The Privacy Trap Hidden Behind “Facebook Handles It”
You create a Facebook Page because you want customers to find your business.
You add your logo, services, opening hours and contact details. Facebook hosts everything. Facebook handles the technology. Facebook provides the statistics.
So it is easy to think:
“Facebook collects the data, so Facebook deals with the privacy responsibilities.”
That sounds reasonable.
Unfortunately, privacy law does not always work that way.
The key question is not simply:
“Who owns the servers?”
It is:
“Who decided that this data processing should happen, and why?”
If your business chooses to operate a Facebook Page, use Page Insights, install tracking tools on a WordPress website or collect information through online forms, your business may still have responsibilities.
That does not mean you are responsible for everything Meta does.
It means your business cannot outsource every privacy decision just by using someone else’s platform.
Responsibility follows the processing decisions you make—not the logo on the server.
This article explains the issue in plain English, with a focus on Facebook Pages, WordPress websites, analytics and tracking tools.
This is general educational information, not legal advice. Privacy obligations depend on your country, industry, audience, technology and data flows.
The Simple Answer
A Facebook Page can create privacy responsibilities for your business.
A website can create even more direct responsibilities because you choose the forms, plugins, analytics tools, cookies and tracking technologies installed on it.
That does not make Facebook “bad” or a website “automatically compliant”.
It means the two options give you different levels of control and responsibility.
Facebook gives you less technical control
Meta controls much of the platform, its systems and its underlying processing.
You still decide to:
- Create and operate the Page
- Publish content
- Choose your audience
- Promote your business
- Use Page Insights
- Connect certain business tools
- Collect enquiries through the platform
Those decisions may matter legally.
WordPress gives you more control
With WordPress, you can usually choose:
- Which forms to install
- Which information to request
- Which plugins to use
- Which analytics system to connect
- Which tracking scripts load
- Which pages use advertising technology
- How long data is stored
- Which services receive information
That control is valuable.
But it also means you have more decisions to make.
Think of it like this:
Facebook is a managed market where the landlord controls much of the building. WordPress is your own workshop. You have more freedom—but you are also responsible for using the tools safely.
Controller, Joint Controller and Processor: Without the Legal Fog
Privacy law uses technical terms to describe different roles.
The three most common are:
- Controller
- Joint controller
- Processor
Let’s make them less intimidating.
A controller decides the purpose
A controller decides why personal information is being used and important parts of how that use happens.
For example, your business may decide to collect names and email addresses so you can:
- Respond to enquiries
- Arrange appointments
- Send a newsletter
- Process an order
- Improve your marketing
That decision can make your business a controller for that activity.
The organisation does not need to physically hold every piece of data to be a controller.
The European Data Protection Board explains that these roles depend on what the parties actually do—not simply what a contract or platform label says.
Joint controllers share decisions
Two organisations may be joint controllers when they both influence the purpose or essential features of a particular processing activity.
That does not necessarily mean they have equal responsibility.
It also does not mean they are jointly responsible for every single thing the other organisation does.
The relationship must be considered activity by activity.
A processor works on someone else’s instructions
A processor handles personal information on behalf of a controller.
For example, a business may use a provider to store customer records or send emails according to the business’s instructions.
But a provider can have different roles for different services.
The same technology company might be:
- A processor for one service
- An independent controller for another
- A joint controller for a specific shared activity
That is why it is risky to label every third party as “just a processor”.
The Wirtschaftsakademie Case: The Facebook Page That Changed the Conversation
The most important case for this topic is Wirtschaftsakademie Schleswig-Holstein.
Wirtschaftsakademie operated an educational-services Facebook Page. Facebook made Page Insights statistics available to the Page administrator and collected information about visitors through cookies and similar technologies.
The Page administrator argued, in effect, that Facebook was responsible for the data processing because Facebook operated the platform.
The Court of Justice of the European Union disagreed.
In its 2018 judgment, the Court held that the Page administrator could be jointly responsible with Facebook for certain processing connected with visitors and Page Insights.
The reasoning was important because the Page administrator:
- Chose to operate the Page
- Helped define its audience and objectives
- Benefited from Page Insights statistics
- Used the information to understand and improve communications
The Court also made clear that receiving statistics in an anonymised form did not automatically remove the underlying privacy issue.
The personal-data processing that created those statistics still mattered.
What the case does not mean
It does not mean:
- Your business controls everything Facebook does.
- You are responsible for every action Meta takes.
- Facebook Pages are automatically unlawful.
- Every Facebook tool has the same legal arrangement.
- You have exactly 50% of the responsibility.
The case must be understood in relation to the particular processing activity.
