Instagram Profile under GDPR/DSG, Privacy Notice and Duties
Introduction
A Swiss company that runs an Instagram profile is not just a content publisher, in many constellations it is also controller under data-protection law for the data of its profile visitors. The CJEU decided this in 2018 for Facebook Fan Pages (C-210/16 "Wirtschaftsakademie Schleswig-Holstein"), and the logic has since been applied analogously to Instagram Business Profiles that use Insights. As profile operator, you therefore face concrete duties under the DSG and the GDPR, even though the technical platform belongs to Meta.
This article shows:
- which data flows arise between profile visitors and Meta when an Instagram Business Profile is opened;
- which legal role you take as profile operator (controller, joint controller, principal);
- which mandatory information your own privacy policy must contain;
- how the bio link, Reels Insights and influencer collaborations should be assessed;
- which agreements you have with Meta (Joint Controller Addendum) and what they really regulate;
- and how to document the Schrems II risk of cross-border transfer to the US.
Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 16, 19, 22), GDPR (Art. 6, 13, 26, 28, 44 et seq.), CJEU C-210/16 (Wirtschaftsakademie), CJEU C-311/18 (Schrems II), EU-US Data Privacy Framework (2023), Swiss-US DPF (2024).
Data flows on profile visit
When a user opens your Instagram Business Profile, the following data flows to Meta:
- Identifiers: Instagram account ID (if logged in), device IDs, IP address, user agent.
- Interaction data: dwell time, scroll depth, likes, saves, shares, profile visits, story views, Reel plays.
- Inferred data: Meta derives interest clusters, demographic estimates and behavioural profiles from these signals.
- Off-app tracking: via Meta Pixel and Conversions API, activities on your own website can be linked to the Instagram account when the same person is logged in.
As profile operator, you see only the aggregated extract in Instagram Insights: reach, impressions, demographics, engagement rates. Aggregated data alone often does not identify individuals, but it is the product of processing individual personal data, and that processing makes you joint controller with Meta.
Joint controllership under Art. 26 GDPR
In C-210/16, the CJEU ruled that the operator of a Facebook Fan Page is joint controller with Facebook, because, by choosing filters and reach settings, the operator shapes the data processing. The Irish data protection authority (DPC), as Meta's lead supervisor, has applied this logic to Instagram Business Profiles for years.
Meta provides a Pages, Groups and Events Joint Controller Addendum (de facto accepted once you enable a Business Profile). The Addendum sets out:
- Meta is primarily responsible for the Insights processing vis-à-vis data subjects;
- Meta is the point of contact for data-subject rights;
- However, as profile operator, you remain obliged to inform users about the joint controllership in your own privacy policy and to provide the mandatory information under Art. 13/14 GDPR and Art. 19 DSG.
Importantly, the Addendum relieves you of some operational duties but not of the basic information obligation, and not of responsibility for the content you post (images of people, stories with employees, user-generated content).
Mandatory information in your privacy policy
On your own website (in the privacy policy or a social-media annex) the following information must appear:
- Platform notice: "We operate an Instagram presence at @yourhandle. The platform provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland, jointly controlled with Meta Platforms Inc. (1 Hacker Way, Menlo Park, CA 94025, USA)."
- Joint controllership: reference to the Joint Controller Addendum and the allocation of responsibilities (Meta for Insights, you for content).
- Categories of data: profile interactions, IP, device identifiers, inferences, direct messages (DMs).
- Purposes: reach analysis, ad optimisation, communication with users.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) or consent, depending on category.
- Cross-border transfer: US, legal basis EU-US DPF / Swiss-US DPF; Meta Platforms Inc. has been self-certified under the EU-US DPF since July 2023.
- Data-subject rights: note that they can be exercised against both Meta and you; reference to the Meta Help Center and to the FDPIC / EU supervisory authority for complaints.
- Retention: reference to the Meta Data Policy, complemented by your own retention practice for direct messages and comments.
Bio link, Reels and influencer collaborations
Three sub-specifics deserve attention:
Bio link: if you place a link from the Instagram bio onto your website, a Linktree or Beacons service is often inserted in between. These providers are independent controllers for link-click analytics and set their own cookies. Mandatory to mention in your privacy policy, otherwise your visitor has an opaque intermediate stop when clicking your bio link.
Reels Insights and Story Insights: these go beyond standard profile insights and concern reach and interaction data for Reels/Stories. They are an additional ground for joint controllership because you actively produce content and measure its performance through Insights.
Influencer collaborations: when you work with creators (mentions, sponsored posts, branded content via Meta Brand Collabs Manager), additional data flows arise: performance data of the influencer account is shared with you. A Brand Collabs contract should explicitly regulate the data-protection role allocation, who is controller for what. Frequent pattern: joint controllership for campaign analytics, separate controllership for engagement data of each respective account.
Note also the UWG obligation to label advertising (#Werbung, #Ad, #PaidPartnership), that is unfair-competition rather than data-protection law, but feeds into the same compliance sphere.
Direct messages and employee data
When your business answers direct messages (DMs) via Instagram, this is a full-fledged personal-data processing operation. Three points:
- Content: DMs can contain sensitive content (complaints, health questions for health brands, mandate enquiries for consultants). These land in Meta's infrastructure and are subject to Meta's retention and third-party access rules.
- Response processes: if you use a social-media management tool (Hootsuite, Sprout, Brandwatch), this is a further processor, with its own DPA and its own sub-processors.
- Employee data: the answers of your staff are archived by Meta. This creates implicit employee monitoring (response times, tone), staff must be informed (Art. 19 DSG, possibly participation rights under the Swiss Participation Act).
If you show employees in Stories or Reels, you need written consent covering purpose, reach, cross-border notice and right of withdrawal. Blanket "social media clauses" in an employment contract are not sufficient for sensitive content.
Schrems II, DPF and TIA
Meta Platforms Inc. has been self-certified under the EU-US Data Privacy Framework since 10 July 2023. Since 15 September 2024, the Swiss-US DPF also applies. With this, cross-border transfer to the US is currently covered with legal certainty, but:
- The DPF certification must be verified periodically (public list at dataprivacyframework.gov).
- The Schrems movement has announced that it will bring the DPF before the CJEU again (the so-called Schrems III case). Until a potential ruling, the compliance situation is stable but not invulnerable.
- For the Schrems II risks (FISA 702, CLOUD Act) you should document a TIA, the DSG effectively requires this documentation through the duty of care in Art. 8 DSG.
- If the DPF were to fall, the EU SCCs and the Swiss Addendum take over as fallback.
Practically, in the record of processing activities you document two pillars for Instagram, DPF and SCCs, and describe the TIA assessment in a two- to three-page memo.
How SIDD supports you
SIDD supports Swiss SMEs, NGOs and brands with a privacy-compliant social-media presence. For Instagram profiles we offer:
- audit of your Instagram presence including bio link, Insights and Brand Collabs;
- drafting of a social-media section in your privacy policy;
- DPIA for extensive social-media strategies (Pixel, Conversions API, influencers);
- employee consent forms and social-media guidelines;
- mandates as external data-protection advisor;
- GDPR DPO and EU representation (GDPR DPO, EU representative);
- awareness training for marketing and content teams (privacy workshop).
Write to us via the contact form or request a quote via the quote form. We deliver an Instagram quick-audit within two working days.
