[Paper Review] Facebook Use of Sensitive Data for Advertising in Europe
This study quantifies Facebook's use of sensitive personal data for targeted advertising in the EU, finding that 73% of Facebook users in Europe are labeled with interests linked to sensitive data—such as sexual orientation, political views, or health—potentially exposing 40% of the EU population. Using a browser extension (FDVT) and NLP-based classification, the authors identify sensitive ad preferences and demonstrate that malicious actors could deanonymize users at a cost as low as €0.015 per person.
The upcoming European General Data Protection Regulation (GDPR) prohibits the processing and exploitation of some categories of personal data (health, political orientation, sexual preferences, religious beliefs, ethnic origin, etc.) due to the obvious privacy risks that may be derived from a malicious use of such type of information. These categories are referred to as sensitive personal data. Facebook has been recently fined EUR 1.2M in Spain for collecting, storing and processing sensitive personal data for advertising purposes. This paper quantifies the portion of Facebook users in the European Union (EU) who are labeled with interests linked to sensitive personal data. The results of our study reveal that Facebook labels 73% EU users with sensitive interests. This corresponds to 40% of the overall EU population. We also estimate that a malicious third-party could unveil the identity of Facebook users that have been assigned a sensitive interest at a cost as low as EUR 0.015 per user. Finally, we propose and implement a web browser extension to inform Facebook users of the sensitive interests Facebook has assigned them.
Motivation & Objective
- To measure the extent to which Facebook assigns ad preferences linked to sensitive personal data (e.g., sexual orientation, political views, health) to users in the European Union.
- To assess the privacy risks associated with Facebook’s processing of sensitive data for advertising, particularly in light of the upcoming GDPR.
- To develop and deploy a browser extension (FDVT) that enables users to discover which sensitive interests Facebook has assigned to them.
- To quantify the number of EU citizens and Facebook users exposed to sensitive ad targeting, and to evaluate the feasibility of identity re-identification via low-cost attacks.
Proposed method
- Collected over 5.5 million ad preferences assigned to more than 4,500 Facebook users via the FDVT browser extension.
- Applied natural language processing (NLP) techniques to automatically classify ad preferences as potentially sensitive based on semantic content.
- Conducted manual classification of 126,000 unique ad preferences by 12 trained panelists to validate and refine the NLP-based classification.
- Used Facebook Ads Manager to query the number of users targeted by each sensitive ad preference across the EU and individual member states.
- Simulated a phishing-like attack to estimate the cost of deanonymizing users with sensitive interests, demonstrating low-cost re-identification risks.
Experimental results
Research questions
- RQ1What portion of Facebook users in the European Union are assigned ad preferences linked to sensitive personal data?
- RQ2To what extent can sensitive personal data—such as sexual orientation, political opinions, or health conditions—be inferred from Facebook’s ad preferences?
- RQ3What is the cost and feasibility for a malicious third party to re-identify users who have been assigned sensitive ad preferences?
- RQ4How does Facebook’s current ad targeting system potentially violate GDPR and national data protection laws?
Key findings
- 73% of Facebook users in the European Union are labeled with at least one ad preference linked to sensitive personal data, corresponding to 40% of the total EU population.
- The Spanish Data Protection Agency has already fined Facebook €1.2 million for processing sensitive data without consent, confirming the commercial exploitation of such data.
- A malicious third-party could re-identify users with sensitive interests at a cost as low as €0.015 per user through simple phishing-like attacks.
- The study identifies that ad preferences such as 'Homosexuality' or 'Communism' can reveal highly sensitive personal traits without explicit user consent.
- The research demonstrates that Facebook’s ad targeting system enables the commercial exploitation of sensitive data in violation of GDPR provisions on special categories of personal data.
- The FDVT browser extension successfully enables users to discover their own sensitive ad preferences, highlighting a practical tool for user awareness and data transparency.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.