Facebook gave 60+ device makers, including Apple, Amazon, and Samsung, deeper access to users' personal info than previously known, through private APIs
The company formed data-sharing partnerships with Apple, Samsung and dozens of other device makers, raising new concerns about its privacy protections.
Context & Ripple Effects
This report opened the arc that defined Facebook's 2018-2019 privacy crisis: beyond the app-permission scandals, the company had built private-API pipelines to roughly 150 partners — including Apple, Amazon, and Samsung — that sat outside the public permission system users actually see. Device-integration deals were the least examined corner of Facebook's data-sharing architecture because they were never surfaced in privacy settings.
The follow-on coverage shows why the disclosure mattered: Sen. Ron Wyden later published Facebook's admission that it had ignored a government-approved auditor's 2013 warnings about partner misuse, and by March 2019 the partnerships were reportedly under federal criminal investigation, with a New York grand jury subpoenaing at least two of the device-makers involved.
First-order effects
- Apple, Amazon, Samsung, and the other 60+ hardware partners held deeper access to user information through private APIs than Facebook had publicly acknowledged, putting their own privacy practices under immediate scrutiny.
- Users learned that data flows to device makers were invisible to the standard app-permission controls they were told governed their information.
Second-order effects
- Facebook was forced into a defensive posture against its FTC consent decree, arguing in December that integration-partner sharing only occurred when users signed in with Facebook accounts — a distinction regulators then had to test.
- Device makers became co-defendants in the narrative rather than neutral platforms, with at least two partners reportedly subpoenaed in the federal probe.
Third-order effects
- If the pattern holds, hardware-software integration deals become a regulated disclosure category of their own, with auditors and prosecutors treating partner APIs as part of a platform's compliance perimeter rather than a private commercial arrangement.
The trend: Platform data-sharing is shifting from opaque bilateral partnerships toward externally audited, regulator-visible access boundaries, with device makers pulled inside the compliance perimeter.