Interviews with 20 current and former Meta and Google staff say FTC consent decrees blocked some user data harvesting, but they are now outdated and inadequate
Google's doomed social network Buzz led US regulators to force Google and Meta to monitor their own data use. X: @jason_kint and @jason_kint X: Jason Kint / @jason_kint : Here is the full piece which to reporter @peard33 credit provides a lot of the history and context and doesn't get snowed by Meta's attempt to rewrite the narrative on the value of a consent decree tightening around its neck. https://www.wired.com/... Jason Kint / @jason_kint : What a load of absolute &$&&$ garbage. Meta's chief privacy officer told me same thing in 2014. That same summer users' private data was being sold, they then covered it up for years and buried the damning platform-wide audit Zuckerberg promised Congress. Same leadership. [image]
Context & Ripple Effects
The reporting revisits a compliance model created after Buzz, with former and current employees describing decrees as having constrained some data practices while no longer matching the companies’ operating realities. That matters because the FTC was already seeking to tighten Meta’s obligations through a proposed restriction on monetizing children’s data.
The adequacy of those obligations is not merely theoretical: Meta had challenged the FTC’s effort to alter its 2020 settlement in court, making the fight over the agency’s authority to modify the order a central test of whether legacy decrees can be updated.
First-order effects
- The accounts put Meta and Google’s decree-based privacy oversight under renewed scrutiny, highlighting a gap between internal monitoring requirements and the data practices they are meant to govern.
- For Meta, the reporting strengthens the context around the FTC’s proposed changes to its existing order; for Google, it renews attention on whether self-monitoring remains a sufficient control.
Second-order effects
- Companies operating under long-lived privacy orders face pressure to show that their compliance programs cover current products and data flows, rather than only the conduct that originally triggered the decree.
- Regulators may favor more specific limits and user choices alongside broad monitoring mandates, as reflected in Meta’s UK commitment to give Marketplace users an opt-out for certain data uses.
Third-order effects
- If legacy consent decrees repeatedly lag product changes, privacy enforcement could shift from static, company-specific settlements toward requirements that are easier to revise and verify over time.
- The larger unresolved issue is whether self-auditing can provide credible accountability when the regulated company controls the underlying systems and evidence.
The trend: This is one data point in a shift from one-time privacy settlements toward more adaptive, enforceable controls over how platforms use personal data.