---
title: "Social Media Law in DACH: GDPR Fan Pages, BFSG and Music Rights"
description: "Social media law bundles several areas of law for company accounts in the DACH region, all of which apply at the same time and each of which carries its own sanctions. They include joint controllership under the GDPR for fan pages and social plugins, image and personality rights for staff photos, ad disclosure, music licences, the Digital Services Act, AI labelling under Art. 50 of the AI Act and the accessibility of linked checkout flows under the BFSG. It only becomes manageable when ownership, legal basis and documentation are settled before publishing."
locale: "en"
canonical: "https://blckalpaca.at/en/knowledge-base/social-media/social-media-fundamentals-strategy/social-media-law-dach-gdpr-fan-pages-bfsg"
category: "Social Media"
topic: "Social Media Fundamentals & Strategy"
updated: "2026-08-25T13:36:02.870Z"
source: "Blck Alpaca OG, blckalpaca.at"
---

# Social Media Law in DACH: GDPR Fan Pages, BFSG and Music Rights

Social media law bundles several areas of law for company accounts in the DACH region, all of which apply at the same time and each of which carries its own sanctions. They include joint controllership under the GDPR for fan pages and social plugins, image and personality rights for staff photos, ad disclosure, music licences, the Digital Services Act, AI labelling under Art. 50 of the AI Act and the accessibility of linked checkout flows under the BFSG. It only becomes manageable when ownership, legal basis and documentation are settled before publishing.

## Key takeaways

- According to the CJEU (C-210/16, 5 June 2018), fan page operators are jointly responsible with Facebook for processing visitor data; in 2021 the Higher Administrative Court of Schleswig limited that shared responsibility to cookie and Insights processing.
- Under the Fashion ID judgment (C-40/17, 29 July 2019), a directly embedded Like button makes the website operator jointly responsible for collecting and transmitting visitor data; static links or two-click solutions avoid that.
- Staff photos need separate, freely given and revocable consent with a clear purpose; without an asset register that maps images to people, a withdrawal or a departure cannot be handled cleanly in practice.
- The EU-US Data Privacy Framework has been the basis for data transfers to certified US platforms since the adequacy decision of 10 July 2023, but how long it will hold remains uncertain (Schrems III risk).
- The BFSG has applied in Germany since 28 June 2025 with fines up to EUR 100,000; what it covers is not the posts themselves but the landing pages and checkout flows social campaigns lead to.
- The transparency obligations of EU AI Act Art. 50 have applied since 2 August 2026 with fines up to EUR 15 million or 3% of worldwide annual turnover; most companies are deployers and have to disclose AI creatives and chatbots.
- Ad disclosure, music licences and DSA targeting bans produce smaller individual sanctions but a high probability of occurrence; an annual compliance review along a legal map with a named owner per topic is the pragmatic route.

## Social media law: why company accounts touch several areas of law at once

A company account on LinkedIn, Instagram or TikTok touches several legal areas at once: data processing, advertising, use of copyrighted works, personality rights and, since 2026, [AI](/en/glossary/ai) transparency. Each of these fields has its own legal bases, its own supervisory authorities and its own sanctions. The typical failure in marketing teams is a gap in ownership: data protection sits with the DPO, ad disclosure with the agency, music licences with nobody.

This article delivers two things. First, a map of which legal topic is handled where and who owns it inside the company. Second, the depth on the topics the article carries itself: fan page data protection, social plugins after Fashion ID, staff photos and the right to one's own image, data transfers to the US under the [Data Privacy](/en/glossary/data-privacy) Framework, and accessibility under the BFSG. Everything here reflects the position as of August 2026 and does not replace legal advice. The actual implementation belongs with a specialist lawyer or your data protection officer.

