Technology

New Mexico Jury Finds Meta Misled Residents on Privacy and Misinformation

Martin HollowayPublished 2w ago2 min readBased on 2 sources
Reading level
New Mexico Jury Finds Meta Misled Residents on Privacy and Misinformation
source:meta.com

A New Mexico jury found Meta violated the state's Unfair Practices Act, ruling the company misled residents about privacy protections and how it handles misinformation. The decision establishes liability under state consumer protection law for what Facebook told users about privacy. Engadget

The verdict was reported on Sept. 25, 2026. Liability is decided. The penalty is not. A judge will decide separately how much Meta will be fined.

The case dates to 2021, when New Mexico sued over the Cambridge Analytica scandal. That timeline ties the case to a data misuse episode from several years earlier, rather than to how Facebook's current products work.

At trial, the state focused on claims that Facebook deceived users about a data breach linked to a third-party personality quiz, an outside app connected to Facebook. Think of it as giving a contractor a key to a building. The state argued there was a gap between what users were told about privacy controls and what happened after data left Facebook through that outside connection. PBS

The underlying incident involved the collection and use of information from 50 million Facebook users, largely without their consent. That data was later used to target political advertising during the 2016 election.

New Mexico reached a jury verdict because it did not join the Cambridge Analytica part of Meta's settlement with 47 U.S. states. Florida also declined that part of the settlement. By staying out, New Mexico kept its case on a separate track to trial.

The broader context here matters for platform operators and compliance teams. Splitting responsibility and the fine between jury and judge is common in these state cases, and it adds weight to the second stage. A company can win narrow points about scope and still face a large fine once deception is found. The decision also pairs privacy and misinformation handling together, treating public statements about controls as binding promises rather than general policy language.

In my view, the longer-term point is about enforcement rather than rearguing the old outside-app system from the 2010s. State attorneys general kept a separate path even when most states settled. Opting out preserved evidence gathering, trial risk, and fine risk. For builders, that raises the cost of inconsistent privacy language across screens, developer documents, permission prompts, and help pages. Precision there becomes a way to limit legal risk. The hopeful side is practical. Clearer limits on outside data flows and plainer user communication make it easier for honest developers to build, because the rules are explicit and can be checked.