Facebook vs. ISO 29100: Auditing Privacy in the Age of Big Data
Compliance of the Facebook Data Use Policy with the Principles of ISO 29100:2011
2014-03-01
Summary
Problem
Method
Results
Takeaways
Abstract
This paper evaluates the compliance of Facebook's Data Use Policy against the 11 privacy principles defined in the ISO 29100:2011 standard. By mapping specific policy clauses to the international framework, the authors identify systemic gaps in how the world's largest social network handles personal identifiable information (PII).
## TL;DR
Does Facebook actually respect your privacy? This paper moves beyond public opinion and conducts a rigorous academic audit. By mapping Facebook’s "Data Use Policy" against the **ISO 29100:2011** international standard, researchers Alexandra Michota and Sokratis Katsikas reveal that Facebook’s compliance is superficial at best, missing critical marks on user consent and data minimization.
## The Core Conflict: Policy vs. Practice
Most Social Networking Site Service Providers (SNSSPs) present privacy policies as take-it-or-leave-it electronic contracts. The authors argue that while "Privacy by Design" is easy to preach for future systems, applying it to "legacy" titans like Facebook is complex but necessary.
The problem isn't just about what they collect, but **how the information flows**. The study identifies a dangerous triangle between the User, the SNSSP (Facebook), and Third-Party Service Providers (advertisers/app developers).
## Methodology: The ISO 29100 Benchmark
The researchers used the 11 privacy principles of ISO 29100:2011 as a "gold standard" for PII (Personally Identifiable Information) protection. These include:
* **Consent and Choice**: Is the user's choice freely given?
* **Purpose Legitimacy**: Are users informed before collection?
* **Data Minimization**: Is processing kept to the bare minimum?

*Figure 1: The complex ecosystem of SNS actors—from data analysts to sponsors—showing why PII is so vulnerable.*
## Key Findings: Where Facebook Fails
The mapping results (detailed in the tables below) show a sea of "Partial Coverage" (O) rather than "Large Extent Coverage" (+).
### 1. The Paradox of Consent
Facebook allows you to edit content visibility, but the audit points out that **consent is indirect**. If you don't provide PII, you can't register. There is no "middle ground" for privacy-conscious users.
### 2. The Persistence of Data
Even when a user chooses "Deletion," data might remain in logs and backups for up to **90 days**. This fundamentally violates the "Use, Retention, and Disclosure Limitation" principle.
### 3. The Shadow of Third Parties
Apps and plugins act as a "thread" that pulls your data out of Facebook’s ecosystem. The audit finds that "Instant Personalization" services often receive User IDs and friend lists without explicit, per-instance consent.

*Table 1: Adherence levels for "Information we receive"—revealing most principles are only partially satisfied.*
## Why It Matters: Beyond Compliance
The study concludes that Facebook's architecture is built for **Openness and Transparency** (they tell you what they do) but fails at **Accountability and Minimization** (they don't stop doing it).
The results suggest that social networks need to:
1. **Add granular privacy preferences** that are currently omitted from menus.
2. **Redesign policies** for simplicity and accessibility rather than legal obfuscation.
3. **Implement true "Privacy by Default"**, where sharing is a proactive choice, not a pre-checked box.
## Conclusion
This paper serves as a vital reality check. While Facebook claims to take privacy seriously, its policy remains a tool for legal protection rather than user empowerment. For future developers, the takeaway is clear: ISO 29100 compliance isn't just a checklist—it requires a fundamental shift in how data flows from the moment of registration.
**Takeaway**: Real privacy requires the right to participate without the obligation to over-share.
