Facebook agreed to settle charges by the US Federal Trade Commission that it had deceived consumers by telling them their information could be kept private and then repeatedly allowing it to be shared and made public. The settlement imposed long-term obligations on the company.
What happened
- The FTC said December 2009 changes made some information users had marked as private, such as Friends Lists, public without warning or consent.
- Facebook was required to obtain users’ express consent before overriding their privacy preferences.
- It had to establish a comprehensive privacy programme and undergo independent privacy audits every two years for 20 years.
- FTC Chairman Jon Leibowitz said Facebook was obliged to keep its privacy promises to its hundreds of millions of users.
Why it mattered
The order became the baseline for later US action against Facebook: alleged violations of it led to the FTC’s record $5 billion penalty in 2019.
Lessons for organisations
Make sure privacy notices and settings accurately describe how data is used, and assess privacy impacts before changing defaults. Regulators treat broken privacy promises as deception, and settlements can bring years of external audits.
Source: Federal Trade Commission
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.