Fake Profiles and Impersonation on Social Media – Know Your Rights

Someone has created a profile on Instagram, TikTok or Facebook using your name, your photographs or your company's identity. Or your own legitimate account has been suspended by a platform that wrongly classified it as fake. Both situations are common – and in most cases a clear violation of platform policies. Under EU law, you have concrete options to challenge a platform's failure to act or its wrongful decision against your own account.

 

Since the Digital Services Act (DSA) came into force, users can challenge moderation decisions through a certified out-of-court dispute settlement body. User Rights is the first such body certified under Article 21 DSA in Europe for Social Media, certified by the German Federal Network Agency (Bundesnetzagentur). The procedure is free of charge for users – the platform bears the costs. No prior internal complaint to the platform is required - but the content should be reported to the platform itself beforehand. Cases are currently reviewed for Instagram, Facebook, TikTok, X, YouTube, LinkedIn, Snapchat and Pinterest. Our assessments are based on platform policies and, where relevant, EU law as well as national law – including German and Italian law in applicable cases.

What Is Impersonation on Social Media?

Impersonation means creating or operating an account that uses another person's or organisation's name, image, or identity markers in a way that could mislead others into thinking the account is official or genuine. This is distinct from anonymous or pseudonymous accounts, fan accounts and parody accounts – which are generally permitted as long as their non-official status is clearly signalled in the account name or description.

Example: An account on Instagram uses your full name and a photograph taken from your own profile. It messages your followers asking for money, claiming to be you in a personal emergency. Despite multiple reports, the platform does not remove the account. This is a clear impersonation violation under every major platform's community standards and is reviewable by User Rights.

Impersonation is also frequently used in combination with other harms: romance fraud involving a fake persona built around a real person's identity, harassment campaigns run from accounts designed to look like the victim, or coordinated efforts to damage someone's professional reputation by posting under their name. User Rights can review the impersonation element in all of these cases.

Common impersonation situations addressed by platform policies:

  • An account uses your name and photographs without your consent
  • A fake profile impersonates your business, brand or public organisation
  • An account messages your contacts or followers while posing as you
  • A fake profile spreads false information in your name
  • Your own legitimate account is wrongly suspended as fake or inauthentic
  • A fan or parody account does not make its unofficial status clear
  • A fake profile is used to run a scam or romance fraud under your identity

 

Impersonation vs. inauthentic behaviour: an important distinction

Not all fake-account enforcement falls within User Rights' scope of review. Platforms distinguish between two separate categories that can look similar from the outside but are treated very differently.

Impersonation – using another real person's or organisation's identity to mislead others – is a content-based policy violation. Platform decisions to remove or refuse to remove such accounts are reviewable by User Rights.

Inauthentic behaviour – coordinated fake accounts, bot networks, artificial engagement and the use of automation to manipulate platform systems – is a behaviour-based enforcement category. Moderation actions taken on these grounds are outside User Rights' scope, because they are not based on the content of a specific post but on how an account operates.

In practice: If a scammer runs 50 bot accounts to amplify fraudulent content, User Rights can review whether the platform acted on the impersonation and fraud in the content – but not whether it correctly identified and removed the bot network as inauthentic behaviour.

Impersonation Policies on Social Media Platforms

All platforms covered by User Rights are subject to the DSA, which requires them to give reasons for moderation decisions and to cooperate with certified dispute settlement bodies. Each platform explicitly prohibits impersonation in its community standards, though the specific policies and their scope differ.

 

Meta: Instagram and Facebook

Meta's Authentic Identity Representation policy prohibits accounts that impersonate real individuals, organisations or entities in a way that is likely to mislead others. This policy is fully within User Rights' scope of review. Meta separately enforces Account Integrity rules against accounts that use misleading information about their own identity or attempt to circumvent previous enforcement actions – also reviewable in its content-related aspects.

Important: Meta's Inauthentic Behaviour policy – which targets coordinated fake accounts and bot-driven activity – is outside User Rights' scope. If your report of a fake account was dismissed and you are unsure which policy Meta applied, the reason given in the dismissal notification will indicate this. If no policy has been specified, it is recommended that you submit the case to User Rights, and User Rights will handle it—including determining which policy is involved.

TikTok

TikTok's Community Guidelines on Integrity and Authenticity (Deceptive Behaviors and Fake Engagement) prohibit impersonation of individuals, organisations or public figures in a way that is misleading. TikTok provides a dedicated reporting pathway for impersonating accounts. Fan and parody accounts are permitted if the account name and description make their unofficial status clear. TikTok's enforcement of Deceptive Behaviors and Fake Engagement is only partially within scope: User Rights can review decisions relating to specific content under this policy, but not those based solely on behaviour.

