Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Audits

Irish Regulator Investigates Instagram Over Children’s Data

Irish privacy regulators have opened two investigations into Instagram over the social media site’s handling of young people’s personal data.

Irish privacy regulators have opened two investigations into Instagram over the social media site’s handling of young people’s personal data.

Ireland’s Data Protection Commission said it launched the investigations in September after receiving complaints about the company. Facebook, which owns Instagram and has its European headquarters in Ireland, said it’s in “close contact” with the commission and is “cooperating with their inquiries.”

The investigations were first reported late Sunday by Britain’s Daily Telegraph newspaper, which said they came after a U.S. data scientist aired concerns that Instagram made public the email addresses and phone numbers of people under 18. The minimum age to use Instagram is 13.

Data scientist David Stier said last year that his analysis found users, including those under 18, who switched their account types to business accounts also had their contact information displayed on their profile. Users were apparently switching to business accounts in order to see statistics on how many likes their posts were getting, after Instagram started removing the feature from personal accounts in some countries to help with mental health.

Facebook said it updated its business accounts since Stier’s findings and “people can now opt out of including their contact information entirely.”

One investigation will look into whether Facebook has adequate safeguards in place for children and whether it has a legal basis to process their data. The other focuses on whether Instagram’s profile and account settings are appropriate for children and follow strict European Union privacy regulations.

“The DPC has been actively monitoring complaints received from individuals in this area and has identified potential concerns in relation to the processing of children’s personal data on Instagram which require further examination,” Deputy Commissioner Graham Doyle said in a statement.

Companies can be fined up to 4% of a company’s annual revenue or 20 million euros ($24 million) — whichever is higher — for breaches of the EU’s General Data Protection Regulation.

Advertisement. Scroll to continue reading.

Related: Irish Regulator Investigates Facebook Over Exposed Passwords

Related: Irish Regulator Probes Google, Tinder Over Data Processing

Related: Facebook Spars With EU Regulator Over Dating App Delay

Related: New Mexico Sues Google Over Collection of Children’s Data

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...