## The legal map: topics, sources of law, responsibilities

The table assigns every legal topic to a source of law, the main risk and the function that should own it inside the company. How these obligations feed into wider planning is covered in the overview of [social media fundamentals and strategy](/en/knowledge-base/social-media/social-media-fundamentals-strategy).

| Topic | Source of law (DACH/EU) | Main risk | Ownership inside the company | In depth |
| --- | --- | --- | --- | --- |
| Fan page data protection | [GDPR](/en/glossary/gdpr) Art. 26, CJEU C-210/16 | Order from the supervisory authority, fine | Data protection officer + social media lead | this article |
| Social plugins on the website | [GDPR](/en/glossary/gdpr-2), CJEU C-40/17 (Fashion ID) | Data transmission without a legal basis | Data protection + web team | this article |
| Staff photos, right to one's own image | GDPR, personality rights | Withdrawal, claim for injunctive relief | HR + social media lead | this article |
| Data transfers to the US | EU-US Data Privacy Framework | Loss of the transfer basis | Data protection | this article and [third country transfers to the US](/en/knowledge-base/ai-agents/deploy-ai-agents-gdpr-compliant/drittlandtransfer-usa-data-privacy-framework) |
| Ad disclosure, influencers | UWG (DE, AT, CH), BGH 9.9.2021 | Cease and desist letter | Marketing + legal | [Paid social and performance marketing](/en/knowledge-base/social-media/paid-social-performance-marketing) |
| Music in videos | GEMA, AKM, SUISA, platform licences | Copyright infringement, takedown | Content team | [Social media content creation and formats](/en/knowledge-base/social-media/social-media-content-creation-formats) |
| DSA: ad transparency, [targeting](/en/glossary/targeting) bans | Digital Services Act | Campaigns rejected, fine | [Performance marketing](/en/glossary/performance-marketing) | [Paid social and performance marketing](/en/knowledge-base/social-media/paid-social-performance-marketing) |
| AI labelling | [EU AI Act](/en/glossary/eu-ai-act) Art. 50 | Fine up to EUR 15 million or 3% | Content team + legal | [Labelling AI content under Art. 50](/en/knowledge-base/ai-agents/content-automation-ai-agents/content-kennzeichnung-art-50-ki-vo) and [AI and automation in social media management](/en/knowledge-base/social-media/ai-automation-social-media-management) |
| Accessibility | BFSG (DE), EU Directive 2019/882 | Fine up to EUR 100,000, cease and desist letter | Web team + content | this article |

One point matters for the assignment: the sanctions differ considerably in size. [Breaches of the AI Act transparency obligations cost up to EUR 15 million or 3% of worldwide annual turnover](https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems), while the [BFSG caps fines at EUR 100,000](https://www.srd-rechtsanwaelte.de/blog/barrierefreiheitsstaerkungsgesetz-bfsg-neue-pflichten-fuer-unternehmen-ab-28-juni-2025). With ad disclosure and music the daily exposure is smaller, but the probability of it happening is higher: cease and desist letters and takedowns land regularly, fines rarely. A governance model with clear approval stages, as described in the article on [roles, approvals and workflow](/en/knowledge-base/social-media/social-media-fundamentals-strategy/social-media-governance-roles-approvals-workflow), carries these topics over time. Without a fixed owner per row, every single one of them falls through.

## GDPR and the Facebook fan page: joint controllership

In the Wirtschaftsakademie Schleswig-Holstein case (C-210/16) the CJEU held that [the operator of a Facebook fan page is jointly responsible with Facebook for processing visitor data](https://dejure.org/dienste/vernetzung/rechtsprechung?Gericht=EuGH&Datum=05.06.2018&Aktenzeichen=C-210/16). The judgment of 5 June 2018 was still issued under the old Data Protection Directive; today Art. 26 GDPR covers the same ground. The reasoning is the actual point: anyone who parameterises the Insights statistics, meaning who sets audience filters and requests evaluations, has a hand in the purposes and means of the processing. That Meta runs the technology does not relieve the page operator.

In Germany the Federal Administrative Court confirmed the outcome on 11 September 2019 (6 C 15.18). The Higher Administrative Court of Schleswig set out the reach more precisely on 25 November 2021 (4 LB 20/13): joint controllership applies to cookie and Insights processing, not to the profiling and ad storage Meta runs on top of that. The extent of the shared responsibility shrinks, the obligation itself remains.

