Social Media Privacy Statistics: What UK Users Should Know
Table of Contents
Social media privacy statistics tell a consistent story for UK users in 2026: social media privacy concerns keep rising, new social media data protection laws are changing what businesses can do with personal data, and a ban on social media for under-16s has pushed privacy back onto the front pages. Many of the questions behind these numbers start with something simple: what is social media privacy, and how much control do UK users really have over it? If you manage a business’s online presence, or you’re simply trying to understand your own exposure, these numbers are worth understanding before your next post goes live.
This guide brings together the most current UK-specific data on social media privacy statistics, covering user sentiment, social media privacy issues by platform, AI data training, the current regulatory position on social media data protection, and the practical steps businesses can take to reduce social media privacy risks.
Three figures worth remembering:
- More than half of Britons (52%) say controlling who can access their data is very important, yet 44% only take moderate steps to protect it (YouGov, January 2026), reflecting widespread social media privacy concerns across every age group
- Meta and X can still use UK users’ public posts and photos to train their AI systems, and the opt-out routes remain hard to find
- The UK’s ban on social media for under-16s, confirmed in mid-2026 with curfews for 17 and 18-year-olds following in July, has reopened the debate about age verification and digital ID
Key Social Media Privacy Statistics at a Glance

Before looking at what’s driving these numbers, here are the social media privacy statistics that matter most for UK businesses and individuals right now, from social media privacy concerns to social media data protection failures.
- 52% of Britons say limiting who can access their data is very important, but only 44% take more than moderate care over it (YouGov, 2026)
- 65% of UK internet users are concerned about being tracked online, and they name social platforms as the main source of social media privacy issues (ONS, 2023)
- 41% of UK internet users cut back on social media in the past year, specifically because of social media privacy concerns (IAB UK, 2024)
- Meta received more than 3.7 million data subject access requests across the EU and UK in a single year (Meta Transparency Report)
- Only 9% of social media users say they read privacy policies carefully before agreeing to them (Deloitte Digital Consumer Trends, 2024)
- Identity fraud and account takeover made up 72% of the 444,000-plus fraud cases Cifas recorded in the UK in 2025, the highest annual total on record
Public Trust and Sentiment: How UK Users Feel About Social Media Privacy
Social media privacy statistics on sentiment reveal a gap between stated social media privacy concerns and how much people actually do about it. That gap matters for any business trying to build a presence on these platforms.
Ask people what is social media privacy in practical terms, and most describe control over who sees their posts, not control over ad or AI training data.
The Privacy Paradox describes this well-documented gap. Research from the Oxford Internet Institute found that 76% of UK users say privacy matters to them, yet only 14% changed their privacy settings in the past year, and fewer than one in ten had read a social media privacy policy in full. Awareness of specific social media privacy issues, such as advertising profiles and AI training data, remains far lower than this general level of concern.
YouGov data from Data Privacy Day 2026 adds a generational split: 63% of over-55s say limiting data access is very important, against just 36% of 18 to 34-year-olds, who lean towards a ‘moderate care’ approach rather than an active one.
Other behaviours match this pattern: 53% accept cookie consent banners without reading them (Deloitte, 2024), and only 28% enable two-factor authentication (NCSC, 2023). For businesses building a social media presence that customers trust, stated concern rarely predicts behaviour, so trust has to be earned through what a brand does with data, not just what it promises.
Platform Privacy Comparison: Which Networks Collect the Most Data
Not every platform handles user data the same way. These social media privacy statistics show that social media privacy issues vary considerably by network, and comparing platforms like this is one practical way to answer what social media privacy is for your own accounts specifically. For a closer look at how this affects brand accounts, see our guide to data privacy in social media marketing.
| Platform | Notable Breach History | AI Training Opt-Out | Third-Party Data Sharing | Transparency Rating |
|---|---|---|---|---|
| Meta (Facebook/Instagram) | Cambridge Analytica (2018); 533m records scraped (2021) | Available but hard to find | Extensive | Moderate |
| TikTok | China-based staff access to EU/US user data (2022) | Limited | Extensive | Low |
| X (formerly Twitter) | 5.4m accounts exposed (2022); Grok AI training (2023) | Limited | High | Low |
| 700m records scraped (2021) | Available | Moderate | Moderate to High |
Meta (Facebook and Instagram)
Meta collects data across Facebook, Instagram, WhatsApp and Threads, building profiles that include browsing activity from outside its own apps through off-Facebook activity tracking. Its advertising platform can target users across more than 2,000 behavioural and demographic categories.
