The third session of the International Grand Committee on Disinformation, a multi-nation body comprised of global legislators with concerns about the societal impacts of social media giants, has been taking place in Dublin this week — once again without any senior Facebook management in attendance.
The committee was formed last year after Facebook’s CEO Mark Zuckerberg repeatedly refused to give evidence to a wide-ranging UK parliamentary enquiry into online disinformation and the use of social media tools for political campaigns. That snub encouraged joint working by international parliamentarians over a shared concern that’s also a cross-border regulatory and accountability challenge.
But while Zuckerberg still, seemingly, does not feel personally accountable to international parliaments — even as his latest stand-in at today’s committee hearing, policy chief Monika Bickert, proudly trumpeted the fact that 87 per cent of Facebook’s users are people outside the US — global legislators have been growth hacking a collective understanding of nation-state-scale platforms and the deleterious impacts their data-gobbling algorithmic content hierarchies and microtargeted ads are having on societies and democracies around the world.
Incisive questions from the committee today included sceptical scrutiny of Facebook’s claims and aims for a self-styled ‘Content Oversight Board’ it has said will launch next year — with one Irish legislator querying how the mechanism could possibly be independent of Facebook , as well as wondering how a retrospective appeals body could prevent content-driven harms. (On that Facebook seemed to claim that most complaints it gets from users are about content takedowns.)
Another question was whether the company’s planned Libra digital currency might not at least partially be an attempt to resolve a reputational risk for Facebook, of accepting political ads in foreign currency, by creating a single global digital currency that scrubs away that layer of auditability. Bickert denied the suggestion, saying the Libra project is unrelated to the disinformation issue and “is about access to financial services”.
Twitter’s recently announced total ban on political issue ads also faced some critical questioning by the committee, with the company being asked whether it will be banning environmental groups from running ads about climate change yet continuing to take money from oil giants that wish to run promoted tweets on the topic. Karen White, director of public policy, said they were aware of the concern and are still working through the policy detail for a fuller release due later this month.
But it was Facebook that came in for the bulk of criticism during the session, with Bickert fielding the vast majority of legislators’ questions — almost all of which were sceptically framed and some, including from the only US legislator in the room asking questions, outright hostile.
Google’s rep, meanwhile, had a very quiet hour and a half, with barely any questions fired his way. While Twitter won itself plenty of praise from legislators and witnesses for taking a proactive stance and banning political microtargeting altogether.
The question legislators kept returning to during many of today’s sessions, most of which didn’t involve the reps from the tech giants, is how can governments effectively regulate US-based Internet platforms whose profits are fuelled by the amplification of disinformation as a mechanism for driving engage with their service and ads?
Suggestions varied from breaking up tech giants to breaking down business models that were roundly accused of incentivizing the spread of outrageous nonsense for a pure-play profit motive, including by weaponizing people’s data to dart them with ‘relevant’ propaganda.
The committee also heard specific calls for European regulators to hurry up and enforce existing data protection law — specifically the EU’s General Data Protection Regulation (GDPR) — as a possible short-cut route to shrinking the harms legislators appeared to agree are linked to platforms’ data-reliant tracking for individual microtargeting.
A number of witnesses warned that liberal democracies remain drastically unprepared for the ongoing onslaught of malicious, hypertargeted fakes; that adtech giants’ business models are engineered for outrage and social division as an intentional choice and scheme to monopolize attention; and that even if we’ve now passed “peak vulnerability”, in terms of societal susceptibility to Internet-based disinformation campaigns (purely as a consequence of how many eyes have been opened to the risks since 2016), the activity itself hasn’t yet peaked and huge challenges for democratic nation states remain.
The latter point was made by disinformation researcher Ben Nimmo, director of investigations at Graphika.
Multiple witnesses called for Facebook to be prohibited from running political advertising as a matter of urgency, with plenty of barbed questions attacking its recent policy decision not to fact-check political ads.
Others went further — calling for more fundamental interventions to force reform of its business model and/or divest it of other social platforms it also owns. Given the company’s systematic failure to demonstrate it can be trusted with people’s data that’s enough reason to break it back up into separate social products, runs the argument.
Former Blackberry co-CEO, Jim Ballsillie, espoused a view that tech giants’ business models are engineered to profit from manipulation, meaning they inherently pose a threat to liberal democracies. While investor and former Facebook mentor, Roger McNamee, who has written a critical book about the company’s business model, called for personal data to be treated as a human right — so it cannot be stockpiled and turned into an asset to be exploited by behavior-manipulating adtech giants.
