Instagram is being investigated by Ireland’s Data Protection Commissioner (DPC)
According to news reports: Ireland’s Data Protection Commissioner (DPC) investigated over handling of children’s personal data on the platform. European Union regulator could fine The social media app’s owner Facebook for broken privacy laws.
It comes amid reports Instagram failed to protect data. And the company allow access to email addresses and phone numbers of those under 18
Facebook rejected the claims but was cooperating with the DPC. A number of US tech giants have their European headquarters in Ireland. And the DPC is the lead European Union regulator under the EU General Data Protection Regulation (GDPR), which came into force in 2018.
The DPC is responsible for protecting individuals’ right to online privacy. And DPC has the power to issue large fines. The Irish regulator is investigating whether Facebook has a legal basis for processing children’s personal data. And if it employs adequate protections and restrictions on Instagram for children.
Separately, it is also looking at whether Facebook has adhered with GDPR requirements in relation to Instagram’s profile and account settings. It is inquiring into whether Facebook is adequately protecting the data protection rights of children as vulnerable people.
The minimum age for having an Instagram account is 13. Instagram targets rule-breaking influencers
Facebook bans QAnon conspiracy theory accounts across all platforms.
Facebook ‘Supreme Court’ to begin work before US Presidential vote: Instagram is a social media platform which and children are using it widely in Ireland and across Europe,
“The DPC has been actively monitoring complaints received from individuals in this area. And the Commission has identified potential concerns in relation to the processing of children’s personal data on Instagram which require further examination.
A parent’s worries
According to reports, the investigation stems from a complaint from David Stier, a US-based data scientist who last year analysed profiles of almost 200,000 Instagram users across the world.
He estimated that for over a year, Instagram given option to at least 60 million users under the age of 18 to easily change their profiles into business accounts.
Instagram business accounts require users to display their phone numbers and email addresses publicly. It means that personal data belonging to many users is visible to other Instagram users.
The same personal information was also contained in the HTML source code of web pages accessed. Hackers can scrap the children information easily, when children use Instagram on a computer.
Mr Stier reported his findings to Facebook. But he wrote in a Medium blog that Instagram had refused to mask the email addresses and phone numbers for business accounts.
However, Facebook did decide to remove the contact information from the source code of Instagram pages.
“We’ve also made several updates to business accounts since the time of Mr Stier’s mischaracterisation in 2019. People can now opt out of including their contact information entirely.”
Mr Stier has also alleged that hackers might have succeeded in stealing personal information from Instagram’s website after it was revealed in May 2019. The company stored contact details relating to 49 million users in an unguarded database owned in India.
Further Mr Stier. Do we have a responsibility to keep kids’ phone numbers and emails hidden so that strangers can’t find them just by clicking a button?”
