Facebook confirms Spotify, Netflix, Dropbox, and RBC had read/write/delete access for messaging integrations, says it was experimental and ended three years ago
In the past day, we've been accused of disclosing people's private messages to partners without their knowledge.
Context & Ripple Effects
This confirmation lands one day after the New York Times reported internal docs showing Facebook gave roughly 150 companies broader access than disclosed, with some able to read private DMs — a story Facebook answered by insisting sharing happened only when users signed in with their Facebook accounts on other platforms. The company is now conceding the sharpest version of the allegation: read/write/delete message access for four household-name partners.
The timing compounds pressure from the prior arc of coverage — June reporting that partner friend-data access continued after the 2015 developer shutdown, Wednesday's 7% stock drop, and a District of Columbia AG lawsuit. Each disclosure narrows the gap between what Facebook told regulators and what its integration program actually did.
First-order effects
- Spotify, Netflix, Dropbox, and RBC are suddenly named parties in a privacy scandal they didn't disclose themselves — each must decide whether to confirm the scope of its messaging integration or stay quiet while Facebook frames it as an ended experiment.
- Facebook's 'experimental and ended three years ago' defense puts its compliance with the FTC consent decree back in play, directly rebutting its own earlier claim that no violation occurred.
Second-order effects
- Other integration partners not yet named face a disclosure race: if more companies had message-level access, partners will want to get ahead of being outed by documents rather than by Facebook.
- Consumer brands weighing Facebook Login integrations now price in headline risk — the sign-in-with-Facebook value proposition weakens precisely because the exchange was broader than users understood.
Third-order effects
- If the pattern holds — broad partner access persisting past public shutdowns — platform data-sharing moves from self-policed API programs toward regulator-audited access controls, with the FTC decree as the test case for whether consent decrees can constrain platform intermediaries at all.
The trend: Platform data-access programs built on user sign-in consent are being repriced as regulatory and reputational liabilities, forcing platforms to treat partner API access as a security boundary rather than a growth channel.