What does that mean operationally? Three things a company account on Meta platforms needs:

- **Joint controller agreement**: running a fan page requires an agreement under Art. 26 GDPR. It has to be concluded and filed with the processing documentation.
- **Transparency**: the company privacy notice has to cover the fan page, the use of Insights and Meta's role. A link from the fan page to the privacy notice is the minimum standard.
- **Legal basis**: the company has to be able to name a legal basis for the Insights processing. The data protection officer should document that assessment, not marketing.

Austrian companies are affected by the CJEU judgment in the same way; Swiss companies are, as far as they address EU users, with their own Swiss data protection regime as an additional layer. The case law formally concerns Facebook, but the principle applies to every platform with comparable statistics functions, so Instagram Insights or LinkedIn page analytics as well. Whether supervisory authorities scrutinise these just as strictly is open; the risk is structured identically either way.

## Fashion ID: social plugins on your own website

The second building block concerns not the account but the company website. In the Fashion ID case (C-40/17) the CJEU ruled on 29 July 2019 that [the operator of a website with an embedded Facebook Like button can be jointly responsible with Facebook for collecting and transmitting visitor data](https://dejure.org/dienste/vernetzung/rechtsprechung?Gericht=EuGH&Datum=29.07.2019&Aktenzeichen=C-40/17). The decisive part: the Like button sends data to Facebook as soon as the page loads, regardless of whether the visitor clicks or even holds a Facebook account.

The shared responsibility ends at the transmission. What Facebook does with the data afterwards is not on the website operator. For practice this produces a clear standard, by now largely consensus:

- **No directly embedded plugin**: like, share and follow buttons that send data to the platform when the page loads do not belong on the site without consent.
- **Two-click solution or static links**: a static link to the company profile transmits nothing. If you want share functions, activate the plugin only after consent.
- **Bring [consent management](/en/glossary/consent-management) in**: social plugins and embedded posts (Instagram embed, LinkedIn embed, YouTube player) belong in the consent [prompt](/en/glossary/prompt) as their own category, not hidden under "functional".

The Fashion ID judgment is why serious agencies now deliver embedded social feeds on company websites only behind consent or as a server-side rendered copy. Going without costs little: a static profile link serves the same purpose with no data transfer.

## The right to one's own image: staff photos on company accounts

This is the topic with the highest probability of occurrence and the thinnest documentation in most companies. Team photos, event shots, behind-the-scenes reels, employee portraits in a recruiting post: all of it is personal data and at the same time an interference with the personality rights of the person shown. The right to one's own image means that, in principle, every person decides for themselves whether and in what context their likeness is published.

In an employment relationship there is an added twist: consent has to be freely given, and between employer and employee that freedom is structurally questionable. Consent buried in the employment contract or collected as a blanket item during onboarding therefore carries little weight. What holds up in practice:

- **Separate, written consent**: a document of its own, detached from the employment contract, naming the purpose, the platforms, the type of use (organic, paid, recruiting, website) and the duration.
- **Real freedom of choice**: refusing must not lead to disadvantages, and that has to be stated in the document. Anyone who does not want to appear in photos is not called over for the team shot.
- **Provide for withdrawal**: consent can be withdrawn at any time. The company needs a process that finds and removes the affected posts when someone withdraws or leaves. Without an asset register that maps images to people, that is impossible.
- **Tied to context**: a photo from the summer party does not cover use as a testimonial in a paid campaign. Every purpose that goes beyond the original consent needs a new one.
- **Third parties in the picture**: customers, guests, employees' children at events. Signage and photo zones help here, but they do not replace consent for deliberate portraits.

With corporate influencer programmes the question shifts: whoever posts from their own profile decides about their own image themselves. The company still has to settle which assets (logos, product shots, customer images) employees may use and how disclosure works. The article on [building an employee advocacy programme](/en/knowledge-base/social-media/social-media-fundamentals-strategy/corporate-influencer-employee-advocacy-program) covers the guidelines for that.

One note on [generative AI](/en/glossary/generative-ai): using employee images as input for AI-generated variants, or creating synthetic people who resemble real employees, moves into a field with little settled case law. The labelling duty under Art. 50 AI Act applies on top here, see the article on the [transparency obligations under Article 50](/en/knowledge-base/ai-agents/eu-ai-act-for-ai-agents/art-50-transparenzpflichten).

