Court Rules
All enforcement actions
InvestigationHigh Risk

NJ AG Investigates Facebook Over Cambridge Analytica Data Harvesting

FacebookMarch 20, 2018New Jersey Attorney General

Summary

The New Jersey Attorney General announced an investigation into how the personal information of millions of Facebook users was harvested and obtained by Cambridge Analytica, a UK-based data analytics company. The AG expressed concern that Facebook may have allowed the harvesting and monetization of user data despite promises to keep it secure.

Contract Impact

In-house legal teams should review vendor agreements with third-party data analytics firms (like Cambridge Analytica), customer terms of service, and data processing agreements. Focus on clauses governing data sharing, user consent for data collection and monetization, security obligations, data retention, and breach notification. Changes may be needed to restrict unauthorized data harvesting, require explicit and granular user consent for data sharing with third parties, enhance audit rights over partner data practices, and strengthen security commitments to align with regulatory expectations and avoid similar investigations.

Contract Search Terms

data sharing agreementthird-party data sharinguser consent mechanismsdata processing addendumdata monetization clausesecurity commitmentsAPI data access termsdata retention policybreach notification clauseaudit rights

Violation Types

Entity Details

Entity

Facebook

Also known as: Meta

Industry

Technology

Official Sources

Source Evidence

Entity Name
"Facebook"
Violation Types
"how the personal information of millions of Facebook users came into the possession of Cambridge Analytica"
Violation Types
"Facebook may have allowed Cambridge to harvest and monetize its users’ private data"
Event Type
"we’ve launched an investigation"

Related Enforcement Actions

CT

Facebook

Connecticut Attorney General William Tong led a coalition of 14 attorneys general in demanding that Facebook disclose whether members of the 'Disinformation Dozen' were granted XCheck protections, which allow users to bypass enforcement rules. The coalition seeks information on the extent of anti-vaccine content from whitelisted users and complaint outcomes.

NJ

23andMe, Inc.

$18.0M

Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.

NJ

Block, Inc.

$45.0M

Block, Inc. agreed to a $45 million multistate settlement with 46 states for allegedly misleading consumers about the safety of Cash App, failing to protect users from fraud, and not providing promised fraud protection. The settlement requires Block to improve customer support, stop misleading claims, and educate consumers about fraud.

NJ

Office of the Attorney General of New Jersey

Attorney General Jennifer Davenport co-led a coalition of 49 attorneys general in calling on the FCC to strengthen rules to cut off scammers' access to legitimate telephone numbers. The coalition's letter requests stronger certification rules, regular reporting, and prohibitions on number cycling to combat illegal robocalls.

NJ

State of New Jersey

Governor Sherrill and Attorney General Davenport announced coordinated executive actions to reduce and eliminate junk fees in New Jersey. The initiative includes an Executive Order directing state agencies to review industries for junk fees and an Enforcement Statement from the Division of Consumer Affairs explaining how junk fee practices may violate the New Jersey Consumer Fraud Act.

NJ

New Jersey Bureau of Securities

The New Jersey Bureau of Securities announced its 2026 annual investment adviser examination, with a particular focus on firms' use of artificial intelligence and cybersecurity protocols. The examination requires nearly 800 registered investment adviser firms to answer questions about AI use in portfolio management, data protection policies, and third-party vendor due diligence. Failure to comply may result in administrative action.