Facebook’s Civil Rights Audit law enforcement’s use of Facebook and access to Facebook data, data scraping, end-to-end encryption and COVID- tracing. By providing transparency on these issues, the Auditors’ goal is to inform future conversations between Facebook and advocates on the company’s current policies and practices. While intervening events (such as time-sensitive Census and election-related issues and the COVID-19 crisis) prevented the Auditors from conducting the kind of comprehensive analysis of Facebook’s privacy policies and practices necessary to make detailed recommendations, the Auditors hope that this chapter helps lay the groundwork for future engagement, analysis, and advocacy on privacy issues at Facebook. A. Privacy Changes from FTC Settlement In July 2019, Facebook entered into a $5 billion settlement with the Federal Trade Commission (FTC) to resolve claims stemming from allegations that Facebook violated a prior agreement with the FTC by giving entities access to data that users had not agreed to share. That settlement was formally approved in court in April 2020. The agreement requires a fundamental shift in the way Facebook approaches building products and provides a new framework for protecting people’s privacy and the information they give Facebook. Through the settlement, Facebook has agreed to significant changes to its privacy policies and the infrastructure it has built for flagging and addressing privacy risks. Specifically, under the settlement Facebook will, among other things: • Develop a process for documenting and addressing identified privacy risks during the product development process; • Conduct a privacy review of every new or modified product, service, or practice before it is implemented and document its decisions about user privacy; • Create a committee on its Board of Directors responsible for independently reviewing Facebook’s compliance with its privacy commitments under the settlement; • Designate privacy compliance officer(s) responsible for implementing Facebook’s compliance program who are removable solely by the Board committee • Engage an independent privacy assessor whose job will be to review Facebook’s privacy program on an ongoing basis and report to the Board committee and the FTC, if they see compliance breakdowns or opportunities for improvement; • Provide to the FTC quarterly and annual certifications signed by Mark Zuckerberg attesting to the compliance of the Privacy Program; and • Report to the FTC any incidents in which Facebook has verified or otherwise confirmed that the personal information of 500 or more users was likely to have been improperly accessed, collected, used, or shared by a third party in a manner that violates the terms under which Facebook shared the data with them. 84

Select target paragraph3