Admitting Tracking ‘Bug’, Facebook Defends European Privacy Practices
Lisa Fleisher / Wall Street Journal :
Context & Ripple Effects
This lands two weeks after Belgium's data regulator concluded that Facebook tracks logged-out, explicitly opted-out, and unregistered users in breach of EU privacy law. Facebook's response is a dual move: recast part of that tracking as a "bug" while defending its broader European privacy practices as compliant.
It matters because the framing sets the template for years of Facebook regulatory positioning — from its later claim that EU privacy rules could weaken its defenses against hacking and fraud, to contending its web tracking doesn't qualify as a "sale" under California's CCPA.
First-order effects
- Facebook buys rhetorical distance from the Belgian regulator's findings by attributing tracking of non-consenting users to an accidental defect rather than policy, while keeping its opt-in European data practices on record as intentional and lawful.
Second-order effects
- National regulators weighing enforcement now face a test case: if the "bug" framing sticks, it lowers the bar for other platforms to reclassify contested tracking as error; if it fails, the Belgian finding becomes precedent for action against logged-out tracking across the EU.
Third-order effects
- If the pattern holds — minimal notification under GDPR to cap fine exposure, narrow definitional fights like CCPA, and slow remediation of SDK-level data flows as New York later found — platform compliance becomes a litigation posture rather than a design principle, pushing regulators toward structural remedies instead of per-incident rulings.
The trend: Facebook is pioneering a defensive compliance playbook — admit defects narrowly, defend practices broadly, contest legal definitions — that shapes how US platforms meet successive waves of EU and state privacy regulation.