Skip to main content

News

..with you every step of the way!

News


20/10/2022

Two minutes to BeReal – but what trouble could it cause?

BeReal has amassed over 27 million downloads worldwide, and is in the process of taking the social media industry by storm. Something that is this popular and is based on taking photos certainly has scope for being a risk in the workplace. This article touches upon those risks.

What is BeReal?

BeReal is a mobile app that was launched in 2020. It has recently taken off and in 2022 it has more than 27 million downloads worldwide. Like many others, it is a photo-sharing social media app however BeReal notifies users to post one unfiltered photo daily (filtering is not possible in the app). At a random point every day, you and your friends on the app will get notifications that “It’s time to BeReal.” The users have a two minute window within which to take a photo of whatever they are doing at that moment and it’ll be shared with friends within the BeReal app. You can still take a picture outside of the two minute window but friends will be informed that it is late. Location information can be shown on the photo, depending on your settings. The pressure is created by the fact that a user cannot see their friends’ posts until they have posted their BeReal moment.

The two minute window for taking a photograph is short in the context of what you may be doing. The name gives it away – it is trying to catch the real moments of your life, not the often carefully curated content that makes up a lot of social media these days.

How can this get people into trouble?

The General Data Protection Regulation (both EU GDPR and UK GDPR) deals with personal data protection and the transference of personal data outside the UK/EU.

The issue created by a BeReal notification coming through at a random point during the working day is that users have in many cases been taking pictures of their computer screens or their workplace, meaning that all of their friends can zoom in and see that information. It doesn’t matter whether sharing is with a select group of friends or the wider world – such sharing can be a data breach if there is personal data within the picture and that could be email addresses, names, addresses, telephone numbers and other information that can be linked to an individual (including other people who may be caught within the photo). There are many posts online of people saying how much they enjoy looking at their friends’ emails, so it is a huge cause for concern and one that employers should not turn a blind eye to. As an employer will often be a data controller, the burden of compliance with data protection laws falls on the employer.

Most company handbooks and policies will contain clauses surrounding social media use and confidentiality, stating that any personal data cannot be shared and could lead to disciplinaries or summary dismissal, depending on the seriousness.

In addition, complaints can be made to the employer by anyone affected and complaints to the ICO or court action could follow, not to mention the possibility of monetary penalties.

What can an employer do?

Whilst this does not justify a breach, some GDPR breaches are unintentional e.g. sending an email to the wrong address. Some however are intentional e.g. sharing data that includes personal data with a competitor. In the context of social media, there is a blurring of these lines and the intentional sharing of a photo via social media could be seen as neglect in the context of taking suitable care with personal data, not to mention a loss of confidentiality. Employees should be aware of the risks involved in taking photographs in the workplace, this being backed up by a robust employer policy on personal data protection and confidentiality.

As it is not possible to monitor everything employees are posting in personal forums, consistent and regular training should be provided to help limit the issue and keep the risks at the forefront of employees’ minds. It is important that employees understand (and are periodically reminded of) GDPR and the concept of confidentiality and how what they believe to be a harmless photo shared with friends can be part of a much wider information protection problem and that failures to protect such information could affect their jobs and the standing of their employer. Although a lot of employees may consider it obvious to not post this content, training is essential to act as a reminder – if you are concentrating on taking a photo within two minutes, you may not stop to consider that something in the background could still lead to a data or confidentiality breach and a loss of business information.

Whilst such risks are not confined to BeReal, this is a timely reminder for employers to check social media, confidentiality and disciplinary policies in their company handbook and review confidentiality clauses in employment contracts so that in if an employee does breach such policies, the employer is able to act quickly and decisively.

This is not legal advice; it is intended to provide information of general interest about current legal issues. You should take specific legal advice before acting in reliance on any of the information provided.