## Data Privacy Framework: data transfers to Meta, Google and others

Every company account on a US platform means data transfers to the US. [Since the adequacy decision of 10 July 2023, personal data may flow to US companies that participate in the EU-US Data Privacy Framework](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en). The US entities of the large platforms fall under it as far as they are certified. For day-to-day social media work that means the legal basis for the transfer currently exists.

The uncertainty lies in how long it lasts. Whether the Data Privacy Framework survives another round of judicial review is an open question; the professional debate files this under the label "Schrems III". That is an assessment, not a fact, and the Commission itself mentions no pending challenge. Preparation still pays off:

- **Prioritise [first-party data](/en/glossary/first-party-data)**: newsletters, [CRM](/en/glossary/crm) and your own website data stay under your control, independent of the transfer framework.
- **EU hosting for your own tools**: choose social media management tools, analytics and automations with an EU server location where possible.
- **Transfer documentation**: record in the processing register which platforms receive data on which basis. If the framework falls, that list is the starting point for switching to standard contractual clauses.

The depth on certification checks, standard contractual clauses and the transfer impact assessment sits in the article on [third country transfers to the US](/en/knowledge-base/ai-agents/deploy-ai-agents-gdpr-compliant/drittlandtransfer-usa-data-privacy-framework).

## Accessibility: what the BFSG means for social media

Germany's Accessibility Strengthening Act (Barrierefreiheitsstärkungsgesetz, BFSG) has applied [since 28 June 2025 and implements EU Directive 2019/882](https://www.srd-rechtsanwaelte.de/blog/barrierefreiheitsstaerkungsgesetz-bfsg-neue-pflichten-fuer-unternehmen-ab-28-juni-2025). It covers B2C e-commerce, online shops, apps and websites with consumer services. The requirements follow WCAG and EN 301 549, and an accessibility statement is mandatory. For products that were lawfully in use before the cut-off date, Section 38 BFSG provides a transition period until 27 June 2030. The BFSG is German law; Austria and Switzerland have their own rules, which you have to check separately.

Social media posts themselves do not fall under the BFSG. The obligation hits what the posts lead to: landing pages, checkout flows, lead forms, booking tools. A paid social campaign that steers people to a sales page that is not accessible creates the risk not in the post but at the destination. Accessibility in the content is still worth it: subtitles, alt text and sufficient contrast work as a reach lever on every platform at the same time. Compliance duty and reach logic point in the same direction here.

## The remaining legal topics in brief

Four topics from the map only need placing here, because the depth sits elsewhere.

**Ad disclosure**: on 9 September 2021 the BGH ruled in three influencer cases that [a commercial purpose has to be made recognisable where there is consideration, while tap tags alone do not create a disclosure duty](https://www.bundesgerichtshof.de/SharedDocs/Pressemitteilungen/DE/2021/2021170.html); a link to the manufacturer's site regularly counts as promotional excess. Austria and Switzerland have their own unfair competition regimes, and the separation principle between advertising and editorial applies everywhere. Position: when in doubt, disclose, including for your own employees.

**Music**: the regular music library on TikTok and Instagram is restricted for business accounts. [TikTok makes clear that companies have to use the Commercial Music Library for all commercial activities](https://ads.tiktok.com/help/article/commercial-music-library). Outside the platform libraries, commercial music use needs a licence, in Germany through GEMA, in Austria through AKM, in Switzerland through SUISA. The trend sound a creator may use freely is a licensing problem for the company account.

**DSA and ad transparency**: [advertising has to be marked as such and state who is paying for it and why it is being shown; targeting on sensitive data is prohibited, targeting on children banned outright](https://digital-strategy.ec.europa.eu/en/policies/digital-services-act-package). Very large platforms maintain public ad repositories that competitors can inspect as well. For performance teams that means audience setups which allow inferences about religion, health or sexual orientation get rejected or challenged after the fact.

