Oculus begins rolling out GDPR-compliant changes including a user-facing Privacy Center, updated ToS, and new Code of Conduct for users
While Facebook is still struggling to regain user trust following a data fiasco that ultimately brought Zuckerberg to testify in front of Congress …
Context & Ripple Effects
This lands mid-arc for Facebook: after the data fiasco that sent Zuckerberg to Congress, the company is racing to be GDPR-ready before the May 25 enforcement date, having already debuted enhanced privacy controls globally, starting in the EU. TechCrunch's companion piece argues those changes comply with the letter but not the spirit of GDPR, given a consent interface built to push users toward yes.
What changed today is scope: the same Privacy Center, refreshed ToS, and a new Code of Conduct are now rolling out on Oculus, meaning Facebook's consent-and-terms machinery is being extended from the social network to its hardware business.
First-order effects
- Oculus users immediately get a user-facing Privacy Center and a new Code of Conduct, with their terms of service realigned to Facebook's GDPR rollout just weeks before enforcement begins.
- The update puts Facebook's hardware arm inside the same consent architecture it built for the social platform, so VR owners now encounter the same ad-choice and data-permission flows critiqued as letter-of-the-law compliance.
Second-order effects
- Because Facebook plans to move 1.5B non-EU users onto US rather than Irish terms in May, limiting GDPR's reach to about 400M people, most Oculus owners will sit outside GDPR protection — making this rollout substantively an EU-region change even though it ships globally.
- If the letter-versus-spirit critique sticks, regulators reviewing one Facebook property have a template for examining them all, raising the cost of minimal-compliance design across the portfolio.
Third-order effects
- The pattern points toward compliance becoming a negotiated process rather than a self-certified one — consistent with Facebook later agreeing in the EU to rewrite its terms and clarify how user data feeds profiling and ad targeting.
- If the structure holds, privacy infrastructure becomes a baseline feature of any platform Facebook owns, hardware included, with jurisdiction carve-outs — not product choices — determining which users actually receive the stronger protections.
The trend: GDPR is forcing Facebook to standardize consent flows and terms across every property it owns, while deliberate jurisdictional carve-outs determine which users actually get the protections.