The practical lesson is simpler:
Using Facebook does not make your business invisible to privacy law.
What Is Page Insights?
Page Insights is Meta’s reporting system for understanding how people interact with a Facebook Page and its content.
It may help show information such as:
- Content reach
- Page interactions
- Audience trends
- Engagement
- Clicks
- Other Page performance information
The exact metrics and availability can change.
The important point is that Page Insights is not simply a harmless scoreboard floating above Facebook. It is created from information about people interacting with your Page and its content.
Meta maintains a dedicated Page Insights Controller Addendum and an information page about Page Insights data.
Those documents should be checked before publishing or updating your privacy information because Meta’s legal entities, wording and procedures may change.
What should your privacy notice explain?
A business using a Facebook Page should consider explaining:
- That the business operates a Facebook Page
- That Meta processes information about Page interactions
- That Page Insights may be generated
- Why the business uses Insights
- How people can contact the business about privacy
- Where to find Meta’s current information about Page Insights
Avoid saying:
“We receive all your Facebook data.”
That may not be true.
Also avoid saying:
“We only receive anonymous statistics, so privacy law does not apply.”
That is too simplistic and is inconsistent with the reasoning in Wirtschaftsakademie.
A safer explanation is:
“We operate a Facebook Page. Meta processes information about interactions with the Page and may provide Page Insights statistics. We use those statistics to understand engagement and improve our communications. The responsibilities of our business and Meta depend on the particular processing activity.”
That wording is clearer and less likely to overclaim.
Page Insights Is Not the Same as Meta Pixel
This distinction matters.
Businesses sometimes treat every Meta tool as though it has the same legal arrangement.
That is risky.
Page Insights relates to your Facebook Page
It concerns activity connected with the Page and its content inside Meta’s environment.
A Meta Pixel operates on your website
A Pixel or other tracking technology may be installed on your WordPress website to send information to Meta.
Your business may decide:
- Which pages contain the tracking code
- Which events are recorded
- Which buttons count as conversions
- Which audiences are created
- Whether the tool is used for advertising or measurement
- Whether sensitive pages should be excluded
- Whether tracking loads before or after consent
Those decisions create a different data-flow question from Page Insights.
Meta’s Business Tools Terms and Data Processing Terms apply to different products and circumstances.
Do not automatically copy the legal wording for Page Insights into your Pixel or Conversions API setup.
The safe approach is:
Analyse each tool, purpose and data flow separately.

What Happens When WordPress Forms Collect Data?
A WordPress contact form may look simple.
A visitor types in:
- Name
- Email address
- Phone number
- Message
- Booking details
They click “Send”.
But several things may happen next:
- The website receives the form.
- WordPress stores the information in its database.
- An email provider sends a notification.
- A CRM creates a contact record.
- An automation tool adds a tag.
- Analytics records a form event.
- An advertising tool may receive a conversion signal.
- A staff member opens the enquiry.
That is not one single processing activity.
It is a chain of connected activities.
You should know:
- What information is collected
- Why it is needed
- Where it is stored
- Who can access it
- Which providers receive it
- How long it is retained
- When it should be deleted
- Whether it is used for marketing
- Whether the visitor agreed to marketing
An enquiry is not automatically marketing consent
Someone asking for a quote has not necessarily agreed to receive a weekly newsletter.
Someone downloading a guide has not necessarily agreed to receive every future promotion.
Keep the purposes clear.
For example:
“We use the information you provide to respond to your enquiry and manage our communication with you.”
If you also want to send marketing emails, explain that separately and collect the appropriate permission.
Do not quietly turn every contact form into a mailing-list signup.
Cookies, Pixels and Similar Tracking Technologies
Many people still talk about “cookies” as though cookies are the entire issue.
Modern websites may use:
- Cookies
- Tracking pixels
- JavaScript tags
- Web storage
- Fingerprinting
- Embedded tools
- Advertising scripts
- Analytics scripts
- Conversion APIs
The UK’s current guidance from the Information Commissioner’s Office covers storage and access technologies more broadly.
That is why “cookies and similar technologies” is often a more accurate phrase than simply “cookies”.
Necessary technology
Some technologies may be necessary for the website or service to work.
Examples may include:
- Security functions
- Shopping-cart functions
- Session management
- Communication transmission
- Basic requested functionality
But “useful for the business” does not automatically mean “strictly necessary for the visitor”.
A tracking tag that helps you advertise is not automatically necessary just because advertising helps pay the bills.
Analytics technology
The UK position changed during 2025 and 2026.
The Data (Use and Access) Act 2025 amended parts of the UK privacy framework. The ICO’s final guidance now recognises a possible statistical-purpose exception for narrowly configured analytics.
