Nothing that happened Wednesday will satisfy Facebook Inc.’s critics. The U.S. Federal Trade Commission, the nation’s chief consumer privacy watchdog, hit Facebook with a $5 billion fine for violating promises to better protect personal information.

This FTC action kicked off after revelations that a politically connected consulting firm obtained information from tens of millions of Facebook users without their explicit permission. That and other eyebrow-raising privacy missteps or creepy data sharing started an overdue reckoning about how Facebook and other internet companies collect repositories of information on what people do and where they go and too often play fast and loose with that data.

The reckoning won’t stop with the fine from the FTC, which said this was a record for any privacy-related enforcement action. It still won’t make anyone happy. Members of Congress have already said that $5 billion is nothing for a company with $45 billion in the bank. Structural changes at Facebook, including a new board committee responsible for privacy and privacy certifications by senior executives, seem smart, but only time will tell.(4) 

AD
AD

Leave aside what the FTC should have done with its power under the law. I want to suggest an action that could make Facebook less of a data-privacy horror show: Give people the power to make Facebook collect less data on them. Not fake empowerment, which is too often the case in internet privacy. I’m talking about a real option to force Facebook and the companies with which it works to collect less data in the first place.

In a way, Cambridge Analytica and related scandals distracted us from the original sin of Facebook: Its zeal to grab as much information as it can about people and harness it to sell advertisements based on their identity and activities online and off.

This behavior did not originate with Facebook. The internet economy is a game of one-upmanship to normalize ever-more inventive and aggressive human surveillance. Facebook shouldn’t receive all the blame for this. (Although it should get a lot of the blame.) This is how the internet works now, and it’s only going to get worse. It is not OK. It’s time to put roadblocks on history’s largest human-tracking scheme at the hands of internet powers and the many other companies complicit in their behavior. We might as well start with Facebook.

AD
AD

Dina Srinivasan, who wrote a compelling legal paper linking Facebook’s privacy shortfalls to monopoly power, proposed a version of the U.S. “do not call” registry introduced in the early 2000s that stopped many telemarketing calls.(3) The idea applied to Facebook is that people would have the option to make Facebook’s surveillance system end at the borders of its internet hangouts.

Facebook would no longer be able to vacuum information about what people do on websites and apps that aren’t owned by Facebook, or would no longer be able collect the location of people as they roam around the world with smartphones that double as Facebook surveillance devices. Yes, Facebook does all this, although many people are not aware of the scope of the company’s information-harvesting practices.

Facebook users today can check a box — if they can find it and understand the language — to tell the company not to use information about their visits to news websites, medical information apps and their trips to the coffee shop for use in tailoring advertisements bought by Ford or Starbucks. But they cannot prevent Facebook from collecting this information in the first place, and the company even collects information on people who don’t have a Facebook account at all.(1) 

AD
AD

Facebook says, in part, that it needs some information such as location to identify fake accounts or other security purposes. But truly, Facebook and other internet companies believe they should gather as much information about people as they possibly can because it might help their business — and hardly anyone has stood in their way.

This is how the internet works. Track everything, break down any semblance of anonymity in online activity to create highly specific personal dossiers. The big lie of Facebook and the internet is that people have knowledge about and control over what happens to their information. They absolutely do not, and people should have a choice to truly opt out of the the great horror show of pervasive internet surveillance. 

To be clear, a “do not call” type option will seriously harm Facebook’s advertising business. That is the point. And any attempts to roll back widespread internet information harvesting will be tough to push through and require vigorous enforcement. The obvious objections are that data harvesting is a standard part of the internet to which people effectively consent. The “everyone does it” line is true, and that’s why the internet economy is broken. 

AD
AD

I don’t want to single out Facebook alone, nor punish it for the sake of punitive justice. But it is beyond time to say no to what has become standard operating procedure online, and that means rolling back the internet surveillance system.

(1) In a perfect encapsulation of all that is broken with Facebook and the internet, tucked into the company’s explanations of the privacy changes it is making is a disclosure of newly discovered data privacy holes.

(2) The “do not call” registry worked until robocalling scammers ignored it.

(3) Also, Facebook and its partners may have found ways around the option to stop tailoring ads based on information gathered outside of Facebook’s walls.

AD

To contact the author of this story: Shira Ovide at sovide@bloomberg.net

To contact the editor responsible for this story: Daniel Niemi at dniemi1@bloomberg.net

This column does not necessarily reflect the opinion of the editorial board or Bloomberg LP and its owners.

Shira Ovide is a Bloomberg Opinion columnist covering technology. She previously was a reporter for the Wall Street Journal.

©2019 Bloomberg L.P.

AD
AD