Can Social Media Companies Legally Sell Your Data?

Photo of author
Author: Alex
Published:
Updated:
Smartphone with social media icons as data streams flow toward corporate and government buildings, shield blocking some streams

Direct Answer: Social media platforms like Facebook, Instagram, and TikTok don’t typically “sell” your raw personal data directly. Instead, they collect massive amounts of information about you and sell advertisers access to your attention through targeted ads. Under laws like the GDPR (EU), CCPA (California), and the UK Data Protection Act, users have specific rights to access, delete, and control how platforms use their data but those rights vary depending on where you live.

Social media data privacy rights users have today look very different depending on which side of the Atlantic you’re on. You open Instagram, scroll through a few posts, like a photo, search for a restaurant and within minutes, ads for that exact restaurant appear in your feed. It feels like the app is reading your mind. In reality, the platform is collecting, analyzing, and monetizing your behavior in ways most people never fully understand. And while laws exist to protect you, the protections are uneven across the US, UK, and EU. Here’s what the law actually says about your rights and what you can do about it. (For a broader look at how companies profit from your information, see our guide: Can Companies Legally Sell Your Personal Data?)

The Short Version

  • Social media platforms collect far more data than most users realize including browsing habits, location, device information, and behavioral patterns and use it to power targeted advertising.
  • In the European Union, the GDPR gives users the right to access, delete, and transfer their data. The EU fined TikTok €530 million in 2025 and Meta €1.2 billion in 2023 for violating these rules.
  • In the United States, there is no single federal privacy law. California’s CCPA gives residents the right to opt out of data selling and sharing, but most other states offer far weaker protections.
  • In the United Kingdom, the UK GDPR and Data Protection Act 2018 provide similar protections to EU law, though recent reforms under the Data (Use and Access) Act 2025 are shifting some of those rules.

What the Law Actually Says About Social Media Data Privacy Rights Users Have

The answer depends entirely on where you live. Three major legal frameworks cover most English-speaking users.

European Union GDPR (2018)

The General Data Protection Regulation (GDPR) is the strongest data privacy law affecting social media users anywhere in the world. It applies to any company processing the personal data of EU residents regardless of where that company is headquartered.

Under the GDPR, social media companies must get explicit consent before collecting and processing your data. “Personal data” covers far more than your name and email. It includes cookies, IP addresses, device IDs, location data, and even your browsing behavior.

The GDPR gives EU residents several specific rights:

Right of access the ability to request a full copy of all personal data a platform holds about you.

Right to erasure (also called the right to be forgotten) the ability to demand that a company delete your personal data when it’s no longer needed or when you withdraw consent.

Right to data portability the ability to download your data in a usable format and transfer it to another service.

Right to object the ability to stop a company from using your data for direct marketing, including targeted advertising.

In May 2026, the European Commission marked ten years since the GDPR entered into force. Since 2018, EU data protection authorities have issued over €7 billion in fines. The two largest penalties both involved social media companies: a €1.2 billion fine against Meta in 2023 for transferring Facebook users’ personal data to the US without proper safeguards, and a €530 million fine against TikTok in May 2025 for sending European users’ data to China.

The GDPR’s enforcement model puts real teeth behind these rights. Every EU country has an independent data protection authority (DPA) with the power to investigate complaints and impose fines of up to €20 million or 4% of global annual revenue whichever is higher.

United States A Patchwork of State Laws

The US has no single federal privacy law covering social media. That gap matters. It means protections depend almost entirely on which state you live in.

California’s CCPA/CPRA is the strongest state-level framework. Under the California Consumer Privacy Act, as expanded by the California Privacy Rights Act, California residents can:

  • Find out what personal data a company has collected about them
  • Request deletion of that data
  • Opt out of the sale or sharing of their personal information (including cross-context behavioral advertising)
  • Limit the use of sensitive personal information like precise location, financial accounts, and browsing history

As of 2026, the California Privacy Protection Agency (CPPA) actively enforces these rules. The agency launched the Data Request and Opt-Out Platform (DROP) on January 1, 2026 a single portal where consumers can request deletion from all registered data brokers at once. In early 2026, the California Attorney General secured a $2.75 million settlement against Disney for failing to honor opt-out requests across Disney+, Hulu, and ESPN+ the largest CCPA settlement to date.

Outside California, protections are far thinner. States like Kentucky, Maryland, and Indiana have new privacy laws that took effect in 2025 and 2026, but they generally offer fewer rights and weaker enforcement mechanisms.

The American Privacy Rights Act (APRA), a proposed federal privacy bill, was introduced in 2024 but expired at the end of that Congress without passing. No federal privacy law has been enacted as of mid-2026.

