Don’t do SECURITY. Do business SECURELY.

Facebook settles FTC charges over broken privacy promises

Facebook agreed to settle FTC charges that it deceived users, accepting independent privacy audits every two years for 20 years.

Facebook agreed to settle charges by the US Federal Trade Commission that it had deceived consumers by telling them their information could be kept private and then repeatedly allowing it to be shared and made public. The settlement imposed long-term obligations on the company.

What happened

  • The FTC said December 2009 changes made some information users had marked as private, such as Friends Lists, public without warning or consent.
  • Facebook was required to obtain users’ express consent before overriding their privacy preferences.
  • It had to establish a comprehensive privacy programme and undergo independent privacy audits every two years for 20 years.
  • FTC Chairman Jon Leibowitz said Facebook was obliged to keep its privacy promises to its hundreds of millions of users.

Why it mattered

The order became the baseline for later US action against Facebook: alleged violations of it led to the FTC’s record $5 billion penalty in 2019.

Lessons for organisations

Make sure privacy notices and settings accurately describe how data is used, and assess privacy impacts before changing defaults. Regulators treat broken privacy promises as deception, and settlements can bring years of external audits.

Source: Federal Trade Commission

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights