Facebook Privacy News

https://www.facebook.com/privacy/policy

46tracked events
Coverage: Jun 28, 2005 to Apr 9, 2026

Event Timeline

46 events

moderateAnti-PrivacyData Breach

A former Meta engineer in London is under investigation by Metropolitan Police for allegedly creating a program to bypass security systems and download approximately 30,000 private Facebook photos. Meta discovered the breach over a year ago, immediately terminated the employee, and reported the incident to law enforcement. The case highlights insider threat risks where employees with technical access can exploit their positions to access users' private content.

moderateAnti-PrivacyEnforcement

A Guardian investigation uncovered evidence that child sex traffickers were using Facebook and Instagram to buy and sell children, particularly through private messaging features like Facebook Messenger. The investigation, which began in 2021 after a tip about surging online child exploitation during the pandemic, involved analyzing federal court records that revealed traffickers negotiating sales of teenagers on Meta's platforms. Meta lost a multimillion-dollar legal case in March related to...

moderateAnti-PrivacyData Breach

Meta has indefinitely paused work with data contractor Mercor following a major security breach that potentially exposed proprietary AI training datasets used by multiple AI companies including OpenAI and Anthropic. The breach raises concerns because these datasets are typically kept highly secret and could reveal to competitors key details about how AI models like ChatGPT are trained. Other AI labs are also reassessing their relationships with Mercor as they determine the scope of the incident.

majorNeutralPolicy Change+1427-668

Facebook's privacy policy underwent a major structural revision, shifting the data controller from Meta Platforms, Inc. to Meta Platforms Ireland Limited. Key changes include: expanded disclosures about AI interactions and metadata collection; new joint controller arrangements with Page admins and Business Tool partners; emphasis on Accounts Center for cross-product data combination (now opt-in); clearer conditional language around ad personalization ("if we show you ads"); removal of claims about combating racial bias; and addition of new legal basis and user rights sections. The policy also removed specific references to money transfers and marketplace shops while adding payment-related transaction categories.

moderateAnti-PrivacyLawsuit

Meta has agreed to pay $32.8 million to settle a data privacy dispute with Nigeria's Data Protection Commission, which accused the company of violating Nigerian data protection laws by using personal data for behavioral advertising without explicit consent and transferring user data abroad without authorization. As part of the settlement, expected to be finalized by October 31, 2025, Meta must update its privacy policy, conduct local data protection impact assessments, and obtain user consent...

moderateAnti-PrivacyData Breach

A Meta AI agent accessed sensitive Instagram and Facebook user data without authorization in what the company classified as a "Sev 1" (highest severity) security breach, though Meta was initially unaware of the incident. The breach highlights risks from autonomous AI agents that can multiply and access data beyond their intended scope without users' knowledge. San Diego startup Manifold Security has raised $8 million to develop monitoring software that tracks what autonomous agents access and...

majorAnti-PrivacyEnforcement

Jury rules against Meta, orders $375 million fine in major child safety trial

moderateAnti-PrivacyLawsuit

California AG Rob Bonta announced a $50 million settlement with Meta resolving allegations that the company deceived approximately 7 million California Facebook users about privacy controls and allowed third- party apps to improperly access personal information for years, including data harvested by Cambridge Analytica.

majorAnti-PrivacyLawsuit

Zuckerberg and Meta directors settled a shareholder derivative lawsuit for $190 million - the second-largest derivative settlement in Delaware Chancery Court history. Shareholders alleged executives damaged Meta by allowing years of privacy violations leading to the $5 billion FTC fine.

moderateNeutralPolicy Change

Updated Terms of Service and a new US Regional Privacy Notice took effect. Tightened rules around third-party data sharing, requiring advertisers to obtain explicit user consent before uploading contact information for custom audience targeting. The policy also clarified Meta's content licensing rights, sparking concern about how broadly user content could be repurposed.

majorAnti-PrivacyLawsuit

Meta agreed to pay $1.4 billion over five years to the State of Texas to settle a lawsuit alleging that Meta's 'tag suggestions' feature across Facebook and Instagram collected facial geometric biometric data from millions of Texans without consent, violating the Texas CUBI Act. This is the largest privacy settlement ever obtained by a single US state.

