The European Center for Digital Rights (Noyb) has sued 11 European countries, trying to stop Meta's plan to train new AI (artificial intelligence) technologies using the personal posts and photos of Facebook and Instagram in the European Union.

Meta will collect third-party AI training data, as well as from the use of its genetic AI capabilities and interaction with pages. It also plans to collect information about people who are not Facebook or Instagram users but appear in posts or photos.
Read more: Facebook wants to use your posts to train AI
The only exception to AI training is private messages between “friends and family,” which will not be processed. However, private messages to businesses and Meta are fair game, and any data collected for AI training may be shared with third parties.
“In contrast to the already problematic practice of companies using some (public) data to train specific AI systems, Meta’s new privacy policy essentially says that it wants to use all user data it has collected since 2007 for any unspecified current and future AI technology,” Noyb said in a press release.
Noyb also pointed out that users do not appear to have the ability to remove their data from the system once it has been collected. As Meta has given EU users until June 26 to opt out of data processing, Noyb has called on European data protection authorities to intervene immediately. After this deadline, there will be no way to go back and personal data will not be able to be removed from Meta’s AI models.
“We retain training data for as long as we need it, as appropriate, to ensure that an AI model is operating properly, securely , and effectively,” Meta AI’s privacy page states. “We may also retain it to protect our interests or those of others or to comply with legal obligations.”
More than 400 million EU users could be affected, Noyb argued, and many Facebook users who have left their accounts are likely unaware that their data will be processed for this purpose. Noyb also claimed that Meta has deliberately complicated the opt-out process by using “dark patterns” to ensure that as few users as possible will block the processing of their data.
Why Meta AI wants EU user data
Meta said the collection of personal data is necessary to train AI services that reflect “the diverse cultures and languages of the European communities that will use them.” The company emphasizes that this participation will help Meta “provide and manage AI technology in our products, enabling the creation of content such as text, audio, images and video, including understanding and recognizing content in features,” according to an AI policy page.
“This includes features not yet available in Europe, such as the ability for users to create custom stickers for conversations and stories, as well as Meta AI, our virtual assistant that you can call upon to answer questions, create images, and more across our family of apps and devices,” Meta’s blog states.
The AI initiative appears to be part of the social media company's effort to attract younger users, according to a post by Facebook chief Tom Alison. Alison stressed that "the future of Facebook" is focused on developing the "best recommendation technology in the world" and creating one of the leading collections of open models, tools and resources for genetic artificial intelligence.
See more: Slack: Trains AI models with your conversations
Noyb calls for full investigation into Meta AI
Noyb plans to file complaints in all EU member states in the coming days, seeking witnesses and hoping the European Data Protection Board (EDPB) will investigate the case. The group claims that the Irish Data Protection Commission (DPC), which is Meta’s EU regulator, made a “deal” with Meta that would allow it to circumvent the GDPR.
According to a complaint filed in Ireland by Noyb, the DPC agreed to stop delaying Meta’s AI training initiative, as long as Meta agreed to make certain changes. These included providing users with a “jewel notice,” “additional transparency measures,” “a dedicated objection mechanism,” and four weeks’ notice to opt out before the training began. Meta also promised that it would only use “personal data (posts, not comments) shared by EU-based users to public audiences on Instagram and Facebook at the time of the training,” and would not include personal data from accounts of minor users under the age of 18.
Noyb chairman Max Schrems accused the DPC of making “illegal deals” with US Big Tech companies, claiming that the DPC “continues to allow the misuse of non-public personal data” of hundreds of millions of European users without oversight.
“We hope that the authorities outside Ireland will take swift action and at least stop this project for a full investigation,” Schrems said. “The EDPB has already issued two such urgent decisions against Meta and the Irish Data Protection Commissioner. It is sad to see that this measure seems to be necessary again and again.”
So far, Noyb has filed complaints in Austria, Belgium, France, Germany, Greece, Italy, Ireland, the Netherlands, Norway, Poland and Spain.
DPC did not immediately respond to Ars' request for comment. Meta declined to comment beyond its blog.
Meta cites a “legitimate interest” in using AI training data.
In a complaint filed in Ireland, the organization Noyb claims that Meta’s plan to collect personal data to create “undefined” artificial intelligence technologies violates the EU’s General Data Protection Regulation (GDPR). The GDPR requires a lawful basis for processing personal data, and Noyb argues that Meta should have sought users’ consent for this processing. Instead, Meta plans to use the legal basis of “legitimate interest,” as stated in the company’s blog.
