| Abstract [eng] |
This Master’s thesis analyses the obligations of social media in the context of the protection of children’s personal data under EU law, assessing whether the legal framework ensures adequate protection and how it is implemented in the practices of Facebook and Instagram. The first part examines the legal position of the child as a data subject and the scope of protected data, as well as the status of social media as data controllers, processors or joint controllers. It also reveals the specific position of the child in social media due to vulnerability, which is understood as dynamic and dependent on personal and social circumstances. In addition, it is emphasised that primary attention should be given to the proper fulfilment of social media obligations, as children’s vulnerability is largely determined by platform infrastructure. It also discusses specific legal safeguards, noting that many are effective, but the regulation remains fragmented, therefore, key standards should be clearly established in legal acts. The second part analyses the requirements arising from Article 8 of the GDPR and concludes that they do not ensure effective protection of children’s personal data. It is established that age is not an appropriate indicator of maturity, although a certain objective age threshold should exist. It is also noted that the requirement of parental (guardian) consent does not reflect contemporary social reality and may restrict the child’s right to privacy, therefore, it should not be established as a mandatory condition for lawful processing. It is further established that social media do not comply with these requirements in practice. It is noted that, in the absence of a clear obligation to verify age, the implementation of legality requirements remains formal, therefore, such an obligation should be established. In addition, different age thresholds across EU Member States lead to unequal levels of protection, therefore a uniform threshold should be applied. The parental (guardian) consent verification model is also difficult to implement in practice, as it remains unclear how to ensure its effectiveness while complying with the principle of data minimisation. The third part examines the effectiveness of the principles of transparency, fairness and lawfulness, data minimisation, purpose limitation and data protection by design and by default, and whether social media implement them properly. It is noted that the principles of transparency, fairness and lawfulness create the conditions for the child and his or her parents (guardians) to understand the data processing, the risks arising from it and their rights, while the principles of data minimisation and purpose limitation restrict excessive processing and the use of data for new, previously undefined purposes, and the principle of data protection by design and by default creates the conditions to limit excessive processing in advance and to ensure that protection is embedded in the service infrastructure itself. However, social media do not comply with these principles in practice. Thus, the results show that the requirements established in data protection law, except those in Article 8 of the GDPR, ensure adequate protection of children’s personal data, but are not implemented in the practices of Facebook and Instagram. Therefore, it is appropriate to consider establishing more of these requirements in legal acts rather than in soft law, as well as strengthening supervisory control and promoting wider publicity of unlawful practices of social media. |