United Kingdom UK GDPR + New Reforms

The UK kept a version of the GDPR after Brexit. The UK GDPR, paired with the Data Protection Act 2018, gives UK residents rights that mirror the EU framework including access, erasure, data portability, and the right to object to automated decision-making.

The Information Commissioner’s Office (ICO) enforces these rules. The ICO previously fined Clearview AI £7.5 million in 2022 for scraping facial images of UK residents from social media without a lawful basis.

However, the legal landscape is shifting. The Data (Use and Access) Act 2025 received Royal Assent in June 2025. Its main data-protection provisions began taking effect in February 2026. This new law introduces “recognised legitimate interests” that don’t require the same balancing test previously required under GDPR, adjusts how organisations handle data subject access requests, and introduces mandatory internal complaints handling from June 2026.

For UK social media users, the core rights remain intact but the gap between UK and EU data protection standards may widen in the coming years.

Three panels comparing EU, US, and UK social media data privacy rights with legal icons for each jurisdiction

How Each Major Platform Handles Your Data

Not all social media companies treat your data the same way. Here’s what the biggest platforms actually do and what the law says about it.

Facebook / Meta

Facebook collects an enormous volume of data: profile information, posts, likes, comments, browsing activity on third-party websites (through tracking pixels and cookies), device information, location data, and even data from apps that use Facebook Login.

Understanding Facebook data rights starts with a distinction that Meta insists on: the company claims it does not directly “sell” personal data. Instead, it sells advertisers access to granular audience targeting. Advertisers choose demographics and interests Meta serves the ad. The distinction matters legally: under CCPA’s broad definition, sharing data for cross-context behavioral advertising counts as “sharing” and triggers opt-out rights for California residents.

Meta’s €1.2 billion GDPR fine in 2023 the largest in history stemmed from its practice of transferring EU Facebook users’ data to US servers, where it could be accessed under US surveillance laws. The EU–US Data Privacy Framework, adopted in July 2023, now provides a legal pathway for such transfers, but legal challenges to this framework remain likely.

Instagram

Instagram, owned by Meta, operates under the same data policies. Any Instagram privacy law question starts with Meta’s broader terms. Users retain copyright ownership of their photos and videos. However, by posting content, users grant Instagram a non-exclusive, royalty-free, transferable, sub-licensable, worldwide license to use, distribute, modify, and create derivative works of that content.

In plain English: you still own your photo, but Instagram can use it for almost any purpose including AI training, promotional features, and allowing third parties to embed or reshare it. That license ends only when you delete the content or close your account, and even then, copies already shared by others may persist.

Instagram’s January 2025 terms update expanded the platform’s ability to use content in AI training datasets and third-party advertising. Content creators who sell images under exclusive licenses risk breaching those agreements by posting the same images on Instagram.

TikTok

TikTok’s data practices have faced the most intense regulatory scrutiny of any social media platform. Whether TikTok data collection is legal depends on which jurisdiction’s rules apply and recent enforcement actions show regulators are losing patience. The app collects device identifiers, keystroke patterns, browsing history, location data, biometric data (including faceprints and voiceprints in some jurisdictions), and content from messages sent through the platform.

The central concern: TikTok’s parent company ByteDance is headquartered in China. Chinese laws including the Anti-Terrorism Law, Cybersecurity Law, Counter-Espionage Law, and National Intelligence Law give the Chinese government broad authority to compel companies to hand over data.

In May 2025, the Irish Data Protection Commission fined TikTok €530 million for transferring European users’ data to China without adequate safeguards. During the investigation, TikTok initially told regulators it did not store European data on Chinese servers only to admit in April 2025 that limited EEA user data had in fact been stored in China.

In the United States, Congress passed the Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACAA) in April 2024, requiring ByteDance to sell TikTok to a non-Chinese owner or face a ban. In January 2025, the Supreme Court unanimously upheld the law. President Trump subsequently arranged a deal in which TikTok’s US operations would be run by a joint venture majority-owned by US investors, with ByteDance retaining a 19.9% stake.

Real-World Examples

The Meta Data Transfer Fine (EU, 2023)

The Irish DPC fined Meta €1.2 billion the largest single GDPR penalty for transferring Facebook users’ personal data from the EU to US servers without providing protections equivalent to EU standards. This wasn’t about selling data directly. It was about where the data was stored and who could access it under US surveillance laws (specifically FISA Section 702). Meta was ordered to suspend transatlantic data transfers and delete improperly transferred data.

TikTok’s €530 Million Penalty (EU, 2025)

TikTok was fined for violating GDPR Article 46 by failing to demonstrate that Chinese law provides privacy protections equivalent to EU standards. The fine included €485 million for the data transfer violation and €45 million for transparency failures specifically, TikTok’s privacy policy between 2020 and 2022 didn’t adequately inform users that their data could be accessed from China. TikTok has said it plans to appeal.

