Belgian data regulator finds Facebook tracks logged out, explicitly opted out, and unregistered users, thus breaching EU privacy law
Facebook ‘tracks all visitors, breaching EU law’ — Exclusive: Social network even sets a new cookie to track untracked EU users who have explicitly opted out of tracking, report says
Context & Ripple Effects
This finding escalates a running confrontation between Facebook and Belgium's privacy commission. A [[a:826670|February study had already concluded the company was violating European consumer protection law even after its January policy update]], and by mid-May the watchdog was publicly slamming its privacy controls as inadequate before taking the matter to court over what it called "flagrant and massive" violations.
What is new here is the scope of the accusation: the commission's report says Facebook not only tracks all visitors but plants a fresh cookie on users who have explicitly opted out of being tracked, and profiles people who have never registered at all. That moves the dispute from how account holders are treated to whether anyone touching a Facebook page can escape surveillance.
First-order effects
- Facebook now faces documented evidence that its opt-out mechanism does not stop tracking, undermining its core legal defense that consent-based controls comply with EU law and strengthening the Belgian watchdog's hand in the court case it filed weeks later.
- Unregistered and logged-out visitors — the bulk of anyone who ever clicks a shared link — are directly affected today, since the report establishes they are profiled without any contractual or consent relationship with Facebook.
Second-order effects
- Facebook's own response confirms the pressure works: within months it forced Belgian users to log in just to view public pages, trading reach for a defensible consent posture.
- Other EU data protection authorities gain a tested playbook — a national study, then litigation — lowering the cost for additional regulators to open parallel actions against the same cookie practices.
Third-order effects
- The pattern holds through to the endgame: a Belgian court ultimately rules the third-party cookie collection illegal, orders deletion of the harvested data, and attaches threatened €250K-per-day fines, showing a single national court imposing ongoing operational constraints on a global platform.
- If national regulators keep proving they can extract product changes and per-day penalties from Facebook, pre-GDPR Europe consolidates around court-enforced consent standards rather than self-regulated privacy policies.
The trend: European national regulators are converting privacy studies into court rulings with per-day fines, forcing platforms like Facebook to restructure products country-by-country ahead of unified EU enforcement.