The US Federal Trade Commission announced a $5 billion penalty against Facebook for violating a 2012 privacy order, alongside new restrictions on how the company handles user data. It was the largest privacy penalty ever imposed on any company at the time.
What happened
- The FTC found that Facebook had deceived users about their ability to control the privacy of their personal information.
- The case followed revelations in 2018 about data harvested by Cambridge Analytica.
- The settlement created an independent privacy committee on Facebook’s board and required quarterly privacy certifications from the chief executive.
- Facebook also had to conduct privacy reviews of new products and strengthen oversight of third-party apps.
Why it mattered
The settlement showed that US regulators were willing to impose very large penalties for privacy failings and to place personal accountability on senior leadership. Critics, including two FTC commissioners who dissented, argued the settlement did not go far enough in changing Facebook’s business model.
Lessons for organisations
Assess privacy risks before launching new products or data sharing, keep firm control over third parties with access to personal data, and make sure board-level oversight of privacy is real and documented.
Source: Federal Trade Commission
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.