ICO hints at Facebook hypocrisy over data protection goals
Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation


The Information Commissioner's Office (ICO) has responded to Mark Zuckerberg's call for greater regulation for internet firms, by asking Facebook to drop its appeal over a data protection fine.
Writing an opinion piece in the Washington Post, Zuckerberg outlined four areas which he felt new regulations and standardised systems were needed. He called for the global enforcement of privacy, election integrity and data protection rights.
While these all sound like the right things to say, the UK's Information Commissioner Elizabeth Denham took the opportunity to point out that Facebook is still fighting current regulations.
"In light of Mark Zuckerberg's statements over the weekend about the need for increased regulation across four areas, including privacy, I expect Facebook to review their current appeal against the ICO's 500,000 fine - the maximum available under the old rules - for contravening UK privacy laws," she said in a statement on Monday.
The fine Denham referred to is the 500,000 fine, the maximum under the Data Protection Act 1998, which the regulator imposed on Facebook in October for serious breaches of data protection law.
An ICO investigation found that between 2007 and 2014, Facebook processed the personal information of users unfairly by allowing app developers access to their information without clear and informed consent - this also included access even if users had not downloaded the Facebook app, but were friends with people who had.
Facebook also failed to keep personal information secure because it failed to make suitable checks on apps and developers using its platform. This directly led to the Cambridge Analytica scandal, which has seen Facebook become the focus of tougher internet and data regulations.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Since then, the social network and Zuckerberg, has sought to change its reputation and by repeatedly sending out the message that it's doing everything it can to comply with data privacy. However, despite talking a good game, there have been plenty of incidents to show the company still isn't on the ball when it comes to data protection, such as the recent announcement that millions of users passwords were left unencrypted.
In response to the ICO's call to drop its appeal, Facebook told IT Pro that it thinks there is a place for increased regulation of the tech industry, but that doesn't mean it won't disagree with regulators on some of the decisions made. The social network stands by the statement it released in November, outlining its appeal.
"The ICO's investigation stemmed from concerns that UK citizens data may have been impacted by Cambridge Analytica, yet they now have confirmed that they have found no evidence to suggest that information of Facebook users in the UK was ever shared by Dr Kogan with Cambridge Analytica, or used by its affiliates in the Brexit referendum," a spokesperson said.
"Therefore, the core of the ICO's argument no longer relates to the events involving Cambridge Analytica. Instead, their reasoning challenges some of the basic principles of how people should be allowed to share information online, with implications which go far beyond just Facebook, which is why we have chosen to appeal."
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Why keeping track of AI assistants can be a tricky business
Column Making the most of AI assistants means understanding what they can do – and what the workforce wants from them
By Stephen Pritchard
-
Nvidia braces for a $5.5 billion hit as tariffs reach the semiconductor industry
News The chipmaker says its H20 chips need a special license as its share price plummets
By Bobby Hellard
-
New Zealand privacy commissioner tipped to become next ICO head
News John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
By Bobby Hellard
-
What is a freedom of information (FOI) request?
In-depth We look at the mechanism citizens can use to hold public bodies to account
By Dale Walker
-
ICO's regulatory Sandbox enters beta phase
News Sandbox will help startups ensure personal data-based products and services comply with data protection laws
By Bobby Hellard
-
ICO to investigate Google over GDPR violations
News UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
By Bobby Hellard
-
ICO myth-busts on the flow of data post Brexit
News The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
By Bobby Hellard
-
Leave.EU faces big fine over data law breaches
News Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
By Alan Martin
-
ICO website knocked offline for more than 24 hours
News The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
By Keumars Afifi-Sabet
-
Five NHS bodies breach Data Protection Act
News The ICO finds five NHS bodies recently breached the Data Protection Act, as the health service is called on to up its security game.
By Tom Brewster