Meta Ordered to Pay $942 Million for Harm to Children and Misleading Safety Claims
What Happened — A New Mexico state court ordered Meta Platforms to pay a combined $942 million after finding that Facebook and Instagram caused mental‑health harm to minors and that the company misled consumers about the safety of its services. The judgment includes a $375 million civil‑penalty verdict and a $567 million abatement fund, plus product‑level obligations such as building an under‑13 age‑prediction model, requiring proof‑of‑age for suspected minors, treating uncertain accounts as minors, deleting data from under‑13 users, and establishing a reporting channel for schools or child‑safety groups.
Why It Matters for Compliance & Audit Readiness
- The ruling underscores that regulators can impose privacy‑and‑child‑protection obligations that must be documented and continuously evidenced for SOC 2 / privacy‑framework audits.
- Controls around age‑verification, data minimisation, and transparent disclosures become audit‑ready evidence points; gaps can translate into multi‑hundred‑million penalties.
- Verisq’s CookiePLUS privacy suite helps organisations map, monitor, and produce audit‑ready proof of consent, data‑deletion, and age‑assurance processes—exactly the evidence the court now demands of Meta.
Who Is Affected
- Social‑media platforms and any SaaS products that collect data from children under 13.
- Companies in the broader tech sector that rely on user‑generated content and targeted advertising.
Recommended Actions
- Map age‑verification and data‑deletion controls to the SOC 2 Privacy principle and relevant GDPR/CCPA provisions.
- Implement continuous evidence collection for consent, age‑assurance, and data‑retention policies (e.g., automated logs, periodic attestations).
- Establish a formal reporting channel for external stakeholders (schools, NGOs) and schedule semi‑annual compliance updates.
Source: Malwarebytes Labs
Technical Notes
- No specific vulnerability or exploit; the risk stems from product‑design shortcomings in age‑verification and data‑handling.
- The court’s order mandates a predictive model for under‑13 users and mandatory deletion of their personal data.
- Enforcement aligns with emerging global privacy regulations that treat child data as a high‑risk category.
Source: same as above