Sources: SEC has asked Facebook how much it knew about Cambridge Analytica's use of user data and how it analyzed the risk of developers sharing data improperly
WSJ Tweets: The Wall Street / @wsj : The SEC is investigating whether Facebook properly warned investors that developers and other third parties obtained user data without permission http://www.wsj.com/... Shalini Ramachandran / @shalini : The SEC is investigating whether Facebook gave investors adequate warning about what it had learned about the Cambridge Analytica data breach in 2015 http://www.wsj.com/... via @WSJ
Context & Ripple Effects
The SEC inquiry lands four months into Facebook's Cambridge Analytica damage-control arc: after the scandal surfaced, Facebook moved first on commercial trust, quietly reassuring ad agencies and trade bodies that customer data was protected, then turned inward with a developer audit that found some big data-takers out of business or refusing to cooperate.
What makes the SEC's questions pointed is that Facebook effectively documented the risk itself: in an April filing with the very agency now asking, it warned it might find more Cambridge Analytica-sized instances of misuse. The investigation is testing whether that filing — and earlier silence about the 2015 breach — met the bar for adequately warning investors.
First-order effects
- Facebook now faces a formal SEC inquiry into whether its disclosures about developer data-sharing risks were adequate, putting its 2015 knowledge of Cambridge Analytica and its internal risk analysis directly under securities-law examination.
- Facebook's own quarterly report to the SEC — flagging possible further misuse — becomes a key document in determining what the company knew and when it told investors.
Second-order effects
- The developer ecosystem Facebook just audited comes under sharper scrutiny: findings that large data-takers are defunct or uncooperative feed directly into the disclosure question, raising the cost of loose platform data access for every remaining developer.
- Advertisers, whom Facebook spent March reassuring after the scandal broke, face renewed uncertainty as the dispute shifts from public-relations management to a regulator probing what the company withheld.
Third-order effects
- If the pattern holds, platform companies' data-governance failures become securities-disclosure events rather than mere privacy scandals — forcing firms to treat developer-data risk analysis as material information for investors, not just users.
- The episode pushes platforms toward rebuilding their consent architecture around third-party data access, since the gap the SEC is probing — developers sharing data improperly — is precisely the layer where user permission was never enforced.
The trend: Platform data scandals are migrating from consumer-privacy crises into securities-regulation territory, with regulators treating what companies knew about third-party data misuse as a disclosure question.