Buried in Meta’s $18B settlement is a legal pass on kids’ data
Buried in Meta’s $18B settlement is a legal pass on kids’ data
Meta 180亿美元和解协议中隐藏着一项针对儿童数据的法律豁免
In addition to paying out up to $18 billion and adding child safety measures, Meta’s settlement agreement with attorneys general from 29 states includes an interesting provision: The states have agreed not to sue Meta under existing child safety laws over its retention and use of children’s data. 除了支付高达180亿美元的赔偿金并增加儿童安全措施外,Meta与29个州总检察长达成的和解协议中还包含一项有趣的条款:各州同意不再根据现有的儿童安全法律,就Meta保留和使用儿童数据的问题起诉Meta。
That permission is being granted for the limited purpose of training and testing Meta’s age-assurance model and includes guardrails, but it’s a curious policy decision to make in a case centered on child safety, and one that could be difficult to properly enforce. 这项许可仅限于训练和测试Meta的年龄验证模型,并包含相应的防护措施。然而,在一个以儿童安全为核心的案件中做出这样的政策决定令人感到好奇,且该条款可能难以得到妥善执行。
As specified in the settlement agreement, Meta must develop, train, and begin testing a model designed to detect which users on Meta’s platforms are under the age of 13. This must be done within a year of the document’s effective date. (While the agreement doesn’t specify that the model has to be AI-based, Meta’s current age-detection tools are powered by AI technology.) 根据和解协议,Meta必须开发、训练并开始测试一种模型,旨在识别Meta平台上的哪些用户未满13岁。这项工作必须在协议生效日期后的一年内完成。(虽然协议并未明确要求该模型必须基于人工智能,但Meta目前的年龄检测工具均由AI技术驱动。)
Under U.S. child safety law, COPPA (Children’s Online Privacy Protection Act) typically requires that websites and apps limit the collection and retention of children’s personal information. Meta’s settlement agreement says that Meta shouldn’t need to violate COPPA to train or implement its age-assurance models. 根据美国儿童安全法律,《儿童在线隐私保护法》(COPPA)通常要求网站和应用程序限制对儿童个人信息的收集和保留。Meta的和解协议称,Meta在训练或实施其年龄验证模型时,不应违反COPPA的规定。
However, the agreement also says that the state AGs have agreed “fully, finally, and forever” not to bring any past, present, or future COPPA claims — or claims under similar state laws — related to Meta’s use of children’s data. The agreement makes clear that Meta can’t use data from users under age 13 for ad targeting, marketing, or algorithmic optimization. 然而,协议同时也指出,各州总检察长已同意“完全、最终且永久地”不再就Meta使用儿童数据的问题,提出任何过去、现在或未来的COPPA索赔,或根据类似州法律提出的索赔。协议明确规定,Meta不得将13岁以下用户的数据用于广告定位、营销或算法优化。
Meta’s request for legal protection, and the state AGs’ willingness to grant it, isn’t unreasonable, says Philip N. Yannella, a partner at law firm Blank Rome and co-chair of its Privacy, Security & Data Protection practice. “These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests,” he said, though he noted a caveat: COPPA is a federal law primarily enforced by the FTC, not the states, so it’s unclear whether the FTC, which isn’t a party to this settlement, has separately agreed to the same compromise. Blank Rome律师事务所合伙人兼隐私、安全与数据保护业务联席主席Philip N. Yannella表示,Meta寻求法律保护以及各州总检察长愿意授予该保护的做法并非不合理。他说:“这类数据最小化防护措施在隐私合规中非常典型,例如验证是否遵守了删除请求。”但他同时也提出了一个注意事项:COPPA是一项主要由联邦贸易委员会(FTC)而非各州执行的联邦法律,因此尚不清楚并非本和解协议一方的FTC是否也单独同意了同样的妥协。
It can be difficult for companies to keep data technically and organizationally isolated from the rest of their systems. Yet Meta is being asked to do just that — to isolate its understanding of children’s behavior signals and other data and use it solely for detecting and removing under-13 users. 对于公司而言,在技术和组织层面将数据与其系统的其余部分隔离开来可能非常困难。然而,Meta被要求做的正是如此——将其对儿童行为信号及其他数据的理解隔离开来,并仅将其用于检测和移除13岁以下的用户。
Fortunately, an independent auditor will be involved in monitoring Meta’s compliance with the settlement so we don’t only have to rely on Meta’s word. Policing this limitation could be complicated. The data could hypothetically feed into other Meta systems over time, or could raise questions over whether the data, signals, or insights derived from it are being used elsewhere within the company. 幸运的是,将有一名独立审计师参与监督Meta对和解协议的遵守情况,因此我们不必仅听信Meta的一面之词。监管这一限制可能会很复杂。从理论上讲,这些数据可能会随着时间的推移流入Meta的其他系统,或者引发关于这些数据、信号或从中得出的见解是否被公司内部其他部门使用的问题。
What’s not clear from the agreement is what data Meta will retain for training the model, how much behavioral information that may include, or how long it will retain the data. We also don’t know how these models will change in the future as Meta meets the settlement’s terms. 协议中不明确的地方在于,Meta将保留哪些数据用于训练模型,其中可能包含多少行为信息,以及它将保留这些数据多长时间。我们也不知道随着Meta履行和解条款,这些模型在未来会发生怎样的变化。
Barring state AGs from raising COPPA or similar state-law claims over this use of children’s data in the future could complicate the legal avenues states can pursue if questions arise around how Meta is using the data. That doesn’t prevent them from pursuing legal claims, notes Joshua Wurtzel, a partner at Schlam Stone & Dolan LLP. “If Meta uses the data outside those lines, the release and covenant not to sue don’t apply,” he said. 禁止各州总检察长在未来就此类儿童数据的使用提出COPPA或类似的州法律索赔,可能会使各州在Meta如何使用数据的问题上产生疑问时,难以通过法律途径进行追责。Schlam Stone & Dolan LLP律师事务所合伙人Joshua Wurtzel指出,这并不妨碍他们提起法律诉讼。他说:“如果Meta在这些界限之外使用数据,那么豁免权和不诉讼承诺将不再适用。”
But those legal disputes could still be complicated, since they’d hinge on whether Meta’s use of the data fell within the settlement’s terms. Peter Jackson, a Data & IP attorney at Greenberg Glusker LLP, agrees, saying the carve-out here could “disincentivize future enforcement actions.” “The Settlement Agreement’s age-assurance measures bear all the hallmarks of a heavy, and perhaps hasty, negotiation,” he says. 但这些法律纠纷可能依然复杂,因为它们将取决于Meta对数据的使用是否在和解协议的条款范围内。Greenberg Glusker LLP的数据与知识产权律师Peter Jackson对此表示赞同,称此处的豁免条款可能会“削弱未来执法行动的动力”。他说:“该和解协议中的年龄验证措施带有沉重且或许仓促谈判的所有特征。”
The decision also touches on a broader question that’s been coming up across the AI industry lately, especially as more AI agents are being developed to help consumers with various tasks. The systems often require significant access to users’ personal data to work well. Similarly, Meta may need deep insight into children’s use of social media in order to identify which accounts belong to young people. 这一决定还触及了近期整个AI行业出现的一个更广泛的问题,尤其是随着越来越多的AI智能体被开发出来以帮助消费者完成各种任务。这些系统通常需要大量访问用户的个人数据才能良好运行。同样,Meta可能需要深入了解儿童对社交媒体的使用情况,以便识别哪些账户属于未成年人。