Home Data Zuckerberg Finally Speaks, Promising Audits And New Curbs On Data Collection

Zuckerberg Finally Speaks, Promising Audits And New Curbs On Data Collection

SHARE:

#WheresZuck? Posting a mea culpa on Facebook after nearly five days of conspicuous silence.

In the wake of the Cambridge Analytica scandal, which broke over the weekend, Facebook CEO Mark Zuckerberg took to Facebook to explain what happened and to outline fixes.

He promised Facebook would investigate all apps that had “access to large amounts of information” before 2014, when Facebook restricted the data developers could access through its API.

Unauthorized data sharing is an intractable issue for Facebook, which hasn’t done a thorough job of monitoring what third parties do with restricted data once it leaves Facebook’s platform.

According to several sources AdExchanger spoke with, Facebook hasn’t been systematic about following up to ensure third parties handle the data they gather from Facebook properly.

Now, Zuckerberg said Facebook plans to conduct a “full audit” of any app with suspicious activity.

Aleksandr Kogan, the academic researcher at the heart of the Cambridge Analytica affair, was reportedly able to access millions of Facebook profiles over just a few weeks back in 2014, when the rules were more lax.

Kogan could do that because Facebook’s API allowed for the collection of friend-related data, which is no longer possible. This was the data he passed to Cambridge Analytica.

Developers can no longer access friend data. But this doesn’t mean apps that gathered it before the 2014 clampdown don’t still have it.

Zuckerberg wrote that any developer refusing a thorough audit will be banned, as will any developers found to have misused PII. Facebook users affected will be notified of any wrongdoing, including those affected by Kogan’s misuse.

Facebook was roundly criticized this week for failing to alert users that their data had been handed over to an unauthorized third party, despite the company knowing since 2015 that Kogan had improperly shared data with Cambridge Analytica.

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Developers will also see their data access restricted even further to prevent other potential abuses. Going forward, the only data an app will get when a user signs in will be the person’s name, profile photo and email address.

And if someone hasn’t used an app in three months, Facebook will remove the developer’s access to that person’s data. Developers will also have to sign a contract before they ask users for access to posts or other private data.

Finally, Facebook has plans to roll out a tool at the top of the news feed to make it easier to revoke app permissions.

Zuckerberg vowed that there will be more changes to come over the next few days.

“Beyond the steps we had already taken in 2014, I believe these are the next steps we must take to continue to secure our platform,” he wrote. “We have a responsibility to protect your data, and if we can’t then we don’t deserve to serve you.”

Must Read

Comic: He Sees You When You're Streaming

IP Address Match Rates Are a Joke – And It’s No Laughing Matter

According to a new report, IP-to-email matches are accurate just 16% of the time on average, while IP-to-postal matches are accurate only 13% of the time. (Oof.)

Comic: Gamechanger (Google lost the DOJ's search antitrust case)

The DOJ And Google Sharpen Their Remedy Proposals As The Two Sides Prepare For Closing Arguments

The phrase “caution is key” has become a totem of the new age in US antitrust regulation. It was cited this week by both the DOJ and Google in support of opposing views on a possible divestiture of Google’s sell-side ad exchange.

create a network of points with nodes and connections, plain white background; use variations of green and grey for the dots and the connctions; 85% empty space

Alt Identity Provider ID5 Buys TrueData, Marking Its First-Ever Acquisition

ID5 bought TrueData mainly to tackle what ID5 CEO Mathieu Roche calls the “massive fragmentation” of digital identity, which is a problem on the user side and the provider side.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

CTV Manufacturers Have A New Tool For Catching Spoofed Devices

The IAB Tech Lab’s new device attestation feature for its Open Measurement SDK provides a scaled way for original device manufacturers to confirm that ad impressions are associated with real devices.

Comic: "Deal ID, please."

The Trade Desk And PubMatic Are Done Pretending Deal IDs Work

The Trade Desk and PubMatic announced a new API-based integration for managing deal ID campaigns built atop TTD’s Price Discovery and Provisioning (PDP) API, which was announced earlier this year.

How Agentic Advertising Platform Aimy Uses Comcast’s Universal Ads API

On Monday, Brand Networks announced that Universal Ads would now be buyable through the company’s agentic ad buying platform, Aimy Ads.