Facebook vs. ISO 29100: Auditing Privacy in the Age of Big Data

Compliance of the Facebook Data Use Policy with the Principles of ISO 29100:2011

2014-03-01
Alexandra K. Michota, Sokratis K. Katsikas
Summary
Problem
Method
Results
Takeaways
Abstract

This paper evaluates the compliance of Facebook's Data Use Policy against the 11 privacy principles defined in the ISO 29100:2011 standard. By mapping specific policy clauses to the international framework, the authors identify systemic gaps in how the world's largest social network handles personal identifiable information (PII).

    ## TL;DR
    Does Facebook actually respect your privacy? This paper moves beyond public opinion and conducts a rigorous academic audit. By mapping Facebook’s "Data Use Policy" against the **ISO 29100:2011** international standard, researchers Alexandra Michota and Sokratis Katsikas reveal that Facebook’s compliance is superficial at best, missing critical marks on user consent and data minimization.

    ## The Core Conflict: Policy vs. Practice
    Most Social Networking Site Service Providers (SNSSPs) present privacy policies as take-it-or-leave-it electronic contracts. The authors argue that while "Privacy by Design" is easy to preach for future systems, applying it to "legacy" titans like Facebook is complex but necessary.

    The problem isn't just about what they collect, but **how the information flows**. The study identifies a dangerous triangle between the User, the SNSSP (Facebook), and Third-Party Service Providers (advertisers/app developers).

    ## Methodology: The ISO 29100 Benchmark
    The researchers used the 11 privacy principles of ISO 29100:2011 as a "gold standard" for PII (Personally Identifiable Information) protection. These include:
    *   **Consent and Choice**: Is the user's choice freely given?
    *   **Purpose Legitimacy**: Are users informed before collection?
    *   **Data Minimization**: Is processing kept to the bare minimum?

    ![Roles and functionalities in a SNS](https://cdn.atominnolab.com/wisdoc/images/20260523-793d0236-1429-4bea-8ef1-eb48fc079c7c/page_001_block_016.png)
    *Figure 1: The complex ecosystem of SNS actors—from data analysts to sponsors—showing why PII is so vulnerable.*

    ## Key Findings: Where Facebook Fails
    The mapping results (detailed in the tables below) show a sea of "Partial Coverage" (O) rather than "Large Extent Coverage" (+).

    ### 1. The Paradox of Consent
    Facebook allows you to edit content visibility, but the audit points out that **consent is indirect**. If you don't provide PII, you can't register. There is no "middle ground" for privacy-conscious users.

    ### 2. The Persistence of Data
    Even when a user chooses "Deletion," data might remain in logs and backups for up to **90 days**. This fundamentally violates the "Use, Retention, and Disclosure Limitation" principle.

    ### 3. The Shadow of Third Parties
    Apps and plugins act as a "thread" that pulls your data out of Facebook’s ecosystem. The audit finds that "Instant Personalization" services often receive User IDs and friend lists without explicit, per-instance consent.

    ![Experimental Result Mapping Table](https://cdn.atominnolab.com/wisdoc/tables/20260523-793d0236-1429-4bea-8ef1-eb48fc079c7c/page_002_block_011.png)
    *Table 1: Adherence levels for "Information we receive"—revealing most principles are only partially satisfied.*

    ## Why It Matters: Beyond Compliance
    The study concludes that Facebook's architecture is built for **Openness and Transparency** (they tell you what they do) but fails at **Accountability and Minimization** (they don't stop doing it). 

    The results suggest that social networks need to:
    1.  **Add granular privacy preferences** that are currently omitted from menus.
    2.  **Redesign policies** for simplicity and accessibility rather than legal obfuscation.
    3.  **Implement true "Privacy by Default"**, where sharing is a proactive choice, not a pre-checked box.

    ## Conclusion
    This paper serves as a vital reality check. While Facebook claims to take privacy seriously, its policy remains a tool for legal protection rather than user empowerment. For future developers, the takeaway is clear: ISO 29100 compliance isn't just a checklist—it requires a fundamental shift in how data flows from the moment of registration.

    **Takeaway**: Real privacy requires the right to participate without the obligation to over-share.

Find Similar Papers

Try Our Examples

  • Search for recent studies comparing the privacy policies of Meta (formerly Facebook) and TikTok against the GDPR or ISO 29100:2011 standards.
  • Which paper first established the "Privacy by Design" 7 foundational principles, and how does ISO 29100:2011 incorporate these into its technical framework?
  • Explore how researchers have applied ISO 29100 privacy controls to the design of decentralized social networks (DeSoc) or Web3 platforms.
Contents
Facebook vs. ISO 29100: Auditing Privacy in the Age of Big Data
1. TL;DR
2. The Core Conflict: Policy vs. Practice
3. Methodology: The ISO 29100 Benchmark
4. Key Findings: Where Facebook Fails
4.1. 1. The Paradox of Consent
4.2. 2. The Persistence of Data
4.3. 3. The Shadow of Third Parties
5. Why It Matters: Beyond Compliance
6. Conclusion