Facebook has to explain better what happens to users' personal data and give them more control, the data commissioner in Ireland, home to the website's international headquarters, said on December 21. Facebook must work towards "simpler explanations of its privacy policies (and) easier accessibility and prominence of these policies," the Irish Data Protection Commissioner (DPC) said after a three-month audit.
It called on the US-based firm behind the social networking website, which has some 800 million users world-wide, to provide "an enhanced ability for users to make their own informed choices based on the available information."
The DPC report, available at www.dataprotection.ie/docs/Home/4.htm, also said that Facebook must provide within 40 days all information it holds on a particular user or non-user if requested to do so.
It also said that information to users on what happens to deleted or removed content, such as friend requests received, "pokes", removed groups and tags, and deleted posts and messages "should be improved".
The DPC conducted the enquiry, aimed at determining whether Facebook complied with Irish and by extension European Union law, because Facebook Ireland is the entity with which non-US and non-Canadian users have a contract, the DPC said.
It followed a string of complaints by an Austrian student called Max Schrems who rose to prominence with his "Europe-versus-Facebook" pressure group, the Norwegian Consumer Council and other individuals.
Schrems, 24, had launched his campaign after being shocked to receive from Facebook, in response to a demand for all the data it held on him, 1,222 pages of information, he told AFP earlier this year.