New York DFS Issues Report Detailing Findings From Its Investigation of Facebook Data Privacy Practices
Privacy, Cyber & AI Decoded Alert | 2 min read
Mar 10, 2021
Blood pressure readings, menstrual cycles, and pregnancy status are among the types of sensitive personal data Facebook was caught collecting from third-party app developers without users' knowledge or permission. After a 2019 Wall Street Journal article exposed the practice, New York Governor Andrew Cuomo called on the New York State Department of Financial Services (DFS) to investigate the allegations, describing the practice as an outrageous abuse of privacy. DFS licenses a Facebook money transmitter subsidiary, Facebook Payments, Inc., but the investigation found it "had no involvement in the privacy issues examined." Given that Facebook, the parent, agreed to cooperate "fully" with the DFS investigation, the parties avoided any issues as to jurisdiction.
On February 18, 2021, DFS released a report summarizing its investigation. The findings included the fact that Facebook regularly obtained sensitive personal data from app developers, stored the data on its servers, and analyzed it for use in generating targeted ads—all of which violated Facebook's own policies.
Facebook's ad revenues—which totaled nearly $87 billion in 2020—account for 98.5% of its global revenue. One of Facebook's most powerful tools is a sophisticated data analytics system used to ensure advertising is targeted based on a user's data. Facebook offers website owners and app developers free access to its online data analytics services whereby the developers program their software to collect certain data about users. That data is then sent to Facebook's analytics service so it can be analyzed. Lastly, the Facebook analytics service provides the developer with an analysis of that usage data, which is often linked with other data that Facebook has on a user.
Facebook policies outline the types of information it collects from partners and places responsibility on these partners to ensure that they have the legal right to collect, use, and share user data before providing it to Facebook. It also prohibits app developers and third parties from sending Facebook sensitive data such as health and financial information. During the investigation, however, Facebook admitted that it uncovered many examples where developers violated the policies by regularly sending sensitive data to Facebook. Notably, Facebook maintains that it stored and analyzed the personal data unwittingly because its internal controls were not effective at enforcing the policy.
Facebook has since implemented remedial measures, including building a screening tool to reject sensitive health information and imposing enhanced app developer education. However, DFS noted that Facebook failed to "engage fully" with respect to other remediation proposals, and that Facebook's effort to enforce its own policies against collection of sensitive data was "seriously lacking." DFS further indicated it would like to see greater transparency in the form of detailed disclosures of the sensitive data that was collected and analyzed in the past—along with more strict enforcement of its data-sharing policies in the future—and called on federal regulators with nationwide jurisdiction to compel Facebook to provide full transparency.
Similar to DFS's investigation and report on the Twitter hack—and Twitter's lack of cybersecurity protections that allowed the accounts of cryptocurrency firms and well-known public figures to be hacked—DFS emphasized that this is another incident demonstrating the need for greater oversight of social media and technology companies. DFS concluded its investigative report with the following call to action: "Our regulatory institutions need to rapidly adapt to the challenges presented by social media giants, big tech, and the analytics industry, and it is imperative that we put in place a clear nationwide legal framework for accountability enforced by a robust federal regulator."
Related Capabilities
Featured Insights

Employment Law Observer
Aug 10, 2026
As Leaves Fall, Leave Requests Rise: Are You Compliant With Chicago’s Expanded Rules?

Press Release
Aug 7, 2026
Daniel McGrath Re-Elected Senior Director of the Federation of Defense & Corporate Counsel

Insights for Insurers Alert
Aug 7, 2026
California Supreme Court Clarifies Pleading Standards for Excess Policy Claims

Press Release
Aug 6, 2026
Charles Townsend Named a Best Mentor Finalist in the 2026 ALM Texas Legal Awards

Webinar
Aug 5, 2026
April Toy Moderates HNBA Webinar on AI in the Practice of Law

Privacy, Cyber & AI Decoded Alert
Aug 5, 2026
2026 AI Compliance: Upcoming Laws Every Organization Needs to Know

Press Release
July 21, 2026 | Updated on August 4, 2026
Three Hinshaw Attorneys Named to the 2026 National Black Lawyers’ Top 40 Under 40 List

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

