A consent decree is a binding settlement between the Federal Trade Commission and a company, supervised by a federal court, that imposes conduct obligations without an admission of wrongdoing. The largest in the privacy field remains the July 2019 order against Facebook, which carried a $5 billion civil penalty and restructured the company's privacy governance, per the FTC's 2019 announcement. The instrument is the commission's main tool against platforms, and its mechanics deserve a closer reading than the headline fine usually gets.
This explainer describes how consent decrees work, what the 2019 order requires in its own terms, and what the instrument cannot do. Media News Watch publishes analysis of the record, not legal advice.
How does a consent decree actually bind a company?
The mechanism is contractual and judicial at once. The company agrees to specified obligations; the federal court enters the agreement as an order; violation of the order becomes contempt of court, a sharper legal exposure than the underlying statute alone. The FTC's own description of the instrument notes that decrees typically run twenty years from entry.
The trade is deliberate. The commission avoids a contested trial with an uncertain standard of proof; the company avoids an admission that would arm private plaintiffs. What the public receives is a compliance regime — auditors, reporting, designated officers — rather than a verdict. Whether that regime disciplines behavior depends almost entirely on enforcement, which is the instrument's structural weakness: the FTC must detect and then act on violations of an order it does not continuously monitor.
What does the 2019 Facebook order require?
The order, entered after the Cambridge Analytica matter, goes beyond a penalty. Per the FTC's July 2019 statement, it requires a privacy program with designated accountable executives, quarterly certifications from officers personally liable for false statements, an expanded independent assessor, and a prohibition on misrepresenting how user data is shared with third parties. The $5 billion penalty was, at entry, the largest the commission had imposed in any privacy case.
The order also tightened an earlier 2012 decree against the same company — a detail worth pausing on. The 2012 order had already barred deceptive privacy representations; the 2019 case arose partly from alleged violations of it. The instrument, in other words, had been applied once and stretched once before the record fine arrived.
What can a consent decree not do?
It cannot admit liability, because by design none is admitted. It cannot set a market-wide rule; a decree binds the signatory company, while other platforms face the same questions only if the commission brings separate cases. And it cannot self-execute: the quarterly certifications and assessments land on the commission's desk, where staff capacity, not the order's text, determines what happens next.
Critics of the commission's approach, including former officials quoted in the FTC's own public record of the 3-to-2 vote, argued the penalty was absorbable for a company of that scale. The dissenting commissioners' position, per their published statements, was that structural limits — not fine size — were the real question. The strongest defense of the instrument, also in the record, is that court supervision survives changes in corporate priorities for two decades, which no statute currently offers the commission for general privacy enforcement.
What remains unknown is compliance in practice: the assessments the order requires are filed to the commission, not published, so the public record cannot establish how the privacy program performs. Readers evaluating any consent decree should apply the same checklist: what is required, who certifies it, who can act on a violation, and what the record shows about enforcement after entry.
