A New Mexico jury has found that Facebook violated the state's Unfair Practices Act nearly 44 million times by misleading consumers about its data-privacy and content-moderation practices, The Record reported on September 25. Each violation carries up to $5,000 in civil penalties, so the total could theoretically exceed $200 billion. A judge will set the amount in the coming weeks.
The strongest case for the verdict
The case for the state is serious, and it should be stated fairly. Deception law does not ask whether a company's privacy practices are wise. It asks whether the company's statements were true. According to The Record, jurors found that Facebook told consumers they controlled how their information was shared and that it did not buy or sell private data, particularly with advertisers. They also found that its statements about hate speech and misinformation were "willfully deceptive."
The Cambridge Analytica findings are the most concrete. The jury held that Facebook lied about its purported probe of third-party applications after the scandal. The underlying facts are not in dispute. The FTC's 2019 action against Cambridge Analytica described an app that harvested data from 50-65 million friends of its 250,000-270,000 U.S. users. If a company promises to audit apps and then does not, a consumer-protection agency is entitled to say so. That is enforcement of a promise, not regulation of a product.
Why this is not the FTC settlement again
Facebook has already paid once for related conduct. In July 2019 the FTC imposed a $5 billion penalty and a 20-year order. The agency said Facebook had let developers reach friends' data without adequate disclosure, promised in April 2014 to stop, and continued until June 2018. The order also created an independent board privacy committee and quarterly compliance certifications.
The New Mexico case shows that a federal settlement does not close the question. State attorneys general can pursue the same public statements under their own deception statutes, in front of local juries, with their own penalty formulas. That is legitimate federalism. It also means that companies face several overlapping penalty regimes for one set of facts, which is hard to price and hard to plan around.
Where the analysis gets uncomfortable
The headline number comes from a counting rule, not from a measure of harm. Forty-four million violations is roughly a per-consumer, per-statement multiplication. At the statutory ceiling, Fortune reported, exposure exceeds $200 billion. A penalty of that scale would bear no relation to any measured injury to New Mexicans. Courts have long treated grossly disproportionate penalties with suspicion under due process, and we expect Meta to make that argument on appeal.
Second, the moderation findings are more troubling than the privacy findings. Privacy statements such as "we do not sell your data" are factual claims that can be checked. Statements that Facebook "does not tolerate hate speech" or deletes "harmful" misinformation are aspirational descriptions of a contested and imperfect editorial process. No platform of Facebook's scale removes everything it says it prohibits. Treating each gap between policy and enforcement as a deception risks punishing the very act of publishing rules.
That has a speech cost. If a public community-standards page becomes a source of per-user liability, the rational response is to publish vaguer standards or none. Users would then get less information about how platforms moderate, not more. Meta has emphasized its First Amendment right to manage its platforms, per Fortune, and that argument, along with disputes over how violations are counted, will get a serious hearing on appeal.
What proportionate enforcement looks like
The verdict is best read as a narrow finding about specific broken promises, especially the post-Cambridge Analytica audit commitments. It should not be read as a template for policing moderation quality through consumer-protection statutes. We would suggest four principles for the judge and for other states:
- Penalize the verifiable falsehoods. Claims about data sales, user controls and app audits can be tested against evidence. Claims about the effectiveness of moderation generally cannot.
- Tie penalties to harm and gain. A figure grounded in Facebook's unlawful revenue or documented consumer injury is defensible. A figure derived from multiplying users by statements is not.
- Prefer injunctions that change conduct. Independent audits, honest disclosures and verified deletion do more for privacy than a large check, particularly against a company with margins that can absorb the fine. Fortune quoted one expert doubting that a penalty would meaningfully discipline Meta.
- Coordinate with federal orders. The FTC's 20-year order already covers privacy governance. State remedies should add to it, not duplicate or contradict it.
The bigger picture
The United States still has no comprehensive federal privacy law, so consumer-deception statutes are doing work that legislation should do. States are filling the gap with juries and per-violation penalties, a method that produces enormous numbers and little clarity. A clear federal standard on data collection, sale and third-party access would let regulators penalize actual privacy failures instead of stretching deception law to cover them.
Meta will appeal, and the eventual penalty may look very different from the theoretical maximum. What should survive is the principle at the center of the case: when a platform tells users it audited apps and protected their data, it must have done so. Beyond that, the remedy should fit the harm.