EFF等组织呼吁FTC拒绝X公司撤销隐私命令请愿
SOURCE / EFF-Updates · EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
原文
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
完整原文
X Corp. should not be able to escape privacy compliance because it changed its name. On May 15, X Corp. filed a petition before the Federal Trade Commission (FTC) to set aside or modify an order issued in 2022 requiring the company to report regularly to the FTC for its violations of user data. The order or “consent decree” is a result of misleading the platforms’ 140 million users by using private information given to secure accounts, like phone numbers and email addresses, for targeted advertising. It also fined the company $150 million for the infraction. As part of an open comments period, EFF and allies including Demand Progress Education Fund (DPEF), National Consumers League (NCL) and Electronic Privacy Information Center (EPIC) call on the FTC to reject this petition . The 2022 order was a renewal of an order stemming from a previous violation. Back in 2011 , Twitter (now X) reached a settlement with the FTC after the regulator found Twitter had failed to secure users’ personal information, resulting in exposure of that data to hackers. The settlement banned the company from misrepresenting its data protection measures, required it to set up safeguards on user data, and regularly report its security posture for twenty years. The renewal updated the expiration of X’s obligations to 2042, but if the FTC accepts X's petition, it would end much sooner. In arguing to set aside the order, X remarks that since the order in 2011 it has “built an entirely new privacy and information security program staffed by new personnel operating under new leadership with a … philosophy grounded on the importance of privacy and information security.” These sweeping assurances that corporate restructuring led to a fundamental change in X’s policy and practices around user data should be met with a healthy dose of skepticism, given evidence to the contrary. For example, the company’s quiet rollout integrated its AI model Grok with the platform in 2024, trained (without meaningful consent ) on X user data. The company was also subject to a massive data breach in 2025. Even if a rotation of leadership led to prioritizing privacy and information security, our letter highlights that this would not be sufficient grounds to remove the order, “ because the FTC orders bind the corporate entity. Those obligations do not dissolve when the employees who negotiated or administered it depart.” X argues that its entry into the AI space should be reason not to continue the oversight, claiming that “terminating the Order is critical to advancing American leadership in artificial intelligence.” Here again, broad-stroke claims that the guardrails in place “[diverts] engineering resources from innovation to compliance paperwork” ignores the dangers that AI introduces to user data. Far from being a reason to waive the order, clever attacks on models trained on user data has the ability to supercharge the types of secondary use violations that led to the 2022 order renewal. After all, an entire art has been developed around engineering LLM prompts to reveal the data a model was originally trained on. Our response to X’s petition debunks many claims the company uses in its arguments. For example, there’s little evidence the order placed an undue financial burden on X. In our letter, we note that the compliance cost is merely “a rounding error against the $200 billion valuation of X Corp. following the xAI merger.” Strong safeguards on our information require eagle-eyed oversight when that data is abused and misused for profiteering ventures. X’s actions not only showed us this in the past, but continue to do so in the present day. We and our civil society partners urge the FTC to take the clear, sensible path and reject X’s petition.
归纳
X公司于5月15日向美国联邦贸易委员会(FTC)提交请愿,要求撤销或修改2022年因误导用户使用私人信息进行定向广告而发布的隐私违规命令。该命令要求X公司定期向FTC报告,并处以1.5亿美元罚款。电子前哨基金会(EFF)联合Demand Progress教育基金、全国消费者联盟和电子隐私信息中心等组织公开呼吁FTC拒绝该请愿。EFF指出,X公司声称重组后隐私政策根本改变的说法缺乏证据,例如2024年未经用户有效同意将AI模型Grok与平台整合并训练,以及2025年发生大规模数据泄露。X公司辩称命令阻碍AI创新,但EFF认为AI反而加剧数据滥用风险,且合规成本对X公司估值而言微不足道。EFF强调FTC命令约束的是企业实体,人员变动不能解除义务,敦促FTC驳回请愿。
点评
企业重组或控制权变更不能解除其数据合规义务,FTC命令约束的是实体而非特定人员。
法律视角点评
AI 生成 · 人工审核核心关切
企业重组或控制权变更不能解除其数据合规义务,FTC命令约束的是实体而非特定人员。
实务启示
中国法律人应关注《个人信息保护法》下企业合并、分立时数据合规义务的承继性,避免以组织架构调整为由规避监管。