California’s CCPA Enforcement Wave (US, 2025–2026)

California regulators have been aggressively enforcing opt-out rights. In 2025–2026, enforcement actions targeted companies including:

  • General Motors A $12.75 million settlement for selling OnStar driving and location data to data brokers, who then sold it to insurance companies for rate-setting.
  • Disney A $2.75 million settlement for failing to honor opt-out requests across its streaming platforms.
  • PlayOn Sports A $1.1 million fine for using tracking tools to collect data from school event ticketholders, including students, and sharing it with advertising and social media partners.

What People in This Situation Typically Do

If you’re concerned about how social media platforms use your data, here are the steps many people take:

1. Check what data platforms hold about you. Every major platform lets you download a copy of your data. On Facebook, go to Settings Your Facebook Information Download Your Information. On Instagram and TikTok, similar tools exist in your account settings. EU and UK residents can also make a formal data subject access request (DSAR) under the GDPR.

2. Adjust your privacy settings. Most platforms bury their strongest privacy controls. Turn off ad personalization, limit location tracking, and restrict third-party data sharing. On Instagram, review which third-party apps have access to your account.

3. Opt out of data selling and sharing (US). California residents can click the “Do Not Sell or Share My Personal Information” link that covered businesses are required to display. The CCPA also requires businesses to honor Global Privacy Control (GPC) signals from web browsers if your browser sends a GPC signal, the business must treat it as a legally binding opt-out.

4. Request deletion of your data. Under the GDPR, UK GDPR, and CCPA, individuals can generally request that a company permanently delete their personal information. Platforms must respond within 30 days (EU/UK) or 45 days (California). There are exceptions for example, when the data is needed for legal compliance or to complete a transaction.

5. File a complaint with a regulator. EU residents can file complaints with their country’s data protection authority. In the UK, complaints go to the ICO. In California, the CPPA accepts complaints through its website. These regulators have the power to investigate and impose fines.

6. Delete your account as a last resort. Closing your social media account terminates the platform’s license to use your content (though shared copies may persist). As of January 2026, California law requires social media platforms with over $100 million in annual revenue to provide a clear, visible “Delete Account” button in their settings.

Tools That Can Help

If you want to take control of your personal data beyond individual platform settings, these tools can help:

DeleteMe A paid service that submits data removal requests to major data brokers on your behalf and monitors for your information reappearing. Useful for removing personal details that social media platforms have shared with third-party data brokers.

Incogni A similar data removal service that contacts data brokers to request deletion of your personal information. Incogni automates follow-up requests and provides regular reports on which brokers held your data and the status of removal requests.

Related Articles

Frequently Asked Questions

Does Instagram have the right to use my photos?

Instagram does not own your photos you keep the copyright. But by posting, you grant Instagram a broad, royalty-free, worldwide license to use, modify, distribute, and create derivative works of your content. This includes using your images for AI training, promotional features, and allowing third-party resharing. That license ends when you delete the content or close your account, though copies already shared by others may remain.

Can TikTok share my data with the Chinese government?

TikTok says it has never received a request for European or American user data from Chinese authorities and has never provided such data. However, Chinese laws including the Cybersecurity Law and National Intelligence Law give the Chinese government broad authority to compel companies operating in China to hand over data. In May 2025, the EU fined TikTok €530 million for failing to prove that European users’ data was adequately protected from potential Chinese government access. In the US, a new joint venture arrangement now places US user data under American-owned infrastructure managed by Oracle.

What rights do I have when I accept terms of service?

Accepting a platform’s terms of service does not eliminate your legal rights. In the EU and UK, the GDPR protects your right to access, delete, and port your data regardless of what the terms say. In California, the CCPA gives residents the right to opt out of data selling and sharing and businesses cannot require consumers to waive these rights. A contract clause that says you give up your CCPA rights is unenforceable under California law.

Can I get my data back from social media platforms?

Yes. Under the GDPR (EU and UK), individuals have the right to data portability platforms must provide a copy of your data in a commonly used, machine-readable format. Under the CCPA (California), individuals have the right to know platforms must disclose the specific pieces of personal information collected over the past 12 months. Every major platform provides a data download tool in account settings. EU and UK residents can also make a formal data subject access request if they want a more complete picture of what a company holds.

Understanding your social media data privacy rights as a user is the first step toward protecting your information. The legal landscape is uneven EU residents have the strongest protections under the GDPR, California residents have meaningful rights under the CCPA, and UK residents sit somewhere in between as reforms reshape their framework. But regardless of where you live, the tools to check, limit, and delete your data from social media platforms exist. The key is knowing they’re there and using them.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Social media data privacy rights users guide  hield protecting phone data with US, EU, and UK legal coverage

Sources & Further Reading

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.