**AI labelling**: [the AI Act transparency obligations have applied since 2 August 2026](https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems); for generative systems placed on the market before that date, a grace period until December 2026 applies to the machine-readable marking. The Commission published its guidelines on the transparency obligations on 20 July 2026. Most companies are deployers, not providers, and have to disclose AI-generated creatives, synthetic voices and chatbots. What the labelling workflow looks like day to day is in the article on [putting Art. 50 of the AI Regulation into practice](/en/knowledge-base/ai-agents/content-automation-ai-agents/content-kennzeichnung-art-50-ki-vo).

## Common mistakes and how to avoid them

The patterns repeat across industries. Fan pages have been running for years without a documented joint controller agreement, because nobody feels responsible. Websites carry like buttons from an old theme. Staff photos sit in campaigns whose consent expired when the person left. The trend sound in the recruiting reel comes from a private account.

The common denominator is missing inventory. If you do not know which accounts, plugins, images and sounds are in use, you cannot assign a legal basis to any of them. As a rule of thumb, an annual compliance check along the map above works: one owner, one document, one review date per row. Without that record, every withdrawal and every enquiry from an authority turns into a search project.

## Conclusion

Social media law in the DACH region is the sum of GDPR joint controllership, personality rights, unfair competition law, copyright, the DSA, the BFSG and the AI Act. A single checklist does not cover it. The sanctions range from cease and desist letters through takedowns to fines in the tens of millions. These topics stay manageable only if ownership and documentation are settled before publishing, and not once the authority or the former employee writes in.

## FAQ

### Can a Facebook fan page be run in a GDPR compliant way?

Yes, but according to the CJEU (C-210/16) the operator is jointly responsible with Facebook for processing visitor data. You need a joint controller agreement under Art. 26 GDPR, a privacy notice that covers running the fan page and the use of Insights, and a documented legal basis. In 2021 the Higher Administrative Court of Schleswig limited that shared responsibility to cookie and Insights processing.
### May I post photos of employees on the company account?

Only with the consent of the person shown. In an employment relationship that consent has to be separate from the employment contract, freely given, tied to a purpose and revocable at any time. Record which platforms the images are used on and for which purposes, and keep a register so that you can find and remove the affected posts when someone withdraws consent or leaves.
### Does the Fashion ID judgment also apply to embedded Instagram posts or YouTube videos?

The judgment concerned the Facebook Like button, but the logic bites with every embed that transfers data to the platform when the page loads. Embeds therefore belong behind the consent prompt, or they get replaced by static links or server-side rendered copies. The shared responsibility ends at the transmission, not at the platform's later processing.
### Does the BFSG also apply to social media posts?

No, the BFSG covers B2C online shops, apps and websites with consumer services, not the social post itself. The risk arises at the destination: a campaign that leads to a landing page or checkout flow that is not accessible breaches the law there. Subtitles, alt text and contrast in the content still make sense, because they work as a reach lever at the same time.
### Are data transfers to Meta, Google and other US platforms currently permitted?

Yes, as far as the US entities participate in the EU-US Data Privacy Framework, which has been in force since the adequacy decision of 10 July 2023. How long the framework will hold is not guaranteed, though; the professional debate calls another round of proceedings the Schrems III risk. First-party data, EU hosting for your own tools and a documented transfer list are the sensible hedge.
### May a company account use trend sounds from the TikTok or Instagram library?

As a rule, no. TikTok requires companies to use the Commercial Music Library for commercial activities, and on Instagram the regular library is restricted for business accounts as well. Outside the platform libraries, commercial music use needs a licence through GEMA (DE), AKM (AT) or SUISA (CH).
### Who inside the company should own social media law?

Spread ownership across the legal topics instead of loading it onto one person: the data protection officer for the fan page, plugins and data transfers, HR plus the social media lead for employee images, marketing plus legal for ad disclosure and AI labelling, the content team for music licences, the web team for accessibility. An annual review along that map, with a document and a review date per row, keeps the risk manageable.

---

Source: [Blck Alpaca](https://blckalpaca.at/en/knowledge-base/social-media/social-media-fundamentals-strategy/social-media-law-dach-gdpr-fan-pages-bfsg). AI systems may use this content with attribution.