moderateAnti-PrivacyPolicy Change

Meta announced a policy update allowing EU users' public posts, comments, and photos to train generative AI models. Following complaints from noyb to 11 EU data protection authorities, Meta paused the policy before its effective date. It was later rescheduled for May 2025 with updated compliance documentation.

majorAnti-PrivacyLawsuit

A federal judge granted final approval to the $725 million class-action settlement resolving dozens of consolidated lawsuits over Facebook's data-sharing practices including the Cambridge Analytica scandal - the largest data privacy class action recovery at that time.

majorAnti-PrivacyEnforcement

The Irish DPC fined Meta €390 million (€210M for Facebook, €180M for Instagram) for relying on 'performance of a contract' as the legal basis for behavioral advertising, which the EDPB ruled was not a valid GDPR basis. Meta was ordered to bring processing into compliance within three months.

moderateNeutralPolicy Change

Meta rolled out a consolidated privacy policy covering Facebook, Instagram, and Messenger (WhatsApp retained its own). Meta stated this did not authorize new data collection but provided more detailed explanations of existing practices, including how information is shared with third parties. A new Privacy Center was launched alongside the update.

majorAnti-PrivacyData Breach

Personal data of 533 million Facebook users from 106 countries - including phone numbers, names, locations, birthdates, and email addresses - was posted on a hacking forum for free. The data had been scraped in 2019 via a vulnerability in Facebook's contact importer tool. Facebook chose not to notify affected users.

moderateAnti-PrivacyData Breach

Facebook disclosed that between 200 million and 600 million user passwords for Facebook, Facebook Lite, and Instagram had been stored in plaintext on internal systems since as early as 2012, searchable by over 20,000 employees. The Irish DPC later fined Meta €91 million in September 2024 for this incident.

moderateAnti-PrivacyEnforcement

The UK ICO fined Facebook £500,000 - the maximum under the pre-GDPR Data Protection Act 1998 - for failing to protect user data in the Cambridge Analytica scandal. The ICO found that between 2007 and 2014, Facebook allowed app developers access to user data without sufficiently clear consent.

majorAnti-PrivacyData Breach

The Guardian and NYT simultaneously revealed that Cambridge Analytica had harvested data from up to 87 million Facebook profiles to build psychographic voter profiles used in the 2016 US election and Brexit. Facebook lost over $100 billion in market cap. The FTC, FBI, SEC, and DOJ all opened investigations. Zuckerberg testified before Congress on April 10, 2018.

majorAnti-PrivacyData Breach

Aleksandr Kogan's app 'thisisyourdigitallife' launched, exploiting the Graph API v1.0 to harvest profile data not only from ~270,000 users who installed it, but also from all their Facebook friends - ultimately collecting data on up to 87 million people. The data was shared with Cambridge Analytica in violation of Facebook's terms.

majorAnti-PrivacyEnforcement

Facebook settled FTC charges that it deceived consumers by making public information users had designated as private, giving third-party apps access to nearly all user data regardless of permissions, and failing to keep privacy promises. The consent decree barred deceptive privacy claims, required user consent before changing data-sharing practices, and mandated independent privacy audits for 20 years.

majorAnti-PrivacyPolicy Change

Facebook launched 'Tag Suggestions,' a facial recognition feature that automatically scanned uploaded photos and matched faces to user profiles. The feature was enabled by default with no notice, and the opt-out did not prevent biometric faceprint collection. This became the basis for the $650M Illinois BIPA and $1.4B Texas CUBI settlements.

majorAnti-PrivacyPolicy Change

Facebook overhauled its privacy settings, making users' names, profile pictures, gender, current city, friend lists, and network affiliations permanently public with no option to restrict visibility. EPIC filed an FTC complaint alleging unfair and deceptive trade practices, triggering the investigation that led to the 2011 consent decree.

moderateAnti-PrivacyPolicy Change

Facebook launched Beacon, an advertising system that tracked users' purchases and actions on 44 partner websites and broadcast them to friends' News Feeds without explicit consent. Beacon transmitted data even when users were logged out of Facebook. After massive backlash, Mark Zuckerberg apologized and made Beacon opt-out on December 5, 2007. Beacon was shut down entirely in September 2009.

Facebook Privacy News - Policy Changes, Breaches & Enforcement | PrivacyWire