But this does not mean:
“Analytics never needs consent anymore.”
The exception depends on conditions, including:
- The sole purpose of collecting statistics
- Appropriate transparency
- A simple and free way to object
- The technology not being used for wider advertising or profiling purposes
If your analytics tool is combined with:
- Advertising
- Retargeting
- Cross-site tracking
- Audience matching
- Profiling
- Other unrelated purposes
do not assume the statistical exception applies.
Advertising and social tracking
Advertising tracking and cross-site tracking generally require much more careful consent treatment.
The ICO makes clear that advertising is not automatically “strictly necessary”. Social-media tracking technologies and cross-site tracking should not simply be switched on before the required permission is obtained.
A banner that says “Reject” is not enough if the tracking script has already fired before the visitor makes a choice.
That is like putting a “Please do not enter” sign on a door after everyone has already walked through it.
The UK Rule Is Not Automatically the EU Rule
Empire Base serves an international audience.
That means we need to avoid turning UK guidance into a worldwide rulebook.
UK
The UK uses:
- UK GDPR
- Data Protection Act 2018
- PECR
- The amended storage and access rules introduced through the Data (Use and Access) Act 2025
The ICO’s current guidance is particularly relevant for UK businesses.
European Union
EU countries continue to apply the GDPR alongside their national implementation of the ePrivacy framework.
The UK’s statistical-purpose exception should not automatically be copied into:
- France
- Germany
- Ireland
- The Netherlands
- Spain
- Other EU countries
A business serving both UK and EU visitors may need a more conservative or region-specific consent approach.
United States, Canada, Australia and elsewhere
Other countries use different concepts and rules.
For example:
- The United States combines federal, state and sector-specific requirements.
- Canada uses frameworks including PIPEDA and provincial privacy laws.
- Australia uses Australian Privacy Principles and has specific guidance on tracking pixels.
- India uses Data Fiduciary and Data Processor terminology under its evolving framework.
Do not assume that a UK cookie decision automatically answers a question about a visitor in another country.
If your business serves several countries, map the markets you actively target.

How to Audit Your Website’s Data Flows
A privacy policy is important.
But a privacy policy cannot repair a website that sends data somewhere unexpected.
You need to inspect what the website actually does.
Step 1: List the tools
Create an inventory of:
- WordPress plugins
- Contact forms
- Analytics
- Advertising pixels
- Consent tools
- CRM integrations
- Email delivery systems
- Chat tools
- Payment services
- Embedded video
- Maps
- Fonts
- Social media widgets
- Backup systems
Step 2: Ask what each tool collects
Do not rely only on the tool’s marketing description.
Check what is actually transmitted.
Possible information may include:
- IP address
- Browser details
- Device information
- Page URL
- Button or form activity
- User identifiers
- Email address
- Purchase value
- Location information
- Event names
- Sensitive information inferred from page visits
Step 3: Test before consent
Open the site in a clean browser.
Reject optional tracking if the consent system offers that choice.
Then inspect whether requests are still sent to analytics, advertising or social-media endpoints.
Step 4: Test after consent
Accept analytics only.
Check what loads.
Then test advertising consent separately, if your website uses it.
Step 5: Submit test forms
Check:
- Where the form data goes
- Whether the email arrives
- Whether a CRM record is created
- Whether an analytics event fires
- Whether advertising tools receive information
- Whether consent records are stored
- Whether sensitive values appear in URLs or event parameters
Step 6: Compare reality with your notices
Your privacy and tracking notices should describe what the website actually does.
Not what you hoped it did six months ago.
A Simple Privacy Audit Table
| Question | What to record |
|---|---|
| What causes the processing? | Page visit, form submission, purchase or signup |
| What technology is involved? | Plugin, script, cookie, pixel or API |
| What data is collected? | Actual fields and parameters |
| Why is it collected? | Enquiry, analytics, advertising or service delivery |
| Who receives it? | Website, CRM, email provider, Meta or other provider |
| What is the business role? | Controller, joint controller or another role |
| What is the provider’s role? | Check the specific product terms |
| Does consent apply? | Consent, exception or another lawful route |
| Does it fire before permission? | Yes or no |
| How long is data kept? | Business and provider retention |
| Can the visitor withdraw permission? | Explain how |
| When was it last tested? | Record the date |
This may look like paperwork.
It is really a map.
And you cannot safely drive a vehicle through a city if nobody knows where the roads go.
The WordPress Responsibility Checklist
WordPress gives you more control, but it does not make the website automatically compliant.
Check that your business:
- Knows which plugins are installed.
- Removes unused plugins and themes.
- Keeps WordPress and plugins updated.
- Limits administrator access.
