It’s not that living in the US puts you totally in the specific characteristics hinterlands. The FTC has a modicum of authority, and has used it when companies grossly overreach–as it did against Facebook in 2011, when the company failed to keep its promises regarding how it treated their data. Facebook had induced user information public, even if they'd previously had more restrictive privacy sets, and allowed third-party developers to mine the data not just of the Facebook users who downloaded their apps, but of all of those peoples' friends.( If that voices familiar, well, it's precisely what allowed the Cambridge Analytica fiasco .)
Even then, though, Facebook got off with a rebuke. It had to sign a consent decree, essentially a promise that it wouldn’t stray again. That's gone unchecked until this week, when the FTC reportedly opened an investigation into the Cambridge Analytica scandal, and could penalty Facebook up to $40,000 per violation–with 50 million people impacted, the potential penalty hypothetically stretches into the trillions.
But the hazards of retroactive fines clearly hasn't done the trick. The FTC, meanwhile, can only work with the legislative tools it’s devoted. So what would it look like if Congress gave it better tools? Other countries might offer something like an outline, if not an outright blueprint.
In Finland, officials feel that their strong public education system and a coordinated government response have been enough to stave off Russia’s propaganda; Sri Lanka banned Facebook, WhatsApp, and Instagram entirely. Which is to say, it's a wide gamut.
On the data privacy front, the most recent high-profile model comes from the European Union, where General Data Protection Regulation becomes the law of the land on May 25. GDPR focuses on ensuring that people who use online services know is not merely exactly what data those companies will take, but how they put it to use.
Zuckerberg, at least, seems supportive of those levels of transparency–although they’re also, since GDPR’s passage, an inevitability. “I is believed that tends to work well is transparency, which I think is an area where we need to do a lot better and are working on, ” Zuckerberg tells WIRED. “I guess guidelines are much better than dictating specific processes.”
‘We do not have an omnibus privacy legislation at the federal level.'
David Vladeck Former Bureau of Consumer Protection Director
Rough guidelines also seem like a more plausible approach in the US due to both precedent and practicality. The EU approach to privacy statute has long been highly detailed and prescriptive, says Vladeck, which sounds good in theory but can create issues in practice. “The implementation of it, in my opinion, is going to be ineffective, because it places an enormous regulatory onu on some parties, and worse, it places an enormous regulatory burden on the data protection authorities that need to enforce it, ” says Vladeck. “I don’t think we could simply take the European regulation and simply adopt it in the United States. But I think there are a lot of elements in it that could provide guidance.”
One danger of an too prescribed statute is that technological solutions can outpace those mandates. Zuckerberg points to Germany, where abhor speech laws involve Facebook and other companies to remove offending posts within 24 hours. “The German model–you have to handle dislike speech in this way–in some ways that’s actually backfired, ” Zuckerberg says. “Because now we are handling hate speech in Germany in a specific style, for Germany, and our processes for the rest of the world have far outshone our ability to handle that. But we’re still doing it in Germany the route that it’s mandated that we do it there. So I suppose guidelines are probably going to be a lot better.”
Zuckerberg also raises the question of the use of artificial intelligence in weeding out unwelcome uploads. “Now that companies increasingly over the next five to 10 years as AI tools get better and better are enabled to proactively ascertain what might be offensive content or infringe some rules, what therefore is the responsibility and legal responsibility of a corporation to do that, ” Zuckerberg says.
Here, too, Facebook’s get out ahead of any possible reporting requirement; it already scans for nudity and terrorist content, and remains hard at work at AI that can place what Zuckerberg calls “really nuanced loathe speech and bullying.”
Eventually, though, Silicon Valley may run out of ways to mollify regulators. By now there have been too many data violates, too much negligence, whether by Facebook, Equifax, or the government itself. “I do think increasingly that there’s a sense that we need it, ” says Vladeck.
At the very least, when regulation does come, Facebook has an open invite to help inform what happens, albeit in gruff words. “Mr. Zuckerberg needs to testify before the Senate and answer some tough questions about Russian activity on the platform, and the style his company protects–or doesn’t–its users’ data, ” said Senator Mark Warner in a email to WIRED Wednesday.
And if it doesn’t pitch in, Congress has a model for privacy protection waiting for it, at the least philosophically, only an ocean away.