Also giving evidence today, journalist Carole Cadwalladr, who has been instrumental in investigating the Cambridge Analytica Facebook data misuse scandal, suggested no country should be trusting its election to Facebook. She also decried the fact that the UK is now headed to the polls, for a December general election, with no reforms to its electoral law and with key individuals involved in breaches of electoral law during the 2016 Brexit referendum now in positions of greater power to manipulate democratic outcomes. She too added her voice to calls for Facebook to be prohibited from running political ads.
In another compelling testimony, Marc Rotenberg, president and executive director of the Electronic Privacy Information Center (Epic) in Washington DC, recounted the long and forlorn history of attempts by US privacy advocates to win changes to Facebook’s policies to respect user agency and privacy — initially from the company itself, before petitioning regulators to try to get them to enforce promises Facebook had renaged on, yet still getting exactly nowhere.
No more ‘speeding tickets’
“We have spent the last many years trying to get the FTC to act against Facebook and over this period of time the complaints from many other consumer organizations and users have increased,” he told the committee. “Complaints about the use of personal data, complaints about the tracking of people who are not Facebook users. Complaints about the tracking of Facebook users who are no longer on the platform. In fact in a freedom of information request brought by Epic we uncovered 29,000 complaints now pending against the company.”
He described the FTC judgement against Facebook, which resulted in a $5BN penalty for the company in June, as both a “historic fine” but also essentially just a “speeding ticket” — because the regulator did not enforce any changes to its business model. So yet another regulatory lapse.
“The FTC left in place Facebook’s business practices and left at risk the users of the service,” he warned, adding: “My message to you today is simple: You must act. You cannot wait. You cannot wait ten years or even a year to take action against this company.”
He too urged legislators to ban the company from engaging in political advertising — until “adequate legal safeguards are established”. “The terms of the GDPR must be enforced against Facebook and they should be enforced now,” Rotenberg added, calling also for Facebook to be required to divest of WhatsApp — “not because of a great scheme to break up big tech but because the company violated its commitments to protect the data of WhatsApp users as a condition of the acquisition”.
In another particularly awkward moment for the social media giant, Keit Pentus-Rosimannus, a legislator from Estonia, asked Bickert directly why Facebook doesn’t stop taking money for political ads.
The legislator pointed out that it has already claimed revenue related to such ads is incremental for its business, making the further point that political speech can simply be freely posted to Facebook (as organic content); ergo, Facebook doesn’t need to take money from politicians to run ads that lie — since they can just post their lies freely to Facebook.
Bickert had no good answer to this. “We think that there should be ways that politicians can interact with their public and part of that means sharing their views through ads,” was her best shot at a response.
“I will say this is an area we’re here today to discuss collaboration, with a thought towards what we should be doing together,” she added. “Election integrity is an area where we have proactively said we want regulation. We think it’s appropriate. Defining political ads and who should run them and who should be able to and when and where. Those are things that we would like to work on regulation with governments.”
“Yet Twitter has done it without new regulation. Why can’t you do it?” pressed Pentus-Rosimannus.
“We think that it is not appropriate for Facebook to be deciding for the world what is true or false and we think that politicians should have an ability to interact with their audiences. So long as they’re following our ads policies,” Bickert responded. “But again we’re very open to how together we could come up with regulation that could define and tackle these issues.”
tl;dr Facebook could be seen once again deploying a policy minion to push for a ‘business as usual’ strategy that functions by seeking to fog the issues and re-frame the notion of regulation as a set of self-serving (and very low friction) ‘guide-rails’, rather than as major business model surgery.
Bickert was doing this even as the committee was hearing from multiple voices making the equal and opposite point with acute force.
Another of those critical voices was congressman David Cicilline — a US legislator making his first appearance at the Grand Committee. He closely questioned Bickert on how a Facebook user seeing a political ad that contains false information would know they are being targeted by false information, rejecting repeated attempts to misleading reframe his question as just about general targeting data.
“Again, with respect to the veracity, they wouldn’t know they’re being targeted with false information; they would know why they’re being targeted as to the demographics… but not as to the veracity or the falseness of the statement,” he pointed out.
Bickert responded by claiming that political speech is “so heavily scrutinized there is a high likelihood that somebody would know if information is false” — which earned her a withering rebuke.
“Mark Zuckerberg’s theory that sunlight is the best disinfectant only works if an advertisment is actually exposed to sunlight. But as hundreds of Facebook employees made clear in an open letter last week Facebook’s advanced targeting and behavioral tracking tools — and I quote — “hard for people in the electorate to participate in the public scrutiny that we’re saying comes along with political speech” — end quote — as they know — and I quote — “these ads are often so microtargeted that the conversations on Facebook’s platforms are much more siloed than on the other platforms,” said Cicilline.
