Facebook vs. The Law: The Fundamental Conflict Between Social Media Growth and Privacy Principles
13540_Privacy Compliance Risks for Facebook.
This paper critically evaluates Facebook's data practices against the OECD Privacy Principles and the Australian Privacy Act 1988. It specifically identifies systematic compliance risks in "Find Friends" (address book importing) and "Places" (location tagging) features, concluding that Facebook's business model inherently conflicts with the Collection Limitation Principle.
TL;DR
This seminal analysis explores how Facebook’s core growth mechanics—importing contact lists and real-time location tagging—violate established global privacy frameworks. The authors argue that Facebook isn't just a platform but an "information company" whose business model requires the erosion of privacy norms, creating significant compliance risks under Australian and OECD standards.
Academic Positioning: This work acts as a bridge between early 2010s tech-optimism and the current era of "Big Tech" regulatory scrutiny, specifically targeting the gap between Terms of Service and actual Information Privacy Law.
The Core Tension: Profit vs. Principle
The central argument of Johnston and Wilson is that Facebook’s business model depends on Information Flux. If the company adheres strictly to the Collection Limitation Principle (only collecting what is strictly necessary), its valuation would likely collapse because its primary asset is the depth and breadth of its user data.
The authors highlight a "Fundamental Clash":
- The Law: Requires data collection to be fair, necessary, and transparent.
- The Platform: Encourages "promiscuity" in data sharing to train users to abandon privacy norms.
Methodology: Auditing the "Shadow" Collection
The authors dissect two primary features where Facebook collects data indirectly—gathering information about people who may not even be on the platform.
1. Indirect Contact Importation
When a new user clicks "Find Friends," Facebook uses an API to suck in their entire external email address book.
- The Deception: Users are told it's to "find friends."
- The Risk: Facebook gains "Relationship" data on non-users without their consent. For sensitive professions (e.g., mental health doctors), this can inadvertently expose patient-doctor links if a doctor uploads their contact list.
2. Location-Based "Tagging"
The "Places" feature (introduced to compete with Foursquare) allows User A to "tag" User B at a specific location.
- The Breach: By the time User B receives a notification and removes the tag, the data—that they were at a specific bar, clinic, or protest—has already been broadcasted. This violates the principle that personal information should be collected directly from the individual whenever practicable.
Legend: The study emphasizes that while registration is made intentionally easy, the legal "Fine Print" has grown exponentially in complexity.
Anatomy of a Privacy Breach
The paper uses the Australian National Privacy Principles (NPPs) as a diagnostic tool.
| Principle | Facebook's Practice | Evaluation |
|---|---|---|
| NPP 1.1 (Necessity) | Collecting full address books by default. | Non-compliant: Not "necessary" for core functions. |
| NPP 1.2 (Fair Means) | Peer-tagging of locations. | Intrusive: Does not allow for pre-approval. |
| NPP 1.3 (Transparency) | Privacy settings only visible after registration. | Breach: Information should be available at/before collection. |
Critical Insight: The "Bundled Consent" Fallacy
One of the most important takeaways for technical architects is the debunking of Bundled Consent. Facebook argues that by clicking "Sign Up," a user consents to the entire Privacy Policy.
The authors argue this is legally invalid because:
- Complexity: A 6,000-word document is not "informed" consent for the average user.
- Dynamic Shifts: Periodic changes to default settings (making more data "Public" by default) cannot be covered by a one-time agreement from years prior.
- Third-Party Data: You cannot consent to the collection of other people's data (your contacts), yet the system is built on this very premise.
Conclusion & Future Outlook
The paper concludes that Facebook is "actively training" society to accept lower privacy standards to fuel its growth. For researchers and developers today, this serves as a warning: User behavior is directed by site design. If a system is designed to favor "sharing," users will share, but that behavior should not be mistaken for a genuine shift in societal values.
Limitations: The paper focuses on the 2012 landscape. Since then, GDPR (Europe) and CCPA (California) have introduced much stricter "Privacy by Design" requirements that address many of the "bundled consent" issues raised here, though the core conflict of "monetizing information" remains unresolved in the OSN industry.
Note: This analysis is based on the paper "Facebook and the Law" by Anna Johnston and Stephen Wilson (2012).