YouTube

YouTube's Impersonation policy prohibits the unauthorized impersonation of a person, entity or channel in a way that could mislead viewers. This covers copying branding, usernames or content to deceive, as well as using AI to copy someone's voice or likeness to falsely imply their authorization. Fan channels are permitted provided they clearly state their unofficial status in the channel name. YouTube considers whether content is parody or satire and whether it features public figures when evaluating removal requests. YouTube's Spam policy additionally prohibits scams, malicious clickbait and the reposting of others' content without transformation — all of which can form part of a fake profile operation. Both policies are within User Rights' scope of review.

X

X addresses impersonation under its Authenticity policy, in the section on inauthentic accounts. Using manufactured identities with stock, stolen or AI-generated profile photos, copied bios or misleading profile information to deceive others is prohibited. Using another person's or organisation's name, profile image or similar identity markers in a misleading way is also prohibited. The policy also prohibits ban evasion — creating new accounts to circumvent previous enforcement actions — and content spam and scams used as part of inauthentic operations. Parody, commentary and fan accounts are permitted provided they are compliant and their purpose is clear. X's Authenticity policy is partially within User Rights' scope: impersonation, fake personas, content spam and scams are reviewable; unauthorized automation and engagement spam are not.

LinkedIn

LinkedIn's Professional Community Policies explicitly prohibit fake profiles, false information about one's identity, and the use of a profile photograph that does not depict the account holder. LinkedIn's professional context makes impersonation particularly harmful: a fake profile using a real person's name and employer can damage professional relationships, mislead recruiters or be used to extract sensitive business information. All LinkedIn community guidelines are fully within User Rights' scope.

Snapchat

Snapchat prohibits accounts that misleadingly impersonate another person or organisation, or falsely associate themselves with one, under the Harmful, False or Deceptive Practices section of its Community Guidelines. This covers impersonating friends, acquaintances, celebrities, brands or other organisations, as well as imitating Snapchat's own branding. The same policy prohibits fraud and scams run through fake profiles, including content that incentivizes users to share personal information under false pretences, and the use of AI-generated or manipulated content for deceptive purposes. Fan, satire and commentary accounts are permitted but must explicitly disclose this in the display name. This policy is fully within User Rights' scope of review — whether a reported impersonation account was left in place, or a legitimate account wrongly actioned, the decision is subject to independent review.

Pinterest

Pinterest's Community Guidelines prohibit accounts that impersonate a person or organisation or misrepresent their affiliation. Fan, parody and commentary accounts are permitted provided the account name and details make clear that no official affiliation exists. Pinterest's Impersonation policy is within User Rights' scope of review.

What Can You Do if You Are Affected?

There are two situations in which User Rights can help: a platform has not acted on an impersonation account you reported, or your own legitimate account has been wrongly suspended or removed as fake.

 

Scenario A: Someone is impersonating you and the platform has not acted

  1. Document the fake account: Screenshot the profile with the account name, URL, date and time – before reporting, as the account may be removed quickly after your report. Where possible, capture the specific content or messages that demonstrate the impersonation.
  2. Report to the platform: Use the in-built reporting function and select the impersonation or fake account category specifically. At Meta, distinguish between impersonation of a real person (Authentic Identity Representation) and an account with misleading identity information – this affects which team reviews your report. Keep a record of the report and any reference number.
  3. Optional: Appeal if dismissed: If the platform dismisses your report, use the appeal mechanism via the help centre or dismissal notification. Note whether the dismissal cites a content-based policy or a behaviour-based one – the latter may fall outside User Rights' scope.
  4. Submit to User Rights: If the platform's inaction was inconsistent with its impersonation or authentic identity policy, submit a complaint. User Rights will assess whether the platform applied its policy correctly.
  5. Consider parallel steps: Depending on the severity, you may also wish to contact a lawyer about civil claims relating to use of your name, image or personal data. These steps are not a prerequisite for User Rights.

Scenario B: Your own account was wrongly suspended or removed as fake

  1. Check the reason: Under Art. 17 DSA platforms must give a specific reason for every moderation action. Identify whether your account was suspended under an impersonation policy, an account integrity policy or an inauthentic behaviour policy.
  2. Appeal internally: Use the platform's appeal mechanism. Provide context that demonstrates the public interest purpose of your content – your organisation, the context in which the footage was captured and the editorial purpose it serves. You do not have to wait for a response by the platform after seven days from the date of your internal complaint. Please always provide evidence of your internal complaint case when you submit a case with User Rights.
  3. Submit to User Rights: If the suspension was based on a content-related policy (such as Authentic Identity Representation) and the complaint to the platform was unsuccessful or unanswered, submit your case.

Note: User Rights does not review hacked or compromised accounts – these are treated as cybersecurity matters by platforms. Direct messages, or moderation actions that were taken more than six months ago also fall outside the scope of review. A full overview is available on the scope of review page.

Is a Platform Failing to Act on an Impersonation Account – or was Your own Account wrongly Suspended as Fake?

Frequently Asked Questions (FAQ)