- Uses strong passwords and multi-factor authentication.
- Knows where form data is stored.
- Knows which services receive form data.
- Uses clear form wording.
- Separates enquiry handling from marketing permission.
- Uses a consent system that actually controls tracking.
- Tests whether optional tags fire before consent.
- Provides a way to change or withdraw choices.
- Avoids putting personal information into analytics URLs.
- Blocks or reviews tracking on sensitive pages.
- Sets sensible retention periods.
- Keeps backups secure.
- Reviews new plugins before installing them.
- Updates privacy and tracking notices when the setup changes.
- Escalates high-risk processing for specialist advice.
A managed WordPress host can help with technical maintenance, security, backups and monitoring.
It cannot decide:
- Why your business needs customer data
- Whether you need a marketing consent
- Which advertising tool fits your business
- Whether your privacy wording is legally adequate
- Whether a specific international transfer is lawful
Those decisions belong to the business and its professional advisers where appropriate.
When You Should Get Specialist Advice
A simple brochure website with a basic contact form is not the same risk as a website handling sensitive personal information.
Seek specialist advice if your business:
- Processes health information
- Handles children’s data
- Processes financial information
- Targets vulnerable people
- Uses detailed behavioural profiling
- Uploads customer lists to advertising platforms
- Combines online and offline customer data
- Operates across several jurisdictions
- Uses automated decisions with serious effects
- Receives a regulator complaint
- Experiences a significant data breach
- Cannot work out which trackers are firing
- Uses sensitive information in URLs or event parameters
The more sensitive the data, the less sensible it is to rely on a generic internet checklist.
Where Empire Base Fits
Empire Base favours WordPress because it gives businesses more control over their website, forms, plugins, content and integrations.
That control can be valuable for privacy because you may be able to:
- Remove unnecessary plugins
- Delay tracking until permission
- Restrict form fields
- Exclude sensitive pages from advertising tools
- Choose different analytics systems
- Replace a supplier
- Review where data is sent
- Keep content and backups in a business-controlled environment
But WordPress is not a compliance certificate.
A badly configured WordPress site can still leak information, fire tracking too early or collect more data than necessary.
Empire Base Managed WordPress Hosting includes technical care such as:
- Server maintenance and security
- Daily cloud backups
- 90-day backup retention
- Vulnerability scanning
- Malware scanning
- Security updates
- Firewall protection
- Uptime monitoring
- Performance checks
- Monthly reporting
That helps with the technical foundation.
Your business still needs to make responsible decisions about forms, tracking, marketing and privacy.
For more on the platform choice, read why WordPress is a smart website foundation for small businesses.
For measurement and analytics, read Facebook Page Insights versus website analytics.
The Bottom Line
Using Facebook does not remove your privacy responsibilities.
Using WordPress does not automatically solve them either.
The difference is control.
Facebook gives you a useful business presence inside Meta’s environment. Your website gives you more ability to choose how information is collected, measured, stored and shared.
That is powerful.
It also means you need to understand the decisions you are making.
You cannot outsource responsibility simply by outsourcing the technology.
Use Facebook carefully.
Use website forms thoughtfully.
Install tracking only when it serves a real business purpose.
Collect less where less is enough.
Test what your website actually sends.
Keep your privacy information honest and current.
And when the situation becomes complicated, ask for qualified advice rather than hoping a generic banner will save the day.
Final Takeaways
- Operating a Facebook Page can involve privacy responsibilities.
- Page Insights should be considered separately from Meta Pixel and other Business Tools.
- The Wirtschaftsakademie case rejected the idea that using Facebook removes the Page administrator’s obligations.
- Controller roles depend on actual decisions, not simply server ownership.
- A WordPress website gives more control but also creates more decisions.
- Forms, analytics, pixels and plugins can create separate data flows.
- UK cookie and tracking rules changed during 2025–26.
- The UK statistical-purpose exception is narrow and not automatically EU-wide.
- Advertising and cross-site tracking need especially careful consent treatment.
- A consent banner does not help if tracking fires before the visitor makes a choice.
- Keep a current inventory of plugins, scripts, forms and external services.
- Get specialist advice for sensitive, complex or international processing.
Build with control. Operate with care.
Empire Base can help provide the WordPress hosting foundation, maintenance, security, backups and performance support behind your website.
- Explore Shared Hosting
- Explore Managed WordPress Hosting
- Return to the Facebook vs Website strategic battleplan
- Read the analytics deep dive
Empire Base provides WordPress hosting and related website services, so we naturally favour WordPress where it fits the business. Greater control can support better privacy decisions, but no hosting provider, CMS or plugin guarantees legal compliance.






