Facebook commits to changes following critical Irish audit
Facebook will likely be in compliance with the law if it makes some changes, Ireland's Data Protection Commissioner said Wednesday
IDG News Service - Facebook plans to change how it retains data and revamp some privacy controls following the release Wednesday of a critical audit from Ireland's data protection authority.
Ireland's Data Protection Commissioner, Billy Hawkes, said if Facebook follows the recommendations, it is unlikely that the social-networking site would be found in violation of Irish data protection laws, which are based on European Union laws.
The agency had more than a dozen recommendations for how Facebook can improve privacy protections and data-handling practices.
Facebook has agreed to the recommendations, and a review on the company's progress is scheduled for next July. Facebook said it would make the changes even in instances where it believes existing practices are in legal compliance.
"Meeting these commitments will require intense work over the next six months," Facebook said in a statement published on its blog.
Facebook said some of the changes will be implemented worldwide, while others will only be visible to European users or to users in areas with local laws that the company is seeking to comply. Facebook Ireland operations have a contractual obligation only to users outside the U.S. and Canada.
Last month, Facebook agreed to implement a comprehensive privacy program after the U.S. Federal Trade Commission found it made deceptive claims over how it shared people's personal data.
Whether the extensive Irish audit forces Facebook to implement better privacy practices in the long term will depend on whether the company makes the changes in "spirit rather than just in the letter," said Kathryn Wynn, a data protection expert with the law firm Pinsent Masons.
"Regulators will find it difficult to keep up with the innovative nature of Facebook developments, so it is possible that Facebook could use technological workarounds in order to overcome changes the ODPC [Office of the Data Protection Commissioner] has called for," she said.
The Irish audit covers many of the issues raised in more than 180 complaints on data retention and disclosure filed with the DPC, although those complaints did not specifically trigger the audit. The results of the audit will be communicated to the complainants, Hawkes said.
Twenty-two of those complaints were filed Europe v. Facebook, a group run by Max Schrems, a law student at the University of Vienna. The group contends -- among many other complaints -- that Facebook does not disclose all of the data it holds on users on request, which it and other data controllers are required to do under E.U. law.
In a press release, Europe v. Facebook wrote that Facebook's business model, which revolves around the heavy processing of personal data, could face limitations following the Irish audit. The group was also leery of the close work between the DPC and Facebook.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Gov't Legislation/Regulation White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Gov't Legislation/Regulation Webcasts