Skip to content
Saturday, August 22, 2026
MEDIA NEWS WATCHMEDIA POLICY · POLITICAL COMMUNICATION
GLOBAL MARKETSPOLICYCOMPANIESTHE ECONOMY
MEDIA NEWS WATCHMEDIA POLICY · POLITICAL COMMUNICATION
policy

What does an FTC consent decree actually require a platform to do?

The government's most common tool for disciplining a tech platform after a privacy failure is not the fine — it is a multi-year compliance regime, and Meta's own record shows how much can still go wrong inside one.

AL
Alexandria Lucas, · August 20, 2026 · 6 min read
What does an FTC consent decree actually require a platform to do?

A consent decree is a court-enforceable settlement in which a company agrees to specific, ongoing obligations — audits, program changes, executive certifications — rather than admitting liability at trial. The Federal Trade Commission’s 2019 settlement with Facebook, which carried a $5 billion penalty and was folded into a modified order in April 2020, is the clearest working example of how one operates.

The distinction matters for anyone tracking how platforms are actually governed, because most coverage of a settlement ends at the headline penalty. The penalty is a one-time event; the decree is the part that keeps operating afterward, and it is the decree — not the fine — that later determines what a platform can say it is legally required to do, including, as the case below shows, decisions about who gets to study it.

A consent decree binds a company to court-supervised terms for years, not a single fine, and gives regulators a standing basis to sue again without reproving the original violation. Facebook’s current order traces back to a 2012 FTC decision addressing deceptive privacy practices, which the agency says the company then violated — producing a second settlement, filed July 24, 2019 in federal court in Washington, D.C. as Civil Action No. 19-cv-2184, according to the FTC’s case file for the matter.

That 2019 settlement carried the $5 billion penalty and a set of new privacy restrictions; the FTC formally approved modifications incorporating those terms into the original 2012 order on April 28, 2020. The mechanism is not self-enforcing: an independent, outside assessor is required to review the company’s privacy program on a recurring basis and report findings back to the agency, per the FTC’s own FAQ on the order.

Who checks whether the company is actually complying?

The independent assessor is the decree’s primary compliance check, and its reviews are where enforcement actually starts. In its FAQ explaining the current dispute with Meta, the FTC states that the assessor “identified several gaps and weaknesses in Facebook’s privacy program,” which the agency treated as evidence the company had “failed to fully comply with the requirements it agreed to.”

That finding is what moved the case forward: on May 3, 2023, the FTC issued an Order to Show Cause — a formal notice requiring Meta to explain within 30 days why the order should not be modified — proposing changes that included a blanket prohibition on monetizing data collected from users under 18. The FTC’s case file shows the proceeding has since gone through repeated extensions and procedural filings, and remained stayed as of July 30, 2025, with Meta retaining the right to appeal any final Commission decision to federal court.

What happens when a platform invokes the decree to justify a policy decision?

The order’s existence has also shaped decisions that have nothing to do with the FTC directly, including access to platform data for outside political-advertising research. In 2021, Facebook disabled the personal accounts of New York University researchers running the Ad Observatory project, which tracked political ads on the platform, and cited privacy obligations in explaining the move.

The FTC publicly disputed that account of its own order. Acting Bureau of Consumer Protection director Sam Levine wrote to Facebook that it would be “inaccurate” to say the 2019 consent decree required disabling the researchers’ access, and said the agency “received no notice that Facebook would be publicly invoking our consent decree” before the company did so, according to NBC News’ reporting on the letter. Facebook subsequently said the accounts were removed for violating its platform terms and internal privacy-program rules rather than the decree itself; researcher Laura Edelson disputed that any violation had occurred. The episode shows a recurring dynamic in platform regulation: a compliance instrument built to protect user privacy became, in this instance, a stated justification for restricting the kind of outside scrutiny that transparency rules are meant to enable.

How common — and how effective — are these decrees industry-wide?

Facebook’s is the largest, but consent decrees are a routine tool across the technology sector, not a one-company story. Twitter received one in 2011 after hackers compromised nine accounts, including then-President Barack Obama’s; Uber received one in 2018 after failing to disclose a 2016 data breach, then suffered another major breach in 2022 despite the decree being in effect; CafePress was ordered in 2022 to add multifactor authentication and encrypt Social Security numbers it held, according to Axios’ reporting on the agency’s track record.

That same reporting quotes then-FTC Chair Lina Khan describing a persistent enforcement gap: some companies, she said, have been “treating FTC orders as suggestions.” Part of the constraint has been resources — the agency’s privacy division within its consumer protection bureau “never had more than 40 employees” during a stretch from 2009 to 2012, per the same account. Khan proposed a structural fix rather than a bigger fine: naming individual executives as accountable parties in future decrees, exposing them personally to fines if a company violates its terms again.

Taken together, the Facebook and industry-wide records point to the same structural weakness from two directions. The Facebook case shows that even the largest decree the FTC has ever imposed — with a named independent assessor, a $5 billion penalty behind it, and years of monitoring — still produced disputed compliance findings and a fight over what the order actually requires. The smaller cases Axios documented show the opposite failure mode: decrees imposed on companies with far less oversight capacity than Meta, on an agency division that has historically been staffed in the dozens rather than the hundreds. Neither pattern is evidence that consent decrees do not work; both are evidence that a decree’s value depends almost entirely on what happens after the signing, not on the settlement announcement itself — the part of the story a press release rarely covers.

For a related business news perspective, read Why platform transparency reports don't actually let you compare platforms.

Sources

  1. FTC, In the Matter of Facebook, Inc. (case file, docket 092-3184/182-3109, C-4365)
  2. FTC, Facebook/Meta Order FAQ
  3. NBC News, 'FTC says Facebook misused privacy decree to shut down ad research'
  4. Axios, 'FTC considers strengthening its consent decree security hammer'