Meta's $18B Settlement Allows Retention of Children's Data for Age-Detection AI Training

Privacy advocates warn of loophole as 29-state deal grants legal cover for data use that would otherwise violate COPPA

edit
By LineZotpaper
Published
Read Time3 min
Meta has agreed to a landmark $18 billion settlement with 29 U.S. states over allegations it improperly collected data from children under 13 without parental consent, but the deal includes a controversial provision that permits the company to retain and use that data to train age-detection models — a trade-off critics say effectively grants a legal pass for exploiting minors' information.

The settlement, announced Wednesday, resolves a multi-state investigation into Meta's practices across Facebook and Instagram, where the states alleged the company knowingly allowed children under 13 to create accounts and collected their personal data in violation of the Children's Online Privacy Protection Act (COPPA). The $18 billion figure — one of the largest privacy-related settlements in U.S. history — is intended to compensate affected users and fund state enforcement efforts.

However, buried in the 87-page agreement is a clause that explicitly allows Meta to keep data already gathered from under-13 users for the purpose of developing and testing automated systems to detect underage accounts. The company can process this data — which includes profile photos, friend networks, and behavioral patterns — to train machine learning models that flag likely children. Meta argued the provision is necessary to build effective age verification tools, which it says will better protect children going forward.

“This settlement ensures Meta is held accountable for past violations while enabling responsible innovation in child safety technology,” a Meta spokesperson said. “The ability to use data for age detection is critical to building systems that keep young people off platforms designed for adults.”

But the carve-out has drawn sharp criticism from privacy advocates and some state attorneys general who participated in the negotiations. “This gives Meta a free pass to exploit children's data under the guise of safety,” said Emily Bauer, director of the Digital Rights Project. “The company broke the law for years, and now it gets to keep the fruits of that violation to build its next product.” The settlement does not require Meta to delete the data after the models are trained; it only restricts other uses, such as advertising or content personalization.

The deal is subject to court approval but has already been approved by the attorneys general of all 29 states involved. Notably, several states — including California, New York, and Illinois — were not part of the multi-state group and are pursuing separate litigation against Meta over similar issues. Their cases may be affected by the precedent set here: the settlement explicitly states it does not limit states' ability to enforce COPPA independently, but critics worry the carve-out normalizes retention of illegally obtained data.

The U.S. Federal Trade Commission, which also has an ongoing probe into Meta's children's privacy practices, declined to comment. Legal experts say the settlement could influence how other tech companies address age verification, potentially leading to broader acceptance of using minors' data for detection tools without explicit parental consent.

§

Analysis

Why This Matters

  • The settlement creates a legal precedent that could allow tech companies to retain data obtained through past violations for safety or age-verification purposes, potentially undermining COPPA's core principle of deleting illegally collected data.
  • For parents and children, the deal means Meta can continue using information from under-13 users without obtaining retroactive consent, raising ongoing privacy risks even as the company promises better future protections.
  • The outcome could shape upcoming federal legislation on children's online safety, including the Kids Online Safety Act (KOSA), by demonstrating that enforcement settlements can include data-retention carve-outs.

Background

Meta has faced years of scrutiny over its handling of children's data. In 2022, the Federal Trade Commission fined the company $5 billion for privacy violations related to Cambridge Analytica, but that case did not specifically address child privacy. Whistleblower Frances Haugen's 2021 disclosures revealed internal research showing Instagram's harmful effects on teens, and subsequent investigations uncovered that the company was aware of large numbers of under-13 users but did little to remove them.

The multi-state investigation began in late 2021, led by a coalition of attorneys general from states including Florida, Nebraska, and Texas. They alleged Meta not only collected data from children without parental consent but also used that data to target ads and train recommendation algorithms. The states originally sought both monetary penalties and a court order requiring Meta to delete all illegally obtained data.

Negotiations stretched over three years, with Meta pushing to retain data for age detection — a capability it says is essential to enforce its own age limits. The final settlement, announced in August 2024, reflects a compromise: Meta pays $18 billion but gets the data carve-out.

Key Perspectives

Meta: The company argues that using children's data for age-detection AI is necessary to improve safety at scale. Without access to real-world data from actual under-13 users, age estimation models would be inaccurate and could flag teens or adults incorrectly, leading to blocked accounts and lost revenue. Meta says it will not use the data for any other purpose and will delete it once the models are validated.

State Attorneys General (participating): The 29 states view the settlement as a major victory. They secured what is essentially a historic financial penalty and obtained commitments from Meta to implement robust age-verification systems by 2026. They argue that without the data-retention provision, the state would have had no leverage to force Meta to build these protections at all.

Critics and Privacy Advocates: Groups like the Electronic Privacy Information Center (EPIC) and the Center for Digital Democracy call the carve-out a betrayal of core privacy principles. They point out that Meta could have trained age-detection models on synthetic data or data from consenting adults. The provision, they say, incentivizes companies to collect children's data first and ask for permission later, knowing they can keep it if they claim a safety purpose.

Non-participating States: California, New York, and Illinois have filed separate lawsuits that argue the settlement does not go far enough. They are seeking deletion of all children's data and are likely to challenge the carve-out in court, creating potential for conflicting outcomes.

What to Watch

  • Court approval process: A federal judge in San Francisco will review the settlement for fairness. Public interest groups may file objections, potentially forcing modifications to the data-retention clause.
  • FTC action: The Federal Trade Commission's separate investigation could result in a broader remedy that requires data deletion nationwide, overriding the state settlement.
  • Implementation timeline: Meta must demonstrate working age-detection systems by January 2026. Failure to meet benchmarks could reopen the settlement or trigger additional penalties.
  • Legislative response: U.S. lawmakers may introduce new bills explicitly barring the use of illegally obtained data for AI training, closing the loophole this case has highlighted.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.