PIERRE, S.D. - Attorney General Marty Jackley today helped lead a bipartisan coalition of 37 state and territory Attorneys General in sending a letter demanding answers from Facebook about the company’s business practices and privacy protections. The letter to Facebook, was led by Attorneys General Tim Fox (R-MT), Marty Jackley (R-SD), George Jepsen (D-CT), Ellen Rosenblum (D-OR), and Josh Shapiro (D-PA).
“Facebook provides its users significant opportunity to share events and personal information,” said South Dakota Attorney General Marty Jackley. “As Attorney General, I am working to protect consumers from the loss of personal information through data-harvesting and breaches. Facebook is being cooperative with our office in determining the best course of action to deal with the data loss that might have occurred for South Dakota residents.”
As the Attorneys General write in their letter to Facebook, news reports indicate the data of at least 50 million Facebook profiles may have been misused by third-party software developers. Facebook’s policies allowed developers to access the personal data of “friends” of people who used certain applications – without the knowledge or consent of these users.
The Attorneys General raise a series of questions about the social networking site’s policies and practices, including:
· Were those terms of service clear and understandable?
· How did Facebook monitor what these developers did with all the data that they collected?
· What type of controls did Facebook have over the data given to developers?
· Did Facebook have protective safeguards in place, including audits, to ensure developers were not misusing the Facebook user’s data?
· How many users in the states of the signatory Attorneys General were impacted?
· When did Facebook learn of this breach of privacy protections?
· During this timeframe, what other third party “research” applications were also able to access the data of unsuspecting Facebook users?
The Attorneys General write in the letter: “Facebook apparently contends that this incident of harvesting tens of millions of profiles was not the result of a technical data breach; however, the reports allege that Facebook gave away the personal data of users who never authorized these developers to obtain it, and relied on terms of service and settings that were confusing and perhaps misleading to its users.”