into their Facebook and Instagram accounts for years will be used for the development of VI technologies. Meta has previously tried to mass process its users' data based on legitimate interest - for the purposes of advertising and marketing, however, the Court of Justice of the European Union has judged that such processing would be illegal. In that situation, which is very similar to this one, the court determined that the basic rights and freedoms of the user are more important than the economic interest of the company, and such processing cannot be carried out on the basis of legitimate interest but on the basis of the informed consent of the user.
An additional problem is that among the users of these platforms there are also minors, for whom the Personal Data Protection Act prescribes special protection standards. Although Meta has announced that it will not process the data of persons under the age of 18, this does not apply to situations when these persons interact with adult users. Such processing may include all interactions that minors have with content and users on the platforms including comments, likes and sharing of posts, which may lead to their profiling and thereby endanger their privacy and security.
Also, our Law gives users the opportunity to choose not to be the subject of decisions made solely on the basis of automated processing, including profiling. In the case of Meta, automated processing and profiling carried out through VI technologies can significantly affect users, especially because the algorithms and methods used are not clearly defined. Meta did not provide enough information about the VI technologies themselves, nor how they work. Transparency regarding the methodology, algorithms, and types of data used to train VI models is critical to understanding the potential risks and implications for user privacy. This lack of information prevents users from making informed decisions and represents an additional violation of the principle of transparency.
WHAT IS HAPPENING IN THE EUROPEAN UNION?
Users of Instagram and Facebook from the territory of the European Union received a short email at the beginning of June, as well as a notification in the application, informing them that Meta intends to improve its services on the basis of VI and that it has therefore made changes to its Privacy Policy, which is starting to be applied from June 26, 2024. The email also stated the following: "In order to provide you with these experiences, we will rely on a legal basis called legitimate interest in the use of your data for the purpose of developing and improving artificial intelligence at Meta." This means that you have the right to object to the way your data is used for these purposes. If your objection is accepted, it will be applied from that moment on."
This announcement caused stormy reactions from users and the professional public. The NOYB organization has initiated procedures in 11 member states, demanding that the competent authorities immediately suspend the implementation of the amended Privacy Policy before it enters into force. Max Schrems, one of the founders of this organization, warns of the following: "Meta basically says that it can use 'any data from any source for any purpose and make it available to anyone in the world', as long as it is done through 'technology VI'”. NOYB also points out that Meta did not provide enough information about what exactly the "VI technologies" referred to are, that legitimate interest cannot be a legitimate legal basis for such processing of user data, and that such processing would make it impossible for users to have control over their data and use the mechanisms prescribed by the GDPR, including the right to be forgotten.
After the initiated proceedings, Meta announced that it had paused its plans for the development of VI technologies in the territory of the European Union, and a few days later it announced that it would not launch such systems in the territory of the EU at all due to regulations in the field of personal data protection.
WHAT DEVELOPMENT OF THE SITUATION CAN WE EXPECT IN SERBIA?
Our Personal Data Protection Act provides for all the rules that Meta would have violated if it had started applying its amended Privacy Policy on the territory of the European Union, i.e. all the rules that made it decide not to process user data in this way on the territory of these countries. Why then does it continue to use the data of users from Serbia for its VI improvements, and in an even less transparent way, without any notification to users?
We will briefly refer to the situation in Brazil, which is not only not in the legal system of the European Union, but, unlike Serbia, is not obliged to harmonize with it. Namely, the Brazilian Commissioner for the Protection of Personal Data has suspended the application of Meta's privacy policy, citing the "imminent risk of serious and irreparable or difficult to repair damage to the basic rights of users", and has determined a fine of 50.000 reais (about 952.000 rsd) on a daily basis in in case Meta does not comply with this decision. Immediately afterwards, Meta announced that it was suspending the development of its VI technologies in Brazil.
The situation in Brazil and the European Union shows us not only that Meta insists on an "all or nothing" policy, that is, that it is not ready to harmonize its operations with the regulations of the country in which it operates, but also that it withdraws without engaging in a legal battle as soon as the competent institutions make it known that the amended Privacy Policy violates the laws in the field of personal data protection. This additionally tells us that Meta is aware that this kind of processing of user data is prohibited in many countries, but will certainly try to do it and hope that the competent institutions will not react.
The competent institution in Serbia - the Commissioner for Information of Public Importance and Protection of Personal Data - not only has at its disposal the mechanisms prescribed by our Law, but can also refer to practice from Europe and the rest of the world, which is developing more and more every day in the benefit of the user. After the initial period, in which no institution announced itself regarding the new situation, the Commissioner announced in mid-August that he had taken a series of steps - initiated contact with the company Meta, with the competent bodies of the European Union, but also with the bodies dealing with the protection of personal data in the region and Europe, "in order to find a permanent solution to this problem". It remains to be seen whether the actions of the Commissioner will ensure that Serbia is a safe country for the protection of personal data or a testing ground for irresponsible policies of large companies.
The author is a lawyer, legal advisor of the Partners Serbia organization