Facebook was planning to release a new feature on app , the “Dating” feature. However, it was forced to pull back its official launch date in Europe because it failed to provide the EU with the necessary information about it in advance and because it failed to demonstrate that “Dating” would respect and protect the privacy and confidentiality of the app’s users.
In particular, Ireland's Independent.ie reported that the Irish Data Protection Commission (DPC) had sent agents to Facebook's offices in Dublin, who proceeded to inspect and seize documents referred to in section 130 of the country's data protection law, seeking documentary evidence that Facebook had not previously made available.
According to the DPC, Facebook talked about the appearance of the “Dating” feature in the EU on February 3.
What caused concern, however, was the fact that Facebook did not provide any information about the impact the new feature would have on data protection (Data Protection Impact Assessment -DPIA) and the decision-making processes followed by Facebook Ireland. Facebook announced its plan to get into the Dating “game” in May 2018, taking the idea from Tinder to create a feature for non-friends on its social network and presenting it at the F8 developer conference. It also attempted to launch the new feature in Colombia. Since then, it has gradually added more countries in South America and Asia. It also launched “Dating” in the US, immediately after the FTC imposed a $5 billion fine for historical privacy mistakes.
Facebook also said that the “Dating” feature would be available in Europe by early 2020, without taking into account the protection of privacy under EU rules. In addition, the DPC confirmed that its representatives visited Facebook’s office in Dublin on February 10 to conduct an inspection and managed to collect relevant documents. The DPC’s head of communications, Graham Doyle, confirmed that they were reviewing all the documents they collected as part of the inspection and that they had asked Facebook further questions about the case, and were awaiting a response. The documents included a DPIA that Facebook did not send to the DPC on February 3, which raised many questions.
So the DPC is going to ask Facebook when it did its DPIA. A Facebook spokesperson said it was very important to get Facebook Dating up and running properly, so it needed a little more time to make sure the feature was ready to go on the European market. He also pointed out that Facebook staff had worked carefully to ensure user privacy and assess the impact of the data processing. The DPC asked Facebook why it did not provide the necessary information in advance, instead of asking the regulator to send agents to Facebook’s offices to collect it, since it claims it is “very important” to get it off the ground “right.” The regulator could ask Facebook to make changes to how it operates Dating in Europe if it is not clear that it complies with EU law. So a delay could mean a lot.
Although a DPIA (a process by which the planned processing of personal data is assessed to take into account the impact on people's rights and freedoms) is a requirement under the GDPR when, for example, processing of a profile or sensitive data is carried out on a large scale.
Finally, launching a Dating feature on a platform like Facebook, which has millions of users, requires even more careful evaluation before it is released to the market.
