Back to all lessons
Awareness Lessons
3 months ago

German Court Orders Social Media Platform to Cease Unlawful Third-Party Data Collection via Business Tools

A German appellate court found that a social media platform acted as a joint controller under GDPR when its 'Business Tools' (e.g., tracking pixels, SDKs) collected personal data from third-party websites and apps without a lawful basis. The root cause is a failure to establish transparent, compliant data processing agreements and obtain proper consent before collecting data across external properties. This matters because businesses embedding such tools on their own sites may unknowingly become co-liable for GDPR violations, exposing themselves to regulatory action and civil damages. The €1,500 damages award signals that courts are willing to enforce individual data subject rights, raising the financial stakes for non-compliance significantly.

Tactical Insight

Immediate actions

  • Audit all third-party tracking tools (pixels, SDKs, scripts) currently embedded on your websites and apps to assess GDPR lawfulness.
  • Implement or update a Consent Management Platform (CMP) to ensure valid, informed consent is obtained before any Business Tool activates and transmits personal data.

Long-term improvements

  • Establish formal Joint Controller Agreements (Art. 26 GDPR) with any third-party platform whose tools you embed, clearly defining each party's responsibilities.
  • Conduct annual Data Protection Impact Assessments (DPIAs) for all third-party integrations that process personal data at scale.
  • Embed privacy-by-design principles into the software development lifecycle so tracking tools are evaluated for compliance before deployment.

Detection & Monitoring measures

  • Deploy continuous website scanning tools (e.g., cookie crawlers) to detect unauthorized or undisclosed data collection by third-party scripts.
  • Monitor regulatory databases and court rulings in relevant jurisdictions to proactively identify compliance risks tied to tools you use.