Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The terms prohibit developers from using Platform Data to discriminate based on protected attributes, make eligibility determinations for housing, employment, credit, or immigration, perform or facilitate surveillance for law enforcement or national security purposes, sell or license Platform Data, or build user profiles without valid user consent. These prohibitions extend to facilitating or supporting third parties in performing these practices.
This analysis describes what Meta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a set of categorical restrictions on Platform Data processing that apply to developers, their Service Providers, and any third parties they support, with violations constituting grounds for immediate enforcement action under Section 7.
Under these terms, developers are prohibited from processing Platform Data, which includes profile information, location data, device information, and browsing activity, for purposes including discrimination, eligibility determinations, surveillance, data sale, or unconsented profile building.
Cross-platform context
See how other platforms handle Prohibited Data Practices for Platform Data and similar clauses.
Compare across platforms →Monitoring
Meta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You will not perform, or facilitate or support others in performing, any of the following prohibited practices (collectively, "Prohibited Practices"): i. Processing Platform Data to discriminate or encourage discrimination in a manner that disadvantages people based on personal attributes including race, ethnicity, color, national origin, religion, age, sex, sexual orientation, gender identity, family status, disability, medical or genetic condition, or any other categories prohibited by applicable law, regulation, or Meta policy. ii. Processing Platform Data to make eligibility determinations about people, including for housing, employment, insurance, education opportunities, credit, government benefits, or immigration status. iii. Processing Platform Data to perform, facilitate, or provide tools for surveillance. Surveillance includes the Processing of Platform Data about people, places, groups, or events for law enforcement or national security purposes. iv. Selling, licensing, or purchasing Platform Data. v. Processing Platform Data without valid User consent in order to build or augment user profiles for any purpose.Excerpt from Meta's Platform Policy
(1) REGULATORY LANDSCAPE: The prohibited practices align with obligations under GDPR (purpose limitation and data minimization principles), CCPA (restrictions on sale of personal information), the Fair Housing Act, Equal Credit Opportunity Act, and other US anti-discrimination statutes. The surveillance prohibition specifically addresses law enforcement and national security processing, which engages Fourth Amendment considerations and applicable national security law frameworks. COPPA is also relevant where Platform Data relates to minors. (2) GOVERNANCE EXPOSURE: High. The breadth of the eligibility determination prohibition, which covers not only denial of benefits but also the terms on which benefits are provided, extends beyond what some developers may have operationally scoped. The prohibition on facilitating third parties in these practices creates vicarious liability exposure for developers whose platforms enable downstream prohibited uses. (3) JURISDICTION FLAGS: GDPR enforcement in the EU creates heightened exposure for prohibited practices involving personal data, with potential fines under GDPR. California CCPA/CPRA restrictions on sale and sharing of personal information align with but may extend beyond the Platform Data sale prohibition. Illinois BIPA may be relevant where Platform Data includes biometric data. (4) CONTRACT AND VENDOR IMPLICATIONS: Developers must contractually prohibit Service Providers from engaging in Prohibited Practices, and the terms make developers responsible for Service Provider non-compliance. Vendor contracts should include explicit representations and warranties aligned with these prohibited practice categories. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct a data processing inventory to map all current uses of Platform Data against these prohibited categories, and should assess whether any existing analytics, profiling, or data partnership arrangements implicate the eligibility determination or profile-building prohibitions.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes a set of categorical restrictions on Platform Data processing that apply to developers, their Service Providers, and any third parties they support, with violations constituting grounds for immediate enforcement action under Section 7.
Under these terms, developers are prohibited from processing Platform Data, which includes profile information, location data, device information, and browsing activity, for purposes including discrimination, eligibility determinations, surveillance, data sale, or unconsented profile building.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Meta.