Structural risks
These risks apply to every Meta product. They are legal obligations and corporate
practices that individual products cannot override. A subsidiary cannot opt out of an
FTC consent decree. A company cannot selectively ignore its home country's intelligence
law for one product. These risks set a grade floor of
D — no Meta product
can score better than this, regardless of its own privacy settings.
critical
Two FTC consent decrees ($5 billion)
2019-07-24
Meta is under two FTC consent decrees (2012 and 2019). The 2019 order imposed a $5 billion fine — the largest ever — and requires a privacy committee with personal liability for executives. Every product Meta makes operates under these constraints, yet violations continue.
critical
PRISM participant since 2009
2009-06-03
Facebook joined the PRISM programme in June 2009. The NSA can collect stored communications directly from Meta's servers.
critical
Cross-subsidiary data sharing
2023-05-22
Meta shares data across Facebook, Instagram, WhatsApp, Messenger, and Threads. Despite WhatsApp's end-to-end encryption, metadata (contacts, usage patterns, location) flows to Meta's advertising infrastructure. The EU fined Meta EUR 1.2 billion for transferring EU data to the US.