A New Mexico jury has found Facebook liable for misleading users about privacy protections under the state’s consumer protection law. The verdict followed a two-week trial focused on statements about user data safeguards and the company’s oversight of third-party applications. The judge will determine penalties separately.
The verdict covers more than 43 million violations
New Mexico’s Department of Justice said jurors found more than 43 million violations. The state argued that Facebook misrepresented protections around data collected through third-party applications, including conduct associated with the Cambridge Analytica scandal. The jury also found that the company misled the public about reviews of outside developers that accessed user information.
Meta disputed the verdict and said it would continue to defend its privacy record. Jurors did not accept every state allegation, and the final financial consequence remains unresolved until the penalty phase. Reporting should therefore distinguish the liability finding from any future award.
Privacy claims need verifiable controls
Digital platforms should be able to demonstrate how third-party access is reviewed, how violations are detected and how public privacy statements map to operational controls. Audit evidence should cover data flows, developer permissions and remediation. SectechMedia tracks related issues in its cybersecurity coverage.

Leave a Reply