UK regulators fined Meta £17.5 million in 2022 after investigating the Cambridge Analytica scandal, a penalty many privacy campaigners still regard as too low given the scale of the breach. Advertising profiling like this is part of a broader pattern of social media privacy issues that campaigners have raised for years.
TikTok
TikTok’s ownership by Beijing-based ByteDance keeps it under ongoing scrutiny from regulators in the UK, the US and the EU. In 2022, TikTok admitted that China-based staff had accessed European and American users’ data, including journalists’.
The UK government banned TikTok from government devices in March 2023, though the app remains freely available to the public. The ICO’s investigation into TikTok’s recommender systems for 13 to 17-year-olds was still active in 2026, and it is often cited as one of the clearest examples of social media privacy issues tied to platform ownership rather than technical failure.
LinkedIn sits in an unusual position. Users willingly share employment history, skills and professional connections, and that data carries real commercial value. In 2021, scraped data from around 700 million profiles, roughly 93% of its user base, was posted for sale online.
LinkedIn does not allow users to opt out of sharing data with Microsoft, its parent company, for product improvement, a distinction many business users miss.
UK Social Media Privacy Law: GDPR, the DUAA and the Under-16 Ban

The legal picture behind these social media privacy statistics has moved fast over the past year. Three developments now shape social media data protection for platforms and businesses in the UK.
UK GDPR still forms the backbone of social media data protection law, but the Data (Use and Access) Act 2025 has changed how it works in practice. Most remaining provisions came into force in February 2026, and from 19 June 2026 organisations must run a formal complaints-handling procedure for data protection issues, including complaints about how social platforms handle personal information.
The Online Safety Act 2023 added obligations on illegal content removal and algorithmic transparency, though its privacy provisions stay secondary to online harm.
The biggest change is the UK’s ban on social media access for under-16s, confirmed by the Prime Minister in June 2026 and extended with curfews for 17 and 18-year-olds the following month. The ban is due to take effect in spring 2027. The Information Commissioner’s Office says data protection law already requires an age-appropriate experience for children under its Children’s Code, but privacy campaigners have raised concerns that the age verification needed to enforce the ban could expand digital ID checks well beyond children’s accounts, adding new social media privacy risks around identity data that becomes an attractive target for attackers.
SMEs operating in Northern Ireland face a further layer: businesses marketing into the Republic of Ireland fall under the Irish Data Protection Commission and EU GDPR, while UK operations sit under ICO jurisdiction, calling for careful social media data protection practices on both sides of the border.
Social Media Data and AI Training: What UK Users Should Know
AI training is now one of the most contested issues in social media privacy statistics, and it caught many users off guard when platforms updated their terms.
Meta announced in June 2023 that it would use public posts, photos and comments from Facebook and Instagram to train its generative AI systems. UK and EU users were given an opt-out window under GDPR pressure, but the ICO found that the process was deliberately difficult to locate.
X updated its privacy policy in September 2023 to allow user data to train Grok, its own AI model, and it did not offer existing users a straightforward opt-out.
A 2024 survey by the Open Rights Group found that 68% of UK social media users were unaware their content could be used for AI training until they were told, and 81% of those who found out said they would have opted out if the process had been clearer.
Regulatory pressure is catching up. The ICO issued a call to generative AI developers in January 2025, asking them to explain clearly how they use people’s personal information, and the EU AI Act’s provisions on training data provenance are now being actively enforced for platforms operating in Europe. For businesses adopting AI tools of their own, this is a reminder that data provenance needs checking before any customer data goes near a model, since AI training carries its own social media privacy risks.
Data Breaches and Identity Theft: The Cost of Exposure
Behind many of the worst social media privacy statistics sits a simple financial reality: exposed data gets monetised fast, and social media privacy risks turn into real financial losses quickly.
Action Fraud recorded 33,000 social media account takeover reports in 2023, a 27% year-on-year rise at the time. The picture has worsened since: Cifas recorded more than 444,000 UK fraud cases in 2025, the highest on record, with identity fraud and account takeover making up 72% of reports.
