According to a leaked internal paper written by Facebook privacy experts last year, the company is unable to determine where most of its user data is stored or how it is utilized once it is gathered. The group in charge of building and maintaining Facebook's ad system, which is at the heart of the company's revenue model, has identified "data lineage" concerns with the way user data is handled. The analysis raises concerns about Facebook's ability to comply with inbound privacy requirements from different parts of the world.
Facebook's Ad and Business Product privacy engineers sought to identify flaws with the company's management of personal data and asked for improvements to the present system as per the leaked 2021 report obtained by Motherboard.
The developers warn that Facebook has "created systems with open borders," likening it to emptying a bottle of ink (representing third-party data, first-party data, and other sensitive information) into a lake (Facebook's open data systems) and then attempting to put the ink back in the bottle.
The research forewarns of impending legislation from governments all over the world, which have begun to press for stricter regulations for social media businesses that manage user data. "We don't have enough control and transparency over how our systems use data, so we can't make confident policy changes or external pledges like 'we won't use X data for Y reason.' " And yet, this is exactly what regulators expect us to do," the engineers write in the document, "raising our risk of errors and deception."
Regulators in Egypt, India, the EU, South Africa, South Korea, Thailand, and the United States are all scrutinizing Facebook, which is estimated to have around three billion-member.
The proposed rule aims to control how social media corporations handle users' personal data. The engineers warn that the company's data handling issue — referred to in the paper as "data lineage" — may generate regulatory concerns in these locations. The EU's tough GDPR regulation, for example, has a "purpose limitation" provision that prevents data acquired for one reason from being used for another.
Meanwhile, Facebook disputed that it was breaking any privacy laws, claiming that the paper did not disclose the company's comprehensive systems and controls for adhering to privacy laws. Facebook representatives told Motherboard that the business was putting in place infrastructure to satisfy privacy regulation standards, such as analyzing user data and employing automation instead of people — an initiative that will need considerable expenditures but is a top priority for the firm.