What happens when a tech giant like Meta uses billions of pieces of user data to train its AI — without clear consent?
While many marvel at the progress of artificial intelligence (AI), Meta's latest move toward "AI everywhere" raises a central question: how safe is our data when it becomes training material for algorithms — without our knowledge?
Meta AI and the Data Question: What's Actually Happening?
Meta (formerly Facebook) plans to train its AI models on content that users have shared on Facebook and Instagram — including text, images, and reactions. Importantly, only public content from adult users (18 and up) will be used. Content from minors is explicitly excluded. Private messages and non-public posts are also unaffected.
The change isn't being introduced quietly — it's being publicly promoted. Still, the central question remains: were the people affected ever actually asked?
Consent? Not at Meta.
Instead of obtaining users' permission, Meta relies on the "legitimate interest" legal basis. That may be convenient from a business perspective — but it's highly problematic from a data protection standpoint. The GDPR requires fair, transparent, and voluntary processing of personal data. And there's not much of that to be seen here.
Criticism from Across Europe
Organizations like noyb and the BEUC (European Consumer Organisation) are sounding the alarm. They've filed complaints against Meta over a lack of transparency and the undermining of fundamental data protection rights. Public pressure is also growing: users want control over their data — especially in the context of AI.
Behind the Scenes: How Exactly Meta Uses Your Data for AI
Meta uses only publicly accessible content from adults — such as photos, captions, likes, and comments — to train AI models. Content from minors and private messages are explicitly not used.
What many don't know: content posted "only" for friends also doesn't count as public and is therefore, according to Meta's current statements, excluded.
Privacy advocates point out that the technical distinction between "public" and "restricted visibility" (e.g., "friends only") isn't always clear-cut. There's uncertainty about whether such content could be affected in individual cases. Meta officially maintains, however, that only genuinely public content is used for AI training.
Also concerning is the lack of transparency: users must fill out a multi-step form to object to the use of their data — with an unclear outcome.
How to Object to Data Processing for Meta AI
For anyone who doesn't want their data used for Meta's AI, there's a way to object — although it's not easy to find:
- Go to the dedicated data usage page: Meta AI opt-out
- Select the "Object to the use of my data" form.
- Enter the required information (name, country, e-mail address).
- Confirm your identity via code.
Meta actively informs users about the new practice — both via app notifications and e-mail. These messages include a direct link to the opt-out form. The process is deliberately cumbersome — but it's worth knowing how it works.
GDPR vs. Big Tech: Why "Legitimate Interest" Doesn't Cut It Here
The crux of the matter: Meta claims that improving AI models is in its "legitimate interest" and uses this as its legal basis. But under the GDPR, this is only permissible if it doesn't override the interests of the individuals concerned. Given how sensitive this data is (facial recognition, family photos, personal statements), that's highly questionable.
Data protection experts warn: "Meta's approach directly contradicts European data protection philosophy — and could end up setting a precedent."
Important: the final assessment by the responsible data protection authorities is still pending. Complaints and review proceedings are underway, particularly through the Irish Data Protection Commission (DPC) and at the European level. The legal situation therefore hasn't been finally resolved.
What Businesses Should Do Now — and How heyData Can Help
Many businesses use AI — often unknowingly, with data-processing tools from third-party vendors. The Meta case shows that transparency, control, and documented consent are mandatory.
heyData provides businesses with concrete support for:
- An instant audit tool to classify the risk level of your AI systems
- A customized roadmap with recommendations based on the EU AI Act
- Team training for responsible AI use & ongoing compliance assurance
- Automated, legally compliant documentation — we take the compliance burden off your shoulders
Use Case: AI Project with Data Protection by Design
A mid-sized company in the financial sector wanted to use AI to run automated customer analyses. With heyData's help, data flows were documented, a Data Protection Impact Assessment (DPIA) was carried out, and clear opt-in mechanisms were put in place. The result: the solution was not only legally compliant but was also received positively by customers — a genuine trust advantage.
Future & Trends: What's Coming on the Regulatory Front
The EU AI Act is establishing new rules for AI models — particularly around biometric data, algorithmic decision-making, and transparency obligations. Companies that embrace privacy by design today will be clearly ahead tomorrow. The topic is also being heavily regulated internationally (e.g., in Canada or California).
AI and Data Protection Worldwide: A Comparison
- California (CCPA/CPRA): Allows objections to automated decision-making
- Canada (CPPA): Requires businesses to conduct risk-based assessments of AI systems
- China: Introduces registration and disclosure requirements for generative AI
Europe is ahead with the EU AI Act — but global standards are evolving rapidly. Businesses should therefore already be thinking internationally today.
Conclusion: Data Is Power — and Responsibility
The Meta case is just the tip of the iceberg. Anyone using AI must take responsibility. Not someday — now.
Data protection isn't a roadblock — it's your seatbelt in an AI-driven future.
In summary:
- Only public content from adults is used.
- Minors and private messages are excluded.
- The final decision from data protection authorities is still pending.
- Meta actively informs users and offers a (though cumbersome) opt-out.







