Facebook’s Civil Rights Audit
law enforcement’s use of Facebook and access to Facebook data, data scraping, end-to-end encryption and
COVID- tracing.
By providing transparency on these issues, the Auditors’ goal is to inform future conversations between Facebook
and advocates on the company’s current policies and practices. While intervening events (such as time-sensitive
Census and election-related issues and the COVID-19 crisis) prevented the Auditors from conducting the kind of
comprehensive analysis of Facebook’s privacy policies and practices necessary to make detailed recommendations,
the Auditors hope that this chapter helps lay the groundwork for future engagement, analysis, and advocacy on
privacy issues at Facebook.
A. Privacy Changes from FTC Settlement
In July 2019, Facebook entered into a $5 billion settlement with the Federal Trade Commission (FTC) to resolve
claims stemming from allegations that Facebook violated a prior agreement with the FTC by giving entities access to
data that users had not agreed to share. That settlement was formally approved in court in April 2020. The agreement
requires a fundamental shift in the way Facebook approaches building products and provides a new framework for
protecting people’s privacy and the information they give Facebook.
Through the settlement, Facebook has agreed to significant changes to its privacy policies and the infrastructure
it has built for flagging and addressing privacy risks. Specifically, under the settlement Facebook will, among
other things:
•
Develop a process for documenting and addressing identified privacy risks during the product development process;
•
Conduct a privacy review of every new or modified product, service, or practice before it is implemented and
document its decisions about user privacy;
•
Create a committee on its Board of Directors responsible for independently reviewing Facebook’s compliance
with its privacy commitments under the settlement;
•
Designate privacy compliance officer(s) responsible for implementing Facebook’s compliance program who are
removable solely by the Board committee
•
Engage an independent privacy assessor whose job will be to review Facebook’s privacy program on an
ongoing basis and report to the Board committee and the FTC, if they see compliance breakdowns or
opportunities for improvement;
•
Provide to the FTC quarterly and annual certifications signed by Mark Zuckerberg attesting to the compliance
of the Privacy Program; and
•
Report to the FTC any incidents in which Facebook has verified or otherwise confirmed that the personal
information of 500 or more users was likely to have been improperly accessed, collected, used, or shared by a
third party in a manner that violates the terms under which Facebook shared the data with them.
84