Account takeovers often lead to wider identity fraud, since a social profile gives enough context to impersonate someone or reach connected services. The average loss per victim of social media-enabled identity fraud in the UK was £1,200 in 2023 (Cifas); the reputational cost to a business account is harder to price.
Scraping, the automated collection of public data, remains a persistent route in. Scraped names, locations, and employer details are often combined with data from other breaches to build profiles used in phishing attacks, and the ICO confirmed in 2024 that scraping publicly accessible social media data can still constitute a breach of the UK GDPR without a lawful basis.
Impact on Younger Users
Younger users show a different pattern in these social media privacy statistics: high platform use alongside low active protection. 43% of UK adults aged 18 to 34 use TikTok weekly (Ofcom), yet only 36% of that age group see limiting data access as very important, against 63% of over-55s (YouGov, 2026).
Some call this privacy nihilism, the sense that data is already out there, so protecting it further makes little difference, a pattern shaping how these social media privacy risks affect younger audiences.
The Privacy Action Gap: Why Concern Rarely Leads to Change

The gap between stated social media privacy concerns and real action is one of the most consistent findings in social media privacy statistics research.
Several factors explain it: privacy settings are often complex by design, there’s a sense of fatalism that data is already out there, and opting out carries a perceived cost, whether that’s losing social features or seeing less relevant content.
For businesses managing customer communities or social advertising, this matters: a growing share of your audience is quietly reducing platform engagement, and targeted advertising built on behavioural data faces more resistance than it used to.
How Businesses Can Reduce Their Social Media Privacy Risk
None of this means retreating from social media entirely. It means treating social media privacy statistics and the social media privacy risks they point to as a checklist rather than a warning.
- Audit your public information: search your business and personal name across platforms and check what’s visible by default.
- Separate personal and business accounts: a personal account linked to a business page widens your exposure.
- Review third-party app permissions regularly: connected apps often keep access long after anyone is using them.
- Understand your advertising data footprint: Meta’s Ad Preferences tool shows the data categories used to target your ads.
- Train your team: most account takeovers start with phishing, so staff managing brand accounts need basic security awareness training.
“The businesses we work with across Northern Ireland are increasingly asking us how to build direct relationships with their audience, through email lists and owned communities, rather than relying entirely on platforms they can’t control,” says Ciaran Connolly, founder of ProfileTree. “That shift isn’t just a marketing preference; it’s a response to genuine concerns about where social media data goes.”
ProfileTree’s digital training programmes cover social media security as part of broader digital literacy sessions for SMEs, and getting this right internally is far cheaper than managing the fallout from a compromised account. For a wider view of where data risk sits across a business, our guide to data privacy and security covers the same ground beyond social platforms alone.
Building a Privacy-Aware Social Media Strategy
Social media privacy statistics point to a consistent conclusion: platforms are not going to make privacy easy by default, so businesses and individuals who want better outcomes need to build the habit themselves. At its core, what is social media privacy comes down to a simple test: would you be comfortable if this data were public tomorrow?
Reviewing what your accounts expose and training the people who manage your platforms takes an afternoon, not a project team. Do it before the next policy change forces the issue.
FAQs
1. What is social media privacy, and how concerned are UK users?
Social media privacy covers how platforms collect, use and share the personal data behind your posts, follows and interactions. Around 72% of UK adults said they were very or somewhat concerned about how social media platforms handle personal data (YouGov, 2023), and social media privacy concerns remain high, with 59% still worried about how much data is collected about them online (YouGov, January 2026). Concern has stayed high even as fewer people say they know how to protect themselves.
2. Can social media platforms use my photos and posts to train AI?
Yes. Meta and X can currently use public posts, photos and comments to train their AI systems. UK and EU users can request an opt-out, but the process is not prominently advertised.
3. Which social media platform has the most privacy issues?
TikTok and Meta consistently receive the lowest transparency ratings. TikTok’s risk centres on government data access via its Chinese ownership; Meta’s comes from the volume and third-party sharing of its data collection.
4. What is the privacy paradox in social media?
The privacy paradox is the gap between how concerned people say they are about their data and how little they do to protect it. UK research found 76% say privacy matters, yet only 14% changed their settings in the past year.
5. How does the UK’s under-16 social media ban affect privacy?
The ban, due to take effect in spring 2027, requires stronger age verification, which campaigners worry could expand digital ID checks well beyond children’s accounts. The ICO says existing law already requires an age-appropriate experience for children under its Children’s Code.