“So, Ms Bickert, it seems clear that microtargeting prevents the very public scrutiny that would serve as an effective check on false advertisements. And doesn’t the entire justification for this policy completely fall apart given that Facebook allows politicians both to run fake ads and to distribute those fake ads only to the people most vulnerable to believe in them? So this is a good theory about sunlight but in fact in practice you policies permit someone to make false representations and to microtarget who gets them — and so this big public scrutiny that serves as a justification just doesn’t exist.”
Facebook’s head of global policy management responded by claiming there’s “great transparency” around political ads on its platform — as a result of what she dubbed its “unprecedented” political ad library.
“You can look up any ad in this library and see what is the breakdown on the audience who has seen this ad,” she said, further claiming that “many [political ads] are not microtargeted at all”.
“Isn’t the problem here that Facebook has too much power — and shouldn’t we be thinking about breaking up that power rather than allowing Facebook’s decisions to continue to have such enormous consequences for our democracy?” rejoined Cicilline, not waiting for an answer and instead laying down a critical statement. “The cruel irony is that your company is invoking the protections of free speech as a cloak to defend your conduct which is in fact undermining and threatening the very institutions of democracy it’s cloaking itself in.”
The session was long on questions for Facebook and short on answers with anything other than the most self-serving substance from Facebook.
Major GDPR enforcements coming in 2020
During a later session without any of the tech giants present which was intended for legislators to query the state of play of regulation around online platforms, Ireland’s data protection commissioner, Helen Dixon, signalled that no major enforcements will be coming against Facebook et al this year — saying instead that decisions on a number of cross-border cases will be coming in 2020.
Ireland has a plate stacked high with complaints against tech giants since the GDPR came into force in May 2018. Among the 21 “large scale” investigations into big tech companies that remain ongoing are probes around transparency and the lawfulness of data processing by social media platform giants.
The adtech industry’s use of personal data in the real-time bidding programmatic process is also under the regulatory microscope.
Dixon and the Irish Data Protection Commission (DPC) takes center stage as a regulator for US tech giants given how many of these companies have chosen to site their international headquarters in Ireland — encouraged by business friendly corporate tax rates.
The DPC has a pivot al role on account of a one-stop-shop mechanism within the regulation that allows for a data protection agency with primary jurisdiction over a data controller to take a lead on cross-border data processing cases, with other EU member states’ DPAs able to feed but not lead such a complaint.
Some of the Irish DPC’s probes have already lasted as long as the 18 months since GDPR came into force across the bloc.
Dixon argued today that this is still a reasonable timeframe for enforcing an updated data protection regime, despite signalling further delay before any enforcements in these major cases. “It’s a mistake to say there’s been no enforcement… but there hasn’t been an outcome yet to the large scale investigations we have open, underway into the big tech platforms around lawfulness, transparency, privacy by design and default and so on. Eighteen months is not a long time. Not all of the investigations have been open for 18 months,” she said.
“We must follow due process or we won’t secure the outcome in the end. These companies they’ve market power but they also have the resources to litigate forever. And so we have to ensure we follow due process, we allow them a right to be heard, we conclude the legal analysis carefully by applying what our principles in the GDPR to the scenarios at issue and then we can hope to deliver the outcomes that the GDPR promises.
“So that work is underway. We couldn’t be working more diligently at it. And we will have the first sets of decisions that will start rolling out in the very near term.”
Asked by the committee about the level of cooperation the DPC is getting from the tech giants under investigation she said they are “engaging and cooperating” — but also that they’re “challenging at every turn”.
She also expressed a view that it’s not yet clear whether GDPR enforcement will be able to have a near-term impact on reining in any behaviors found to be infringing the law, given further potential legal push back from platforms after decisions are issued.
“The regulated entities are obliged under the GDPR to cooperate with investigations conducted by the data protection authority, and to date of the 21 large-scale investigations were have opened into big tech organizations they are engaging and cooperating. With equal measure they’re challenging at every turn as well and seeking constant clarifications around due process but they are cooperating and engaging,” she told the committee.
“What remains to be seen is how the investigations we currently have open will conclude. And whether there will ultimately be compliance with the outcomes of those investigations or whether they will be subject to lengthy challenge and so on. So I think the big question of whether we’re going to be able to near-term drive the kind of outcomes we want is still an open question. And it awaiting us as a data protection authority to put down the first final decisions in a number of cases.”
She also expressed doubt about whether the GDPR data protection framework will, ultimately, sum to a tool that can regulate underlying business models that are based on collecting data for the purpose of behavioral advertising.
“The GDPR isn’t set up to tackle business models, per se,” she said. “It’s set up to apply principles to data processing operations. And so there’s a complexity when we come to look at something like adtech or online behavioral advertising in that we have to target multiple actors.