New California Data Privacy Law Could Spell Trouble for Facebook

Law takes direct aim at some of Facebook's current business practices

Article's Main Image

On Thursday California Governor Jerry Brown signed into law a comprehensive data privacy bill that will force the tech giants, most notably Facebook FB, to fundamentally alter the way they conduct business.

The regulations that will be promulgated after the bill's enactment will force Facebook to operate in a manner that is wholly at odds with the revenue-generating model it has used for the past decade to achieve phenomenal earnings growth. The California Consumer Privacy Act doesn’t take effect until 2020, and the tech companies through their trade association lobbyists will endeavor to minimize, amend or water down some of the more vexatious provisions of the sweeping bill.

Why was the law rushed through the legislature?

The law was uncharacteristically rushed through the legislature with alacrity.The reason for its speedy enactment? A group of well-connected and knowledgable Silicon Valley data privacy advocates had previously crafted a more restrictive measure that would have been far more onerous on tech companies. The privacy coalition enshrined their efforts into a ballot initiative referendum that would have been presented to voters in November. The deadline for rescinding that initiative was Thursday night.

Laws passed through a ballot initiative are much harder to change, particularly referendums that are well drafted.The tech companies, with a gun to their heads, chose the Consumer Privacy legislation as the lesser of two evils.

The law expands the definition of what constitutes personal information and gives California users the right to view the data that Facebook has collected and request it be deleted and not sold to third parties; users can elect to opt out of sharing their information entirely. Furthermore, companies must provide consumers information on the source(s) of the information collected, as well as the commercial purpose for which their private data was collected. The law prohibits companies from charging or penalizing users if they decide to opt out.

Although the law only covers California residents, undoubtedly other states as well as the federal government will use the regulations as a template; most will adopt the existing legislation in its entirety, with minor revisions. In short, the California privacy protection coalition has done all the heavy lifting. All U.S. consumers will be afforded similar protections shortly.

Data privacy coalition comprised of Silicon Valley insiders

Who are these private data guardians who spearheaded the consumer privacy initiative and why do the qualifications of its members and supporters matter for Facebook?

The unique composition of the group matters in two ways. First, its members are all tech savvy and reside in the Bay Area. This, in and of itself, gave them an advantage over their European counterparts who must determine what specific provisions in the General Data Protection Regulation are necessary to carry out the stated privacy protection purposes of the law.

This data privacy group is problematic for Facebook because most of its members and avid supporters are consummate Silicon Valley insiders, or former employees of the tech companies. Some are former Google GOOG software engineers. The group itself has support from a wide range of individuals within academia, the legal and business communities as well as a large group of parents concerned their teenage children are becoming addicted to social media platforms. Most importantly, members of the group are technically savvy and are thoroughly conversant in how the social media platforms are designed and operated.

The tech-ad business is a labyrinthine web of interconnected entities and corporations, who, through complex contractual arrangements between themselves and Facebook, share, transfer, manipulate and sell users' personal data. Members of data privacy coalition understand this business strategy and all of its moving parts.

Regulators for the European Union had several meetings with Facebook executives prior to the enactment of the GDPR in May, in order to understand Facebook’s business model so they could implement appropriate privacy provisions. It was a case of the regulated instructing the regulators. No member of the California group needs to consult with or meet Facebook executives to acquire sufficient tech-ad acumen to craft meaningful privacy regulations that will likely to force Facebook to change its core business practices.

After several meetings with tech executives within the industry, the privacy coalition concluded that tech companies were never going to police themselves. This realization provided the impetus for the group to collaborate with high-level players in Silicon Valley who had the expertise and knowledge of social media needed to craft substantive consumer privacy rights provisions.

The one common theme that ran throughout the group was that, in terms of data privacy protections and safeguards, despite Facebook’s pious statement to regulators and the public that they were concerned about user’s private data, the tech industry was never going to upend their lucrative tech-ad business models.

Importantly, most of the individuals within the coalition were former software engineers at Google or investors or former employees of Facebook. From the start , the group was comprised of tech experts from within the very industry they are seeking to hold accountable. They came to the fight well-equipped, with individuals who are thoroughly conversant with the Silicon Valley tech giant’s business processes.

One of the volunteer members of the coalition, Mary Stone Ross, is an example of the caliber of professionals enlisted for the fight. Ross is a former CIA employee and former legal counsel to the House of Representatives Intelligence Committee. She is a resident of the Bay Area. Real estate developer Alastair Mactaggart, who organized the effort and put $2 million of his own money to fund the initiative, persuaded Ross to join the team to craft the actual policy and help shepherd it through the system.

The members of the group have demonstrated with aplomb their refusal to be intimidated by Facebook and Google. It should be noted that Facebook executives had previously expressed, unequivocally, their disapprobation with the group's privacy objectives and some of its members' publications that were critical of the deleterious effects the platform had on children.

There are ambiguities in some of the bill’s provisions. For example, while Facebook cannot sell information to third parties without the users’ consent, it may “share” that information with others. During the next two years, the coalition plans to monitor any changes to the legislation proposed by the tech companies to ensure the primary precepts of the privacy legislation survive intact. Their leverage over the powerful tech giants? Resuscitation of the ballot initiative acts as a Sword of Damocles that will continue to hang over the head of the tech giants until the bill becomes law in 2020.

