Internal docs show Facebook gave ~150 companies access to more user data than disclosed; some could read private DMs; Facebook says it didn't violate FTC decree
Internal documents show that the social network gave Microsoft, Amazon, Spotify and others far greater access to people's data than it has disclosed.
Context & Ripple Effects
This lands six months after reporting that Facebook had given 60+ device makers deeper data access through private APIs than it had acknowledged — the same pattern, now documented internally and scaled to roughly 150 companies including Microsoft, Amazon, and Spotify. Within two days, Facebook confirmed that Spotify, Netflix, Dropbox, and RBC held read/write/delete access for messaging integrations, calling it an experiment ended three years prior.
The stakes are the 2011 FTC consent decree: Facebook asserts the arrangements did not violate it, putting its own compliance reading directly against the documents' contents. It also fits a longer arc of internal records contradicting public claims, from researcher datasets covering half of US users rather than all to presentations touting dominance over 78% of US adults.
First-order effects
- Microsoft, Amazon, Spotify, and the other named partners are thrust into the story as recipients of undisclosed access, forcing each to account for what they received and whether any of it touched private messages.
- Facebook's claim of FTC-decree compliance is now a testable assertion, since the internal documents define exactly what was shared and with whom.
Second-order effects
- The FTC faces pressure to treat partner data-sharing as a decree question rather than a privacy-policy dispute, making enforcement posture toward Facebook the immediate variable.
- Other platforms holding similar integration deals must decide whether to pre-disclose them or wait to be documented, as Spotify and Netflix were after Facebook's confirmation.
Third-order effects
- If internal-docs-versus-public-claims keeps recurring across separate episodes, the durable fix regulators reach for is audited, inventoried data-access agreements rather than self-certified compliance — shifting partnership governance from contract to oversight.
- Partners may reprice the risk of deep platform integrations generally, favoring narrow, revocable permissions over privileged APIs.
The trend: Platform data partnerships are moving from opaque bilateral API privileges toward externally verifiable permission boundaries, driven by leaked internal records outrunning official disclosures.