Facebook, Instagram, and Twitter gave data access to domestic surveillance firm Geofeedia; all have blocked access after ACLU shed light on the relationship
Matt Cagle / ACLU of Northern California :
Context & Ripple Effects
The ACLU of Northern California's report forced an immediate reckoning: Facebook, Instagram, and Twitter all cut off Geofeedia's data access within days, and The Verge's follow-up revealed Facebook had itself been a Geofeedia customer before severing ties for ToS non-compliance. The story matters because it turned informal developer-API norms into a contested boundary over who may buy social data and for what purpose.
The aftermath shows the pressure compounding rather than fading: Geofeedia shed more than half its staff after losing all three feeds (31 of 60 employees), Twitter extended the logic to its own partner by cutting off Dataminr's geospatial intelligence sales to police, and Facebook eventually rewrote its platform terms to explicitly bar developers from feeding Facebook or Instagram data into surveillance tools (March 2017 policy update).
First-order effects
- Geofeedia loses its core product overnight — access to Facebook, Instagram, and Twitter data streams is blocked at the source, leaving a firm whose business was built on those APIs with nothing to sell.
- Facebook faces an awkward disclosure of its own: it was a paying Geofeedia customer even as it supplied the data, forcing it to frame the cutoff as a ToS violation rather than a policy reversal.
Second-order effects
- Twitter applies the same standard to adjacent partners, cutting off Dataminr's sale of geospatial intelligence to police under ACLU pressure — signaling that any downstream reseller of social data for surveillance is now exposed.
- Social-media-monitoring vendors lose their primary data supply chain, collapsing the market segment Geofeedia anchored and pushing buyers toward whatever narrower sources remain permitted.
Third-order effects
- Platform terms of service harden into de facto access-control law: Facebook's explicit prohibition on using developer data in surveillance tools shows civil-society pressure translating directly into written API governance, without any regulator involved.
- If the pattern holds, the permission boundary on public social data gets set case-by-case by advocacy campaigns rather than statute — a structure where a single NGO report can restructure an entire vendor category.
The trend: Access to public social-platform data is being governed less by regulators than by platform terms rewritten under advocacy pressure, turning API permissions into the real regulatory layer for surveillance technology.