Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit

Avatar
Austrian privacy non-profit noyb (none of your business) has sent Meta’s Irish headquarters a cease-and-desist letter, threatening the company with a class action lawsuit if it proceeds with its plans to train users’ data for training its artificial intelligence (AI) models without an explicit opt-in. The move comes weeks after the social media behemoth announced its plans to train its AI models

Austrian privacy non-profit noyb (none of your business) has sent Meta’s Irish headquarters a cease-and-desist letter, threatening the company with a class action lawsuit if it proceeds with its plans to train users’ data for training its artificial intelligence (AI) models without an explicit opt-in.

The move comes weeks after the social media behemoth announced its plans to train its AI models using public data shared by adults across Facebook and Instagram in the European Union (E.U.) starting May 27, 2025, after it paused the efforts in June 2024 following concerns raised by Irish data protection authorities.

“Instead of asking consumers for opt-in consent, Meta relies on an alleged ‘legitimate interest’ to just suck up all user data,” noyb said in a statement. “Meta may face massive legal risks – just because it relies on an ‘opt-out’ instead of an ‘opt-in’ system for AI training.”

The advocacy group further noted that Meta AI is not compliant with the General Data Protection Regulation (GDPR) in the region, and that, besides claiming that it has a “legitimate interest” in taking user data for AI training, the company is also limiting the right to opt-out before the training has started.

Noyb also pointed out that even if 10% of Meta’s users expressly agree to hand over the data for this purpose, it would amount to enough data points for the company to learn E.U. languages.

It’s worth pointing out that Meta previously claimed that it needed to collect this information to capture the diverse languages, geography, and cultural references of the region.

“Meta starts a huge fight just to have an opt-out system instead of an opt-in system,” noyb’s Max Schrems said. “Instead, they rely on an alleged ‘legitimate interest’ to just take the data and run with it. This is neither legal nor necessary.”

“Meta’s absurd claims that stealing everyone’s personal data is necessary for AI training is laughable. Other AI providers do not use social network data – and generate even better models than Meta.”

The privacy group also accused the company of moving ahead with its plans by putting the onus on users and pointed out that national data protection authorities have largely stayed silent on the legality of AI training without consent.

“It therefore seems that Meta simply moved ahead anyways – taking another huge legal risk in the E.U. and trampling over users’ rights,” noyb added.

In a statement shared with Reuters, Meta has rejected noyb’s arguments, stating they are wrong on the facts and the law, and that it has provided E.U. users with a “clear” option to object to their data being processed for AI training.

This is not the first time Meta’s reliance on GDPR’s “legitimate interest” to collect data without explicit opt-in consent has come under scrutiny. In August 2023, the company agreed to change the legal basis from “legitimate interest” to a consent-based approach to process user data for serving targeted ads for people in the region.

The disclosure comes as the Belgian Court of Appeal ruled the Transparency and Consent Framework, used by Google, Microsoft, Amazon, and other companies to obtain consent for data processing for personalized advertising purposes, is illegal across Europe, citing violation of several principles of GDPR laws.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

 The Hacker News 

Total
0
Shares
Previous Post

Kremlin-linked hackers target webmail servers of Eastern European government agencies

Next Post

Ban sales of gear from China’s TP-Link, Republican lawmakers tell Trump administration

Related Posts

New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users

Cybersecurity researchers are alerting to a new malware campaign that employs the ClickFix social engineering tactic to trick users into downloading an information stealer malware known as Atomic macOS Stealer (AMOS) on Apple macOS systems. The campaign, according to CloudSEK, has been found to leverage typosquat domains mimicking U.S.-based telecom provider Spectrum. "macOS users are served a
Avatar
Read More

Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber Attacks

A Chinese national has been arrested in Milan, Italy, for his alleged links to a state-sponsored hacking group known as Silk Typhoon and for carrying out cyber attacks against American organizations and government agencies. The 33-year-old, Xu Zewei, has been charged with nine counts of wire fraud and conspiracy to cause damage to and obtain information by unauthorized access to protected
Avatar
Read More

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Stealing User Assets

Cybersecurity researchers have uncovered over 40 malicious browser extensions for Mozilla Firefox that are designed to steal cryptocurrency wallet secrets, putting users' digital assets at risk. "These extensions impersonate legitimate wallet tools from widely-used platforms such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox
Avatar
Read More