IMY Imposes Fines on Apoteket and Apohem for Meta Pixel Data Transfer
Background
On August 30, 2024, the Swedish Authority for Privacy Protection (IMY) imposed substantial fines on two pharmacy companies - Apoteket AB (37 million SEK) and Apohem AB (8 million SEK) - for improperly transferring sensitive personal data to Meta through the Meta Pixel tracking tool.
The Investigation
IMY's investigation revealed several serious violations:
- Sensitive Data Transfer: Both companies were found to be inadvertently sharing sensitive health-related information with Meta through their websites.
- Lack of Protection: The implementation of Meta Pixel resulted in unauthorized transfer of personal data, including information about medical products and health conditions.
- Insufficient Controls: The companies failed to implement adequate safeguards to protect sensitive personal data.
Key Findings
-
Types of Data Transferred:
- Information about purchased medicines
- Health-related search queries
- User browsing patterns on health-related pages
-
Legal Violations:
- Breach of GDPR Article 9 (processing of special categories of personal data)
- Inadequate technical and organizational measures
- Lack of proper impact assessments
Server-Side Tracking as a Solution
This case highlights why server-side implementation of tracking pixels is crucial:
-
Data Control:
- Filter sensitive information before sharing
- Control exactly what data is sent to third parties
- Implement proper anonymization
-
Compliance Benefits:
- Maintain control over data flows
- Implement proper consent management
- Ensure GDPR compliance
Implementation Guidelines
-
Moving Meta Pixel Server-Side:
- Implement server-side tracking container
- Filter sensitive data parameters
- Control data flow through server-side rules
-
Data Protection Measures:
- Implement proper consent management
- Regular privacy impact assessments
- Document all data processing activities
-
Best Practices:
- Regular audits of data flows
- Staff training on privacy requirements
- Clear documentation of technical measures
Recommendations for Companies
-
Immediate Actions:
- Audit current tracking implementations
- Identify potential data leakage points
- Document all third-party tools in use
-
Long-term Solutions:
- Move to server-side tracking
- Implement proper data filtering
- Regular compliance reviews
Conclusion
The IMY ruling against Apoteket and Apohem serves as a crucial reminder of the importance of properly implementing tracking tools, especially when dealing with sensitive personal data. Server-side tracking emerges as a key solution to maintain marketing capabilities while ensuring GDPR compliance and protecting user privacy. Companies must take proactive steps to review their tracking implementations and consider moving to server-side solutions to avoid similar penalties.