Refacto

Industry story

New Mexico Jury Finds Meta Liable for 43 Million Privacy Violations

antitrust privacy walled-gardens

A New Mexico jury found Meta deceived users about privacy and content moderation, counting Mark Zuckerberg's 2010 promise that users 'have control over how your information is shared' once for each of the state's 2.1 million residents. The total violation count exceeded 43 million under a state law allowing fines up to $5,000 per violation, putting the statutory ceiling above $215 billion. The state asked Judge Francis Mathew to impose a fine of $35–$40 billion.

Meta's lawyer called the penalty 'astronomical' and unconstitutional. Notably, Meta's spokesperson responded by reaffirming the company's commitment to giving users 'control over their data' — nearly identical language to what the jury found deceptive. The case establishes a precedent where standard platform privacy-promise language can be priced on a per-resident basis, creating a significant exposure model for any platform operating at scale.

Analysis

Showing the shorter version.

A New Mexico jury found Meta liable for more than 43 million privacy violations, stemming from a 2010 Mark Zuckerberg statement that users have "control over how your information is shared." The math: 2.1 million New Mexico residents, multiplied across the promises at issue, each worth up to $5,000 under state consumer-protection law. The statutory ceiling lands above $215 billion. The state is asking for $35 to $40 billion. Meta calls it unconstitutional.

The irony that Meta's spokesperson then repeated nearly verbatim the language the jury just called deceptive tells you something about where the company's lawyers think real exposure lands.

The dollar amount will get cut. The method might not.

The $215 billion number does not survive appeal. A penalty larger than Meta's roughly $160 billion in annual revenue triggers the Supreme Court's own proportionality rule, and no trial judge wants to author a number that gets reversed on sight. The state's own $35 to $40 billion ask signals the plaintiff doesn't expect the ceiling to hold either. This ends closer to a number a CFO can reserve against than to a number that breaks the balance sheet.

Our call: Judge Francis Mathew sets the final penalty below $40 billion, a reduction of more than 80% from the statutory ceiling. Reduction is near-certain; the size depends on the judge. Revisit by 2027-06-30.

The more durable piece is the per-resident multiplication theory itself. State attorneys general now have a damages template: take boilerplate privacy language, multiply by the census, and each state's consumer-protection statute hands you a number a CFO has to at least model. The template spreading to other states is the real risk for the industry, and it doesn't require New Mexico's number to hold.

Who this hits

Mid-tier ad-tech companies running the same "you control your data" consent copy without Meta's legal reserves get repriced on risk before they lose a single case. Walled gardens absorb it. The compliance and consent infrastructure layer, companies like LiveRamp (the data connectivity platform) and ID5 (the identity resolution provider) plus the consent-management platforms, picks up a new sales pitch built on that fear.

For any operator, the immediate task is an audit: where does your product promise "control," and do your data-sharing contracts with demand partners actually allow it? That's where the promise breaks down in practice. Fix the copy edit now. Reserving billions is harder to undo.

Also covered this issue

Comments