Study finds the US FAFSA application page shared users' info, including names, zip codes, and email addresses, with Meta via the company's tracking pixel
apparently including while doing something as private as applying for government financial aid. Read the full report from @suryamattu and @colinlecher today. https://themarkup.org/... Frank Bajak / @fbajak : The U.S. Department of Education was sharing student financial loan application data with Facebook ... until @themarkup exposed it. https://twitter.com/... @themarkup : “They are sloppy and they are not focused on doing their job in general on the issue of privacy,” said @leoniehaimson, co-chair of the Parent Coalition for Student Privacy. https://themarkup.org/... @juwanthewriter : Social media Financial aid orgs 🤝 Preying on young ppl for gain https://twitter.com/... Jason Kint / @jason_kint : For those who read the @lorenzofb Vice report earlier this week on the leaked internal Facebook document about how it doesn't know what it does with your data, I would assume this financial aid data is now also “in the lake” and there is nothing you can do about it. Chaos. https://twitter.com/... Brooke Binkowski / @brooklynmarie : Incredibly disgusting shit from @Meta as usual https://twitter.com/... @themarkup : For prospective college students, applying online for federal financial aid also meant sharing personal data with Facebook. https://themarkup.org/...
Context & Ripple Effects
This is not the first time the FAFSA site has been caught mishandling applicant data: back in 2017 researchers showed an SSN-plus-birthdate flaw on the same portal that echoed an IRS tool pulled months earlier. What changed with The Markup's report is the direction of the leak — not a break-in, but the Education Department itself wiring applicants' names, zip codes, and email addresses to Meta through a tracking pixel while they applied for aid.
The finding also slots into a documented pattern around student and financial data: universities were already shown working with outside firms to data mine and rank prospective students, and The Markup's later Warren-led investigation of tax filing tools found the same pixel-to-Meta pipeline carrying income data — suggesting the FAFSA case was one instance of a broader government-and-finance-to-ad-platform leak.
First-order effects
- Applicants who used the FAFSA page had financial-aid application details transmitted to Meta for advertising purposes, and the Education Department now owns the cleanup: pulling the pixel and answering for why a benefits portal carried commercial trackers at all.
- The Parent Coalition for Student Privacy, quoted in the coverage calling the agency 'sloppy' on privacy, gains a concrete grievance to press against the Department, which had positioned the site as a secure gateway for aid.
Second-order effects
- Every other federal and state benefits site running Meta or Google analytics faces the same question, since the FAFSA precedent shows the exposure comes from standard embed code rather than any hack — auditors and lawmakers need no new evidence to demand pixel audits.
- Meta's ad-targeting machinery takes fresh reputational damage in exactly the verticals where it is already vulnerable: the company was previously flagged for letting financial-services advertisers target restricted age groups in violation of its own anti-discrimination policies, and aid-adjacent targeting deepens that regulatory exposure.
Third-order effects
- If the pattern holds across FAFSA, tax software, and university recruitment, the structural issue is that public institutions adopt commercial analytics tooling with no privacy gatekeeping, leaving journalists — not regulators or internal review — as the discovery mechanism.
- That dynamic points toward formal requirements for privacy review of government web properties and stricter limits on what data ad platforms may receive from public-benefit workflows, turning each exposed agency into a case study for legislation.
The trend: Sensitive government and financial workflows are being quietly wired into ad-platform tracking infrastructure, with the leaks surfacing through investigative reporting faster than institutional oversight can catch them.