
Nearly a decade after the Cambridge Analytica scandal exposed how far personal information could travel beyond Facebook, a New Mexico jury has delivered a verdict with consequences that reach beyond one data-harvesting episode.
Jurors in Santa Fe found on Friday, September 25, that Meta misled New Mexico residents through statements about user data, misinformation, hate speech and the enforcement of its platform rules. The judge—not the jury—will decide the financial penalties and whether Meta must make operational changes. Meta says it disagrees with the verdict and will continue to defend itself.
The immediate legal fight is confined to one state. The larger question is national: when a technology company tells billions of people that they control their information or that platform rules apply consistently, are those statements marketing language—or enforceable promises?
What the jury actually decided
The case arose from allegations connected to Cambridge Analytica, the political consulting firm that obtained information from millions of Facebook profiles through a third-party application. But the verdict covered a broader set of public statements made by Facebook and its executives.
According to Reuters’ account of the trial and verdict, jurors found 26 of 29 statements identified by the state to be misleading. The statements concerned how Facebook shared or handled user information, its treatment of hate speech and misinformation, and whether policies were applied consistently. The jury rejected three of the state’s challenged statements, including some claims concerning efforts to remove harmful content and fact-checking.
The New Mexico Department of Justice said the jury counted 43,899,725 violations of the state’s Unfair Practices Act. That number should not be mistaken for a final penalty. Judge Francis Mathew has discretion over the amount, and further proceedings will address both civil penalties and any order requiring changes to the company’s conduct.
Meta denied that it sells users’ information and argued that the state presented isolated excerpts without the surrounding context. A company spokesperson told Reuters that Meta’s platforms are forums for free expression and said the company prioritizes speech, protects user information and gives people control over their data.
Why this case is about more than Cambridge Analytica
The Cambridge Analytica scandal remains the case’s foundation. Information gathered through a personality-quiz application was used to build voter profiles, even though many affected Facebook users had never installed the app themselves. The Federal Trade Commission said in 2019 that Cambridge Analytica, its former chief executive and the app developer were accused of using deceptive tactics to collect personal information from tens of millions of people for voter profiling and targeting.
What makes the New Mexico verdict significant is its focus on what Facebook told consumers after serious concerns were already known. The state argued that users were not merely harmed by one outside firm; they were misled about how the platform’s business practices, privacy controls and content policies worked.
That distinction matters because modern platforms do not sell a simple product. Users exchange attention, behavioural information and social connections for access to services. The rules governing that exchange are scattered across privacy notices, help pages, executive statements, settings menus and public promises. If those representations can form the basis of consumer-protection liability, technology companies may have to treat public assurances with the same care as formal contractual language.
The verdict tests the limits of “user control”
Technology platforms often describe privacy as something users can manage through settings. But meaningful control requires more than a visible button. People must understand what information is collected, which outside parties can receive it, what inferences are created from it and whether deleting or restricting access actually changes how the system operates.
The gap between technical permission and informed consent has long been central to the Facebook controversy. A person may agree to an app’s terms without realizing that the app can also gather information connected to friends. A user may disable one form of personalization while other signals continue to shape recommendations or advertising. Dense policies can disclose practices formally without making them understandable in practice.
Federal regulators previously addressed parts of this problem. In 2019, Facebook agreed to a $5 billion FTC settlement and new privacy restrictions resolving allegations that it violated an earlier privacy order. The same day, the company agreed to pay $100 million to settle Securities and Exchange Commission charges that its investor disclosures described misuse of user data as a hypothetical risk after the company knew misuse had occurred. Facebook did not admit or deny the SEC findings.
The New Mexico case shows why those earlier settlements did not end the accountability debate. Regulators can impose compliance structures, but juries may still be asked whether particular statements deceived ordinary consumers under state law.
Privacy, hate speech and misinformation are now legally connected
The verdict also crossed a line that technology companies often try to keep separate: privacy practices on one side and content moderation on the other. New Mexico challenged statements in both areas, arguing that Facebook’s representations about enforcing hate-speech and misinformation rules could influence whether people chose to use the service.
This does not mean a jury ordered Meta to remove more speech, nor did it decide what Facebook’s moderation policy should be. It decided whether identified statements about those policies were misleading under New Mexico consumer law. That is a narrower legal question, but one with potentially wide implications.
Platforms have legitimate reasons to preserve discretion. Context changes, automated systems make mistakes and global rules collide with local laws and cultural norms. At the same time, a policy advertised as universal can create false confidence if undisclosed exemptions or inconsistent enforcement materially change how it operates.
Meta’s First Amendment argument will likely remain important as the case proceeds. Courts must distinguish between government interference with a platform’s editorial judgment and enforcement of laws against deceptive commercial statements. The eventual appeal could help clarify where that boundary lies.
The penalty headline is not the final outcome
New Mexico law allows a civil penalty of up to $5,000 for each willful violation, and the state says it will seek the maximum. Multiplying that ceiling by the jury’s violation count produces a theoretical figure far beyond a routine corporate fine. But the court has not imposed that amount, and headlines presenting it as money Meta already owes would be misleading.
The more durable consequences may come from injunctive relief. Attorney General Raúl Torrez said the state may seek corrections to past statements and an audit of Meta’s management of user data. The scope, feasibility and constitutional limits of any such order will be contested, and Meta can appeal.
This is also New Mexico’s second jury victory against Meta in six months. An earlier case addressed claims about child safety on Facebook, Instagram and WhatsApp. The latest verdict concerns a different set of allegations, so the outcomes should not be blended together. Their combined message, however, is difficult to ignore: state consumer-protection law is becoming a serious route for challenging how large platforms describe themselves to the public.
What changes for ordinary users?
Nothing about the verdict immediately rewrites Facebook’s privacy settings or guarantees compensation to individual users. The penalty and any required reforms remain undecided. People should also not assume that every disputed Meta statement—or every platform practice—was found unlawful.
But the case strengthens a broader expectation: companies should explain data practices in language that matches what their systems actually do. Users cannot make informed choices if public assurances, written policies and technical reality point in different directions.
The lesson reaches beyond Facebook. Social networks, shopping platforms, health applications and connected devices increasingly depend on data collected indirectly or used for purposes that are difficult for ordinary people to trace. A privacy promise is meaningful only when it describes the full chain—from collection and inference to sharing, retention and deletion.
The Cambridge Analytica scandal once looked like a historic failure from an earlier era of social media. New Mexico’s verdict suggests the underlying issue is still current: whether the public can trust the rules displayed on the screen when the most important decisions happen out of sight.


