Processing under EU Regulation 2021/1232 Summary : This is a report made by Meta Platforms Ireland Limited (Meta Ireland) in accordance with EU Regulation 2021/1232 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-independent interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a report which relates to its processing of personal data in reliance of the EU CSAM Derogation. This report is published for the purposes of compliance with this reporting obligation and provides data relating to our use of technology for the detection, reporting and removal of child sexual abuse material (CSAM). Specifically, this report covers the period from January 1, 2024 to December 31, 2024 inclusive . Please note that this report only covers specific measures falling within the area of applicability of the EU CSAM Derogation and does not give a full account of the measures Meta Ireland takes to protect children on its technologies. Detail : (1) The type and volumes of data processed: We run our media matching technology on images and video (media) across Messenger and Instagram Direct on surfaces that are not end-to-end encrypted. (2) The specific ground relied on for the processing pursuant to Regulation (EU) 2016/679: The processing in the area of applicability of the EU CSAM Derogation in particular serves to protect the vital interests of victims of sexual abuse. It is also carried out in the public interest and supported by a legitimate interest of providers to avoid CSAM being shared on their services, and to protect third parties against this type of abuse. Meta Ireland describes the legal bases for its processing of personal data under Regulation (EU) 2016/679 in the Privacy Policy (https://www.facebook.com/privacy/explanation), specifically in the section “ What is our legal basis for processing your information, and what are your rights ? ”. Further information on the specific legal bases Meta Ireland relies on is available here: https://www.facebook.com/privacy/policy?subpage=7.subpage.1-WhatIsOurLegal. (3) The ground relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable: To the extent that the processing in scope of the EU CSAM Derogation involves data transfers from Meta Ireland to the United States or other countries outside of the EEA, Meta Ireland uses appropriate data transfer mechanisms under Regulation (EU) 2016/679. Meta Ireland relies on Standard Contractual Clauses approved by the European Commission for the internal transfers to Meta Platforms Inc. as its processor. (4) The number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children: Between January 1, 2024 and December 31, 2024, we actioned around 1.5 million pieces of media constituting CSAM that were detected using our media matching technology, in private message threads on Messenger and Instagram Direct which included an EU user. (5) The number of cases in which a user has lodged a complaint with the internal redress mechanism or with a judicial authority and the outcome of such complaints: During the same period, users appealed the actions of around 76.9 thousand pieces of their shared media content. Following the appeals process, around 1.8 thousand pieces of content were restored and account actions reversed. (6) The numbers and ratios of errors of the different technologies used: Of the around 1.5 million actioned pieces of media, around 1.8 thousand pieces of content were restored and account actions reversed since we identified an error in our detection. The overturn rate is therefore 0.12%. (7) The measures applied to limit the error rate and the error rate achieved: Meta Ireland uses media matching technologies that help detect, remove and report the sharing of media that exploits children. These media matching technologies create a unique digital signature of an image (known as a "hash"), which is then compared against a database containing signatures (hashes) of previously-identified CSAM. Daily samples of media detected by our technology as CSAM are audited by human reviewers. There is also an alert system in place which ensures that high volume clusters are flagged and reviewed. Further, we provide an appeal mechanism if a sender of a message disagrees with content we have removed as CSAM. (8) The retention policy and the data protection safeguards applied pursuant to Regulation (EU) 2016/679: Meta Ireland has robust data privacy, security and retention policies in place. These policies include industry standard encryption of data in transit; access control; and strict retention policies for detected media containing CSAM. Detected CSAM is generally retained for one year. If users appeal our actions, Meta Ireland retains the data related to the appeal for a period of 195 days. (9) The names of the organisations acting in the public interest against child sexual abuse with which data has been shared pursuant to this Regulation: The National Center for Missing and Exploited Children (NCMEC). Date of report: January 30, 2025