Facebook response to privacy issues duplicitous and inadequate

After the Cambridge Analytica data abuse revelations, Facebook’s contention that not many of its users would ultimately leave or opt out of features on the platform was based, in part, on consumer ignorance. Most people who use the site are not aware of the amount of information gathered, the undisclosed processes by which their personal data has been extracted, the extent of the manipulation and the multiple parties who have access to the personal data and subsequently transfer it to others who don’t directly participate in the Facebook platform.

Once these data harvesting techniques are disclosed to consumers, some will be appalled at the types of information Facebook gleans from their pages as well as that of their friends. How many Facebook friends will approve of having their personal data transferred to app developers and others for profit?

Those securities analysts who subscribe to the view that Facebook has fared well since the privacy abuse disclosures might want to reassess their intermediate revenue and operating margin projections for the company in light of this new legislation.

1297179822.png

It is interesting to note the duplicity and outright deception employed by Facebook executives since the scandal first erupted. CEO Mark Zuckerberg has been positively mealy-mouthed, appearing solicitous when addressing concerns for user’s privacy, yet in the same breath, failing to detail with specificity what steps his company will implement to ensure privacy safeguards are in place.

In meetings with both U.S. Congressional leaders as well as EU officials, Zuckerberg’s responses to queries were evasive and he provided no particular information, save for empty bromides or anomalous answers to specific questions.

Shortly after the privacy abuse revelations, Zuckerberg said, on the one hand, that he agreed “in spirit” with a new EU law that requires higher standards for protecting user data, but on the other, he made no commitment to enforcing those standards for the remaining 1.4 billion users outside the jurisdiction of the GDPR.

As David Carroll, media professor at Parsons School of Design, noted in terms of Facebook’s privacy procedures for Europeans versus those in the rest of the world, “Clearly someone has not told Mark about his dual-citizen problem.” Carroll further noted that, “He’s terrified about asking all 2.2 billion users for consent to track them off of Facebook. Most will say hell no.”

In an interview with Reuters immediately after the Cambridge Analytical ignominy, Zuckerberg said that Facebook would be looking into new global standards that “should directionally be, in spirit, the whole thing,” but declined to give specifics. As of Thursday, he now no longer needs to concern himself with those standards.

Facebook’s response to concerns raised about data abuse is not indicative of a company concerned about user’s privacy. The company has threatened to sue news outlets for stories reporting the scope of the company’s data breaches. Despite its feigned concern for the privacy rights of its users, Facebook fought assiduously to quash the California Consumer Privacy bill, all the while mouthing platitudes about the company laboring valiantly to protect users' privacy.

Facebook’s statements on revenue impact of privacy laws strains credulity

The modus operandi of Facebook has been very simple, yet phenomenally lucrative. Sell users' data unimpeded to third parties without their knowledge or consent. Does anyone doubt that once this essential business practice is circumscribed, the revenue stream will remain the same?

The company’s comments concerning the effect of the privacy abuse stigma on its bottom line strain credulity.

Carolyn Everson, Facebook vice president of global marketing solutions, told the Wall Street Journal at a London conference in April that the EU "has really set a very strong standard for privacy and consumer consent and I think it’s going to benefit everybody around the world.The actual most meaningful controls and settings...are going to be the same.” Everson said the company would implement changes mandated by the law globally, with minor tweaks to account for things such as different national laws.

Finally, Everson said the company also doesn’t expect stricter privacy laws, which could lead consumers to opt out of targeted ads, to cut into its ad sales. She added, “We are not anticipating major changes to our overall revenue and business model.”

This statement is but one example of the balderdash coming from the lips of Facebook executives in terms of trying to reconcile its professed and undying devotion for protecting users' privacy with the reality of data privacy laws impairing its revenue growth.

After Everson’s comments, it is interesting to note that after implementation of the GDPR, what actually happened is Zuckerberg put 1.4 billion Facebook users on a boat to California, beyond the reach of the EU’s GDPR jurisdiction. As of last Thursday, all of it was for naught. Nonetheless, it does demonstrate that Everson’s statement on Facebook’s intention to apply the GDPR universally was clearly a material misrepresentation.

Security analysts ought to note that, to date, Facebook hasn’t come up with a viable solution to the problems the GDPR creates for its business model, most notably how it intends to make up for revenue lost from users telling the company not to sell their information to third parties.

Have any security analysts projected the effect to the company if 10% of 1.4 billion users say no to Facebook? How about 20%? How much will Facebook charge users to remain on the platform. How much will users be willing to pay to see pictures from Aunt Sally’s barbecue? Will any potential subscriber revenue replace lost advertising dollars?

It is too early to tell the extent to which the GDPR, and California’s Consumer Privacy Act, will ultimately have on the revenue stream of Facebook. No mater how the law is interpreted and enforced in the short term, it is indisputable that Facebook’s enviable operating margins and explosive earnings growth all have occurred in a laissez-faire business environment of zero regulation.

It is unprecedented for a company with one of the world’s highest market capitalizations to just now appear as a blip on the radar screen of regulators. Try as it may, California’s new expansive data privacy law is a bullet Facebook can’t dodge

Facebook and the other tech giants will endeavor during the next decade to unravel the privacy regulations. But, much to their chagrin, they will realize, once the genie is out of the bottle, its hard to get it back in.

Disclosure: I have no positions in any of the securities referenced in this article.