“Specifically, we have legitimate interests in processing data to create these services, and this means that people can object using a form found in our Privacy Center if they wish,” Meta’s blog states.
Noyb argues that Meta is trying to establish technology as a purpose for data collection, which is not usually the case under the GDPR, where technologies are considered a “means” rather than an “end.” “The processing of personal data cannot be justified by the desire to use a database system, a hard drive , or analytics software,” Noyb’s complaint states. “It must be justified by the need to achieve a specific goal or purpose, which Meta fails to demonstrate.”
Noyb argues that allowing Meta to use this legal basis would open the way for any tech company to argue that creating new services requires invasive data collection. “If simply extracting personal data from various systems to support any type of new processing for any unspecified purpose constituted a ‘legitimate interest,’ this would mean that any controller could use personal data from any source for any new purpose,” Noyb’s complaint states. “This narrative that Meta is promoting is completely outside the common understanding under the GDPR.”.
Meta considers legitimate interest to be the appropriate legal basis for collecting AI training datasets, as OpenAI and Google have used the same legal basis for the same purpose. However, the Norwegian Data Protection Authority has raised concerns about Meta’s policy on collecting AI data, noting that Meta must use user posts and images for training, which other AI companies do not.
“Meta’s artificial intelligence service is controversial because, in addition to open data from the Internet, it must use user posts and images in education,” the Norwegian agency reports. “Many object to their content being used in this way, as posts and images on social media are often private.”.
See also: Imagine with Meta AI was trained on 1.1 billion photos from Instagram and Facebook
According to the Norwegian agency, it is “doubtful” that Meta’s legal basis complies with the GDPR. “In our view, the most natural thing would be to ask users for their consent before their posts and images are used in this way,” the Norwegian agency says.
Schrems agreed with this view, stating that the EU has already rejected the idea that Meta has a “legitimate interest” in collecting personal data for personalized advertising, so it is unlikely that the court would approve an even more vaguely defined “legitimate interest.” “The European Court of Justice (ECJ) has already made it clear that Meta does not have a “legitimate interest” in overriding users’ right to data protection when it comes to advertising,” Schrems said. However, the company is trying to use the same arguments to train unspecified “AI technology.” It appears that Meta is once again blatantly ignoring the CJEU’s rulings.
Noyb also noted in his complaint that, despite other AI companies having low levels of GDPR compliance, Meta’s AI plan seems extremely problematic. “We are not aware of any controller that has suggested that all personal data ever entered into their systems will be used to train AI technology,” Noyb’s complaint states.
Meta's overly complicated opt-out process
Under Meta’s agreement with the DPC, Facebook and Instagram users should be able to opt out of AI training datasets. However, Noyb criticized Meta for not offering a simple one-click option. Instead, it requires users to log in, find a public form, and provide a reason for opting out.
The Norwegian Data Protection Authority has stressed that any reason for an exception seems acceptable, which Noyb sees as evidence that Meta is deliberately complicating the process. If every reason is acceptable, why is a justification required, other than to create a barrier between the user and the exception?
Noyb claims that Meta uses dark patterns to prevent users from opting out. When users received an email about the policy change and clicked on the opt-out link, they were redirected to a login page, then to their news feed instead of the opt-out form. This required returning to the email and clicking the link again to access the form.
Meta also failed to inform users about a “hidden” opt-out form, which is used for requests regarding personal data used to develop AI. This form is hidden on another page of Meta’s privacy policy.
Schrems from Noyb states: “Shifting responsibility to the user is absurd. The law requires Meta to obtain consent to participate, not to provide a hidden and misleading opt-out form. If Meta wants to use your data, it must ask for your permission.”
Furthermore, Meta admitted that it cannot separate the personal data of individuals who opted out from the data of other users, potentially indicating that opting out of EU users may not even be technically feasible. Meta only promises to “handle objection requests in accordance with relevant data protection laws,” which means that not all opt-outs will be honored.
The Norwegian Data Protection Authority has confirmed that it has received complaints about Meta's AI training plan and promises to take them seriously and give them high priority.
Noyb warned that Meta’s EU policy could affect all Meta users worldwide, who could be used for experimental technology. To prevent Meta from implementing this plan, Noyb asked EU data protection authorities to launch “an urgency procedure” that could lead to a swift temporary ban and a final decision by the EDPB within a few months. During this period, Meta will have time to explain how this approach is legal.

Read more: OpenAI: Creation of a Security Committee and training of a new AI model
However, if data protection authorities decide that Meta's AI project does not comply with the GDPR, Noyb expects significant fines that will be "effective, proportionate and dissuasive."
Source: arstechnica
