Facebook is to pay a record-breaking $5bn (£4bn) penalty to settle Federal Trade Commission (FTC) charges that the company deceived users about their ability to control the privacy of their personal information
The tech giant has also agreed to new data use restrictions and modifications to its corporate structure.
The regulator says the Facebook penalty is the largest ever imposed on any company for violating consumers’ privacy and almost 20 times greater than the largest privacy or data security penalty ever imposed worldwide. It is one of the largest penalties ever assessed by the US government for any violation.
The penalty is the result of investigations into allegations that political consultancy Cambridge Analytica improperly obtained the data of up to 87m users. Personal data was illegally harvested from people who responded to an online personality quiz and their friend networks, which was then sold to the data analytics firm.
The FTC alleged that many users were unaware that Facebook was sharing such information, and therefore did not take the steps needed to opt-out of sharing. The regulator said Facebook took inadequate steps to deal with apps that it knew were violating its platform policies.
The settlement imposes stringent new restrictions on Facebook’s business operations and creates multiple channels of compliance via a 20-year order which is intended to increase transparency. The company is required to restructure its approach to privacy from the corporate board-level down, and establish strong mechanisms to ensure that Facebook executives are accountable for the decisions they make about privacy, and that those decisions are subject to meaningful oversight.
The order establishes an independent privacy committee of Facebook’s board of directors, removing unfettered control by Facebook’s CEO Mark Zuckerberg over decisions affecting user privacy. Members of the privacy committee must be independent and will be appointed by an independent nominating committee. They can only be fired by a supermajority of the Facebook board of directors.
Facebook will be required to designate compliance officers who will be responsible for Facebook’s privacy program. These compliance officers will be subject to the approval of the new board privacy committee and can be removed only by that committee—not by Facebook’s CEO or Facebook employees. Zuckerberg and designated compliance officers must independently submit to the FTC quarterly certifications that the company is in compliance with the privacy program mandated by the order, as well as an annual certification that the company is in overall compliance with the order. The order also strengthens the independent third-party assessor’s ability to evaluate the effectiveness of Facebook’s privacy program and identify any gaps.
Joe Simons, FTC chairman, said: ‘Despite repeated promises to its billions of users worldwide that they could control how their personal information is shared, Facebook undermined consumers’ choices.
‘The magnitude of the $5bn penalty and sweeping conduct relief are unprecedented in the history of the FTC. The relief is designed not only to punish future violations but, more importantly, to change Facebook’s entire privacy culture to decrease the likelihood of continued violations.’
As part of Facebook’s order-mandated privacy program, which covers WhatsApp and Instagram, Facebook must conduct a privacy review of every new or modified product, service, or practice before it is implemented, and document its decisions about user privacy. The designated compliance officers must generate a quarterly privacy review report, which they must share with the CEO and the independent assessor, as well as with the FTC upon request. The order also requires Facebook to document incidents when data of 500 or more users has been compromised and its efforts to address such an incident, and deliver this documentation to the FTC and the assessor within 30 days of the company’s discovery of the incident.
Additionally, the order imposes significant new privacy requirements, including greater oversight over third-party apps and providing clear and conspicuous notice of Facebook’s use of facial recognition technology.
In a related, but separate development, the FTC has announced separate law enforcement actions against Cambridge Analytica, its former CEO Alexander Nix, and Aleksandr Kogan, an app developer who worked with the company, alleging they used false and deceptive tactics to harvest personal information from millions of Facebook users. Kogan and Nix have agreed to a settlement with the FTC that will restrict how they conduct any business in the future.
In addition Facebook is to pay $100m to settle charges brought by the Securities and Exchange Commission (SEC) that the company made misleading disclosures regarding the risk of misuse of Facebook user data. The SEC said for more than two years, Facebook’s public disclosures presented the risk of misuse of user data as merely hypothetical when Facebook knew that a third-party developer had actually misused Facebook user data.
The regulator alleged that during this two-year period, Facebook had no specific policies or procedures in place to assess the results of their investigation for the purposes of making accurate disclosures in Facebook’s public filings.
Stephanie Avakian, co-director of the SEC’s enforcement division, said: ‘As alleged in our complaint, Facebook presented the risk of misuse of user data as hypothetical when they knew user data had in fact been misused. Public companies must have procedures in place to make accurate disclosures about material business risks.’
In a statement, Zuckerberg acknowledged the SEC and FTC findings and said of the FTC order: ‘The agreement will require a fundamental shift in the way we approach our work and it will place additional responsibility on people building our products at every level of the company. It will mark a sharper turn toward privacy, on a different scale than anything we’ve done in the past.
‘The accountability required by this agreement surpasses current US law and we hope will be a model for the industry.
‘It introduces more stringent processes to identify privacy risks, more documentation of those risks, and more sweeping measures to ensure that we meet these new requirements.
‘Going forward, our approach to privacy controls will parallel our approach to financial controls, with a rigorous design process and individual certifications intended to ensure that our controls are working - and that we find and fix them when they are not.’
Pat Sweet | 24-07-2019