How businesses can assess Meta's AI training data opt-out

person at a desk reviewing a laptop screen with a thoughtful expression, natural light
TL;DR

Meta is using public UK Facebook and Instagram posts to train its AI under legitimate interests in UK GDPR, not with explicit consent. The opt-out is individual and per-account. For a UK services firm, the proportionate response is to map social media exposure, submit objections for priority accounts, update your data protection records, and tighten posting policies for staff.

Key takeaways

- Meta is training AI on public UK Facebook and Instagram content from adults under legitimate interests in UK GDPR. The ICO has confirmed it is monitoring the rollout. - The opt-out is an individual objection form submitted per account. There is no organisational switch a business can use to cover all staff or all Page content at once. - Priority accounts for objection are those that regularly post identifiable clients, regulated information, or special-category data such as health or financial detail. - Update your Record of Processing Activities to reflect that social media platforms may access public content for AI training, and run a short DPIA if your feeds feature identifiable individuals. - Objecting does not remove content from prior AI training. Deleting sensitive historic posts reduces future exposure but does not undo training that has already occurred.

A notification appears in your Facebook feed. Meta will use your public posts to train its AI. Near the bottom, a hyperlinked word: “object”. You click through, fill in a form, and wonder whether that settles it.

For a UK services firm that relies on social media to reach clients, it rarely does. The opt-out is individual, per-account, and not unconditional. The useful work is understanding what is actually in scope, what objecting achieves, and what your data protection records should reflect.

What is Meta’s AI training data opt-out?

Meta is using public content from Facebook and Instagram posted by UK adults to train its generative AI models. It is relying on “legitimate interests” under UK GDPR as its legal basis rather than seeking explicit consent. An objection form is available for UK and European users, but the process is per-account, not organisation-wide, and Meta retains discretion over whether to honour each submission.

Meta’s current UK rollout follows a pause in mid-2024, when the Information Commissioner’s Office intervened over an earlier version of the plan. The ICO has confirmed it is monitoring Meta’s approach as notifications reach UK users. The equivalent EU rollout was halted entirely after the European Data Protection Board objected.

Privacy lawyers have questioned whether “legitimate interests” can sustain this use. In July 2023, the Court of Justice of the European Union ruled in Case C-252/21 that Meta could not rely on the same basis for behavioural advertising. That ruling creates a context in which AI training claims may face similar scrutiny from regulators and courts.

In practice, the objection process works as follows: UK users see an in-app notice and click the word “object”, which opens a pre-filled form. Since the ICO’s intervention, providing an explanation of how the processing affects them is now optional rather than mandatory. Meta says it will review each submission, but that review is discretionary rather than an unconditional opt-out.

Why does this matter for a UK services firm?

The content your firm publishes on social media, and the content your staff post under their own names when it references work, often includes information that is personal under UK GDPR. Client images, staff photos at a site visit, tagged testimonials, and location data from project posts are all potentially in scope. In sectors with regulatory obligations, the exposure is more significant still.

Ofcom’s 2023 research found that 71% of UK adults use Facebook and 49% use Instagram. For services firms, these platforms are often a primary channel for referral marketing, case-study visibility, and community presence. Withdrawing entirely is rarely commercially viable, which is why the workable strategy is reducing the sensitivity of what gets posted rather than exiting the platforms.

There are also client relationship considerations. Someone who gave consent to appear in a social post consented to that use. Their agreement does not automatically extend to AI training by a third party. If a client later discovers their image or story contributed to a commercial AI model, and your firm had the means to object and did not, the conversation is harder to have.

For firms in regulated sectors, FCA social media guidance and similar regulatory frameworks layer additional record-keeping obligations on top of GDPR. The question of what is posted publicly, and why, is already governed. Meta’s AI training adds one more reason to document the answers clearly.

Where will you actually encounter this?

Exposure comes through three channels. Your firm’s Facebook Page and Instagram Business account are the most visible: public posts, comments, and tagged images are in scope. Staff personal profiles are equally significant, because a public post by an employee referencing a client, showing a work site, or tagging colleagues is in scope even if the business did not publish it. Meta’s in-app AI features are the third route.

Meta has stated it does not use private messages or content from accounts set to restricted privacy for AI training. The difficulty is that many businesses set their Page content to public by default, and many staff operate personal profiles in public mode for professional visibility.

The in-app AI feature exposure is worth noting separately. If your team uses Meta’s AI assistant inside Messenger, Instagram, or WhatsApp Business, those interactions are governed by a broader data policy than standard published posts. The NCSC’s guidance on AI security recommends treating third-party AI tools as supply-chain components, which means asking what data is retained, for how long, and for what purposes.

A one-page inventory is a useful starting point: list your firm’s social accounts, their visibility settings, and the typical content type for each.

When should you act, and when can you hold off?

Act promptly when your feeds regularly feature identifiable individuals, particularly clients, or anything touching special-category data such as health information, ethnicity, or financial detail. If the ICO or a client ever questions how their data was handled, a documented assessment and timely objection submission puts you in a much stronger position than having no record of having considered the issue.

Prioritise accounts carrying the most sensitive content. That means owners and directors whose personal profiles are closely linked to the business brand, staff in regulated roles, and corporate accounts that routinely post identifiable client content or location data.

For each priority account, the practical steps are brief. Log in and follow the in-app notice to the “object” link, or use Meta’s web form directly. Complete the form and save a screenshot or PDF as a record. Calendar a follow-up in 30 to 60 days to confirm Meta’s response.

Under UK GDPR Article 21, individuals have a statutory right to object to processing based on legitimate interests, and the controller must stop unless it can demonstrate compelling grounds. If Meta declines an objection without satisfactory explanation, that outcome can be raised with the ICO.

One firm boundary to note: objecting does not undo prior AI training. The effect is on future use only. If older posts contain particularly sensitive material, deleting them is a prudent additional step, separate from the opt-out process.

What other data protection obligations connect to this?

Meta’s AI training sits within a broader UK GDPR obligation you already carry: keeping records that reflect how personal data flows through the platforms you use. Your Record of Processing Activities should note that public social media content is accessible to platform providers for their own purposes, including AI training. If your feeds regularly feature identifiable individuals, a short DPIA using the ICO’s free template is the proportionate next step.

Your privacy notice should tell clients and staff that social media platforms may use publicly visible content for their own purposes under their published terms. A short additional line in your existing customer privacy notice handles this. Staff social media policy should discourage employees from posting identifiable client detail or internal images without explicit permission.

Two further angles are worth keeping in mind. The CMA’s 2023 foundation model review flagged concerns that a small number of large platforms are accumulating data advantages that could affect market competition over time. For a services firm, content you post publicly may eventually contribute to AI models operating in your market. The useful guard is to keep proprietary client insight and commercially sensitive detail off public posts.

The NCSC recommendation to treat AI-enabled platforms as supply-chain components applies here too. A brief supplier assessment covering what Meta processes, under what legal basis, and what controls you apply is a proportionate, documented response that also strengthens your position with insurers if coverage questions ever arise.

Sources

- ICO (2024). Guide to the UK General Data Protection Regulation (UK GDPR). Authoritative reference on legitimate interests as a lawful basis and individuals' rights to object under Article 21. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-uk-gdpr - ICO (2024). AI and data protection risk toolkit. ICO guidance on managing risk when personal data is used in AI systems, including by third-party platforms. https://ico.org.uk/for-organisations/ai/ai-and-data-protection-risk-toolkit - ICO (2024). DPIA template for UK organisations. Free template enabling SMEs to document data protection impact assessments for higher-risk processing activities. https://ico.org.uk/media/for-organisations/documents/2258461/dpia-template.docx - ICO (2024). Data controllers and data processors: what the difference is and what the governance implications are. Explains Meta's status as an independent controller for AI training purposes, distinct from a processor for business Pages. https://ico.org.uk/for-organisations/guide-to-data-protection/key-dp-themes/controllers-and-processors - Court of Justice of the European Union (2023). Case C-252/21, Meta Platforms v Bundeskartellamt. Ruling that Meta could not rely on legitimate interests for behavioural advertising, creating relevant precedent for AI training legal basis questions. https://curia.europa.eu/juris/liste.jsf?num=C-252/21 - Competition and Markets Authority (2023). AI foundation models: initial report. CMA assessment of how large platform data advantages may distort AI market competition over time. https://www.gov.uk/government/publications/ai-foundation-models-initial-report - National Cyber Security Centre (2023). The security of AI systems. NCSC guidance recommending organisations treat third-party AI providers as supply-chain components requiring basic risk assessment. https://www.ncsc.gov.uk/whitepaper/security-of-ai-systems - Ofcom (2023). Online Nation 2023. Annual research finding 71% of UK adults use Facebook and 49% use Instagram, establishing the commercial dependency context for UK SMEs. https://www.ofcom.org.uk/research-and-data/media-literacy-research/online-nation - TechCrunch (2024). Hey, UK! Here's how to opt out of Meta using your Facebook and Instagram data to train its AI. Walkthrough of Meta's UK objection process, including the ICO's intervention on the mandatory-explanation requirement. https://techcrunch.com/2024/10/03/hey-uk-heres-how-to-opt-out-of-meta-using-your-facebook-and-instagram-data-to-train-its-ai - Euronews Next (2025). Meta is about to use Europeans' social posts to train its AI. Documents Meta's EU rollout pause and the objection deadline before training commenced. https://www.euronews.com/next/2025/05/13/meta-is-about-to-use-europeans-social-posts-to-train-its-ai-heres-how-you-can-prevent-it

Frequently asked questions

Does my firm have a legal right to stop Meta using our social posts for AI training?

Under UK GDPR Article 21, individuals have a right to object to processing based on legitimate interests. Meta has provided an objection form for UK users, but it is per-account, not organisational, and Meta retains discretion over outcomes. Your firm cannot submit a blanket organisational objection. The practical route is to submit individual objections for accounts carrying sensitive content and document each submission.

What happens to content Meta has already trained on if we object now?

Objecting does not undo prior AI training. Meta will not retrain existing models to remove data already used. The value of objecting is preventing future use. For historic posts containing sensitive material such as client images or location data, deleting those individual posts reduces future indexing risk, though it does not guarantee removal from training sets already collected.

Do we need a DPIA just because we use Facebook for marketing?

A DPIA is formally required under UK GDPR where processing is likely to result in high risk. For firms posting generic content with no identifiable individuals or special-category data, a brief documented risk consideration is typically sufficient. Where your feeds regularly feature identifiable clients, staff in sensitive contexts, or anything touching health or financial data, a short DPIA using the ICO's free template is the proportionate response.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation