Cybersecurity Policy Report, Social Media Platforms Advised by German Regulator to Police Ads for Privacy Violations, (May 13, 2026)
By Tony Foley
The Hamburg State Commissioner for Data Protection and Freedom of Information (HmbBfDI) has issued guidance on the impact of a recent ruling by the Court of Justice of the European Union concerning the responsibilities of online marketplaces under the EU General Data Protection Regulation (GDPR) on social media platforms.
On Dec. 2, 2025, the CJEU found that online marketplace owners qualified as data controllers under the GDPR and were responsible for the lawful processing of personal data contained in advertisements published on their platforms. Specifically, the court found that, before publication of an advertisement containing personal data and using appropriate technical and organizational measures, an online marketplace must identify advertisements that contain sensitive personal data and verify whether the user preparing to place the ad is the person whose sensitive data appears in it. If the user is not offering his or her own data for publication, the marketplace must verify that the person whose information is being published has given explicit consent to publication and must refuse publication if consent is absent and there is no other legal basis for processing under the GDPR (CPR, Dec. 2, 2025).
In its guidance, HmbBfDI said the CJEU decision required operators of online platforms to implement effective protective measures to ensure the removal of illegal content and prevent it from being republished. The agency added that the principles of the CJEU decision were applicable to social media platforms that qualified as data controllers under the GDPR. In particular, HmbBfDI emphasized that the responsibility arises if a social media platform uses personal content for advertising purposes or other commercial interests that go beyond the mere provision of the social media service to the user. The agency contended that this is regularly the case when algorithms, rankings or comparable mechanisms are used that are geared to the platform's own economic interests, a circumstance that it said can be presumed for platforms like Facebook, Instagram, and YouTube.
The guidance clarifies that a social media company classified as a data controller must take risk-based measures aimed at removing illegally published personal content and preventing its publication but adds that this does not mandate a general monitoring obligation for user-generated content or a general identification obligation for users. When a data subject reports illegal content to the social media platform, the platform must remove it and is further required to take appropriate measures to prevent further dissemination.
The detailed assessment of the HmbBfDI may be downloaded from the guidance but is available only in German.
News: InternationalLegislation DataPrivacy GDPR