Sources: Facebook's probe of its platform's developers finds that some developers who took large chunks of data are out of business and some won't cooperate
Deepa Seetharaman / Wall Street Journal : Tweets: @rebeccaballhaus and @rmac18 Tweets: Rebecca Ballhaus / @rebeccaballhaus : Three months in, Facebook's internal probe into the potential misuse of user data is hitting a snag: The company can't track where much of the data went after it left the platform or figure out where it is now. http://www.wsj.com/... Ryan Mac / @rmac18 : This is unsurprising and echoes what experts like @ashk4n have said: Once the data is out there, it's impossible to get back. Also a pretty good argument for why Facebook shouldn't be in charge of auditing or regulating itself. http://www.wsj.com/...
Context & Ripple Effects
The probe is Facebook's answer to the Cambridge Analytica fallout: after suspending quiz-app firm CubeYou and hiring an outside forensics team whose Cambridge Analytica audit was cut short when the UK ICO asked it to step down, the company turned inward to audit its own developer ecosystem. Three months in, sources tell the Journal the effort is stalling — much of the extracted data cannot be traced once it left the platform, and some heavy-extraction developers are defunct while others refuse to cooperate.
That stall lands on top of an existing legal exposure: former FTC officials had already argued Facebook's data practices may breach its 2011 privacy consent decree, and weeks later the SEC asked how much Facebook knew about improper developer data sharing. A self-audit that cannot locate the data undermines the company's ability to demonstrate remediation to either regulator.
First-order effects
- Facebook's audit deliverable is compromised: with defunct and uncooperative developers, the company cannot produce a complete accounting of where large data extracts went, weakening its position with the FTC and UK ICO.
- Developers who took bulk data now face a choice between cooperating with Facebook's probe or leaving the company unable to verify misuse — but cooperation offers them little protection since the data itself is already dispersed.
Second-order effects
- Regulators are pushed toward independent verification rather than self-reporting: the forensics-firm episode showed even Facebook's chosen auditors can be sidelined, so the FTC and SEC have reason to demand their own access rather than accept Facebook's findings.
- Other platform operators watching this face the same audit problem — any developer ecosystem built on broad data access inherits the same untraceability, raising the cost of defending similar API programs.
Third-order effects
- If data extraction at scale is effectively irreversible, the durable fix moves upstream: platforms restricting what developers can pull in the first place, and external bodies — not the platform — auditing the pipeline, since Ryan Mac and privacy experts argue the data's dispersal is precisely why Facebook should not be its own regulator.
The trend: Platform data governance is shifting from post-hoc self-audits toward upstream access limits and externally enforced oversight, because extracted user data cannot be recalled once it leaves the platform.