Don’t do SECURITY. Do business SECURELY.

FTC imposes record $5 billion privacy penalty on Facebook

The US Federal Trade Commission orders Facebook to pay $5 billion and accept new privacy oversight after the Cambridge Analytica scandal.

The US Federal Trade Commission announced a $5 billion penalty against Facebook for violating a 2012 privacy order, alongside new restrictions on how the company handles user data. It was the largest privacy penalty ever imposed on any company at the time.

What happened

  • The FTC found that Facebook had deceived users about their ability to control the privacy of their personal information.
  • The case followed revelations in 2018 about data harvested by Cambridge Analytica.
  • The settlement created an independent privacy committee on Facebook’s board and required quarterly privacy certifications from the chief executive.
  • Facebook also had to conduct privacy reviews of new products and strengthen oversight of third-party apps.

Why it mattered

The settlement showed that US regulators were willing to impose very large penalties for privacy failings and to place personal accountability on senior leadership. Critics, including two FTC commissioners who dissented, argued the settlement did not go far enough in changing Facebook’s business model.

Lessons for organisations

Assess privacy risks before launching new products or data sharing, keep firm control over third parties with access to personal data, and make sure board-level oversight of privacy is real and documented.

Source: Federal Trade Commission

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights