Skip to content
Security & Trust

Facebook Liable for Over 43 Million Violations in New Mexico Privacy Verdict

The state seeks up to $5,000 per violation; a penalty hearing is Oct. 1. The verdict turns on what Facebook told users.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Facebook Liable for Over 43 Million Violations in New Mexico Privacy Verdict

AI-generated image for WebPulse. About our images

Key finding

Violations found by the jury: 43 million+ (Source: SecurityWeek (September 28, 2026))

What the jury decided

On Friday, jurors in Santa Fe held Facebook, a Meta property, liable under New Mexico's consumer protection law for misleading users about how their data is safeguarded, SecurityWeek reported. They counted more than 43 million violations after a two-week trial. Jurors further concluded that Facebook's public statements about its probes of outside app developers who collect user data, made in the wake of the Cambridge Analytica affair, were misleading. The state did not prove its claim that Facebook made false statements about removing harmful content. Meta said it disagrees with the verdict and will keep defending itself.

43 million+
Violations found by the jury
Source: SecurityWeek (September 28, 2026)

The liability sits in the statement, not only the breach

The case has its origin in a personality quiz run by an outside developer. SecurityWeek reports that information from about 87 million profiles ended up, through a sale, with the political consultancy Cambridge Analytica. The jury's findings, though, concern what Facebook said about protecting data and policing developers. For an executive, the distinction matters. A breach is an event. A public statement about data protection is a standing commitment that a jury can test against practice. Privacy notices, security pages and customer assurances all make that kind of commitment.

In closing, Facebook's counsel called the state's evidence stale. They noted that New Mexico had five years to build its case yet pointed to just one additional breach. The jury nonetheless sided with the state on the privacy claims.

Penalties are counted per violation

The state wants the top figure of $5,000 for each violation. SecurityWeek puts the ceiling at more than $200 billion if the judge imposes the maximum on every one, and interest would add to that if Meta appeals. The judge will decide on penalties at a hearing on Oct. 1, and the state is also seeking an injunction against similar practices. The violation count far exceeds the state's population of more than two million. SecurityWeek says jurors found the deceptive statements affected that entire population, but it does not explain how the violations were tallied.

$5,000
Maximum penalty sought per violation
Source: SecurityWeek (September 28, 2026)
Over $200 billion
Potential total if maximum awarded on every violation
Source: SecurityWeek (September 28, 2026)

Peter Ormerod, who teaches law at Villanova University as an associate professor, doubted in comments to SecurityWeek that this verdict will meaningfully discipline Meta, pointing to how profitable the company is. That assessment is specific to Meta. The source offers no view on how a per-violation penalty would land on a company with thinner margins.

A state that did not sign the settlement kept its own case alive

Meta's August deal with a group of states over child safety carries a price of up to $18 billion. SecurityWeek reports that the 130-page agreement also released Meta from future liability tied to the Cambridge Analytica breach. New Mexico did not sign that deal and pursued its case alone; Florida also did not sign, leaving the door open to future litigation. A separate two-phase trial in New Mexico over Meta's protections for minors had already produced $942 million in judgments this year. This is one company and one state's record. It does show that a state outside a settlement can carry its own claim forward.

$942 million
Prior New Mexico judgments against Meta (minors' safety case)
Source: SecurityWeek (September 28, 2026)

Questions for your team

1. Which public statements, including privacy notices, security pages and customer contracts, describe how we protect data and vet third parties? Who checks each one against current practice, and how often?

2. Do we have a current inventory of third-party apps, plugins and integrations with access to customer data? Could we show what we did when we investigated them?

3. Has counsel modelled per-violation penalty exposure under the consumer protection statutes in the states where we operate?

4. When we sign a settlement or release, who reviews which future claims it covers and which claimants are not bound by it?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: SecurityWeek.

Share this insight