US data protection

New Mexico's 44-Million-Violation Meta Verdict Punishes Deception, but Per-Statement Math Is No Privacy Policy

A jury found Facebook misled consumers about privacy and moderation. The liability finding is sound; a penalty topping $200 billion is a blunt tool.

Meta in New Mexico: The Numbers People of Internet Research · US ~44M Violations found by jury Nearly 44 million Unfair Practices… $5,000 Maximum penalty per violation Statutory ceiling; a judge sets th… $200B+ Theoretical maximum exposure If the maximum were applied to eve… $5B 2019 FTC privacy penalty Record FTC penalty over Facebook's… peopleofinternet.com
Meta in New Mexico: The Numbers People of Internet Research · US ~44M Violations found by jury $5,000 Maximum penalty per violation $200B+ Theoretical maximum exposure $5B 2019 FTC privacy penalty peopleofinternet.com

Key Takeaways

A New Mexico jury has found that Facebook violated the state's Unfair Practices Act nearly 44 million times by misleading consumers about its data-privacy and content-moderation practices, The Record reported on September 25. Each violation carries up to $5,000 in civil penalties, so the total could theoretically exceed $200 billion. A judge will set the amount in the coming weeks.

The strongest case for the verdict

The case for the state is serious, and it should be stated fairly. Deception law does not ask whether a company's privacy practices are wise. It asks whether the company's statements were true. According to The Record, jurors found that Facebook told consumers they controlled how their information was shared and that it did not buy or sell private data, particularly with advertisers. They also found that its statements about hate speech and misinformation were "willfully deceptive."

The Cambridge Analytica findings are the most concrete. The jury held that Facebook lied about its purported probe of third-party applications after the scandal. The underlying facts are not in dispute. The FTC's 2019 action against Cambridge Analytica described an app that harvested data from 50-65 million friends of its 250,000-270,000 U.S. users. If a company promises to audit apps and then does not, a consumer-protection agency is entitled to say so. That is enforcement of a promise, not regulation of a product.

Why this is not the FTC settlement again

Facebook has already paid once for related conduct. In July 2019 the FTC imposed a $5 billion penalty and a 20-year order. The agency said Facebook had let developers reach friends' data without adequate disclosure, promised in April 2014 to stop, and continued until June 2018. The order also created an independent board privacy committee and quarterly compliance certifications.

The New Mexico case shows that a federal settlement does not close the question. State attorneys general can pursue the same public statements under their own deception statutes, in front of local juries, with their own penalty formulas. That is legitimate federalism. It also means that companies face several overlapping penalty regimes for one set of facts, which is hard to price and hard to plan around.

Where the analysis gets uncomfortable

The headline number comes from a counting rule, not from a measure of harm. Forty-four million violations is roughly a per-consumer, per-statement multiplication. At the statutory ceiling, Fortune reported, exposure exceeds $200 billion. A penalty of that scale would bear no relation to any measured injury to New Mexicans. Courts have long treated grossly disproportionate penalties with suspicion under due process, and we expect Meta to make that argument on appeal.

Second, the moderation findings are more troubling than the privacy findings. Privacy statements such as "we do not sell your data" are factual claims that can be checked. Statements that Facebook "does not tolerate hate speech" or deletes "harmful" misinformation are aspirational descriptions of a contested and imperfect editorial process. No platform of Facebook's scale removes everything it says it prohibits. Treating each gap between policy and enforcement as a deception risks punishing the very act of publishing rules.

That has a speech cost. If a public community-standards page becomes a source of per-user liability, the rational response is to publish vaguer standards or none. Users would then get less information about how platforms moderate, not more. Meta has emphasized its First Amendment right to manage its platforms, per Fortune, and that argument, along with disputes over how violations are counted, will get a serious hearing on appeal.

What proportionate enforcement looks like

The verdict is best read as a narrow finding about specific broken promises, especially the post-Cambridge Analytica audit commitments. It should not be read as a template for policing moderation quality through consumer-protection statutes. We would suggest four principles for the judge and for other states:

The bigger picture

The United States still has no comprehensive federal privacy law, so consumer-deception statutes are doing work that legislation should do. States are filling the gap with juries and per-violation penalties, a method that produces enormous numbers and little clarity. A clear federal standard on data collection, sale and third-party access would let regulators penalize actual privacy failures instead of stretching deception law to cover them.

Meta will appeal, and the eventual penalty may look very different from the theoretical maximum. What should survive is the principle at the center of the case: when a platform tells users it audited apps and protected their data, it must have done so. Beyond that, the remedy should fit the harm.

Sources & Citations

  1. The Record: New Mexico jury finds Meta deceived consumers
  2. FTC: $5 billion penalty and new privacy restrictions on Facebook (2019)
  3. FTC: Cambridge Analytica action (2019)
  4. Fortune: New Mexico jury finds Facebook liable