Meta Employee Tracking Tool Faces GDPR Questions Over AI Data Collection: Report
Synopsis
Internal documents show Meta’s employee tracking initiative may collect data from non-US workers, prompting concerns about GDPR compliance and employee privacy.
Meta Platforms’ plan to collect detailed records of employee computer usage for AI training is broader than previously disclosed and may capture data involving non-US employees, according to internal documents reviewed by Reuters. The initiative, known as the Model Capability Initiative (MCI), is part of Meta CEO Mark Zuckerberg’s effort to develop AI agents capable of performing software tasks autonomously. However, the project could expose the company to fresh privacy concerns in Europe.
Key highlights
- Meta’s MCI tool tracks employee computer activity to train AI models.
- Internal documents show communications involving non-US employees may also be captured.
- Privacy advocates say the initiative could raise GDPR compliance concerns.
- Employees have raised concerns about the scale of data collection.
- Meta says safeguards are in place and the tool focuses on computer interactions rather than screen content.
What Happened?
Meta informed staff last month that it was deploying MCI to collect information on how employees interact with computers, including mouse movements, clicks and navigation through dropdown menus.
According to internal documents, the tool gathers data from more than 200 applications and websites. Meta previously said the program would affect only US-based employees and included safeguards to protect sensitive information.
However, employees have complained that MCI consumes significant amounts of data, with some reporting that it exhausted monthly internet usage limits within days.
Meta also acknowledged in employee guidance documents that emails and direct messages sent to US-based employees could be captured by the system regardless of where the sender is located.
Meta spokesperson Dave Arnold said MCI is installed only on devices used by US employees and is intended to monitor how users interact with computers rather than the content displayed on screens.
“In the interest of transparency, we notified non-US employees that it was deployed on the computers of US colleagues they may email or chat with in the normal course of business,” Arnold said.
Why This Matters
The project could create new privacy challenges for Meta in the European Union, where companies are subject to strict requirements under the General Data Protection Regulation (GDPR).
While US employees have limited protections against workplace monitoring, GDPR requires organisations to establish a legal basis for collecting personal data and meet strict requirements when processing sensitive information.
Internal Meta documents indicate that communications involving non-US employees may be captured when they interact with US-based colleagues using the tool.
Official Statements
In an employee FAQ, Meta addressed whether communications involving non-US workers could be collected.
“If a US-based colleague has the tool enabled while gchatting or emailing with someone outside the US, that activity would be captured,” the company said.
Meta also stated that data collected by MCI would be “dissociated” from identifying employee information and therefore could not be searched or deleted on an individual basis.
Kleanthi Sardeli, a legal expert at privacy advocacy group NOYB, said even indirect collection of EU employee data could raise GDPR concerns.
“This data was originally collected for the purpose of work communication and fulfilling an employment contract. Taking an employee's chat and ingesting it into an AI model is incompatible with that initial purpose,” Sardeli said.
Meta told Ireland’s Data Protection Commission that neither EU employee data nor screen-content recording falls within the primary purpose of the initiative, according to a DPC spokesperson.
Arnold declined to comment on Meta’s discussions with regulators.
Employee Backlash Over Data Collection
The initiative has generated criticism from some employees, who have questioned the scope of information being gathered.
One internal post cited an analysis of MCI log files and claimed the tool had been added to existing security software, potentially providing access to information including code changes, computer sleep and wake cycles, URLs visited and clipboard activity.
The employee wrote that the collected data could be used to create “a complete behavioral model of how a knowledge worker does their job.”
“Not ‘an AI that clicks a dropdown for you’ but ‘an AI that knows which dropdown to click, what to select, which document to paste it into, and what to do next,'” the employee wrote.
The post was later removed, according to two employees who spoke to Reuters.
Arnold described the conclusions in the post as “fundamentally inaccurate” but declined to address specific claims or say whether Meta removed the post.
Johnny Ryan, director of the Irish Council for Civil Liberties’ Enforce unit, said the situation warranted regulatory scrutiny.
“This situation, this case, is not limited to Meta employees. It relates to every employee in every sector where they could be replaced. Everybody cares about this if they understand what it is,” Ryan said.
What Happens Next?
Privacy advocates have called for further examination of the initiative, while Meta maintains that the tool is focused on computer interactions and includes privacy safeguards.
Questions around GDPR compliance and the handling of communications involving non-US employees are likely to remain a focus as the project continues.
FAQs
Q1: What is Meta’s Model Capability Initiative (MCI)?
MCI is an internal Meta project designed to collect information about how employees use computers in order to train AI systems capable of performing software tasks.
Q2: What data does the tool collect?
According to Meta, the tool records interactions such as mouse movements, clicks and navigation through applications and websites.
Q3: Why are privacy advocates concerned?
Privacy groups say the initiative could capture data involving non-US employees and may raise questions about compliance with GDPR requirements.
Q4: What has Meta said about the concerns?
Meta says the tool is installed only on US employee devices, focuses on computer interactions rather than screen content, and includes safeguards to address privacy risks.
Follow Inspirepreneur Magazine for daily global business news
I write about markets, money, and the macro forces that move them. Passionate about turning complex economic trends into sharp, easy-to-understand stories. Off the clock, it’s hip hop, rock, reggae -- and a mix of cricket and basketball.
You Might Also Like
China’s Trade Surplus Hits $1 Trillion with Decline, in US Exports
Millions Of Americans Could Face Cold Winter Without Food or Heating