Security News

New Mexico Jury Finds Meta Deceived Users on Data Privacy, Nearly 44 Million Times

The Record · 29 Sept 2026
Key Takeaway Australian small businesses using platforms like Facebook for advertising or customer engagement should regularly review how those platforms handle user data and avoid over-relying on their privacy claims.

A New Mexico jury has found that Facebook, owned by Meta, violated the state's Unfair Practices Act nearly 44 million times by misleading consumers about its data privacy practices. Each violation can carry a civil penalty of up to $5,000, meaning the final damages, to be decided by a judge, could reach billions of dollars.

Jurors concluded that Facebook falsely claimed users controlled how their information was shared and that it did not buy or sell private data to advertisers. The jury also found the company's statements about hate speech and misinformation to be 'willfully deceptive,' including claims it did not profit from harmful content, that it removed misinformation, and that it applied its community standards evenly without special protections or exceptions for politicians or high-profile figures.

The jury further determined that Facebook lied about promises made after the Cambridge Analytica scandal to investigate apps that accessed large amounts of user data, conduct audits, cut ties with developers who misused data, and notify affected users. This case adds to a growing list of legal actions against Meta over its data privacy record, which has already resulted in tens of billions of dollars in penalties.

data privacy Meta Facebook consumer protection regulation
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.