FTC Should Keep X's Privacy Order Through 2042
Visual status: no verified article image is available. The reporting remains text-first.
FTC should keep X's privacy order in force through 2042.
X Corp has asked the Federal Trade Commission to set aside or modify a 2022 consent decree that requires ongoing reporting on its data practices, a move that comes as the agency weighs how much oversight to maintain after a string of privacy missteps. The petition, filed May 15, seeks to end or roll back a court approved order that ties X's compliance to regular disclosures about security and privacy posture and carries a $150 million penalty for the original violations. The decree traces back to a long running dispute over how the platform used private information, such as phone numbers and email addresses supplied to secure accounts, to fuel targeted advertising for hundreds of millions of users.
The petition is now in the hands of the FTC as part of an open comments period, with digital rights groups led by the Electronic Frontier Foundation and allies Demand Progress Education Fund, the National Consumers League, and the Electronic Privacy Information Center urging the agency to reject the bid. The groups argue that the underlying violations remain relevant and that the revised settlement, its 2011 foundation plus a 2022 renewal that stretches obligations to 2042, reflects a hard won, long tail of accountability. They contend that X's claim of a fresh privacy program staffed with new leadership does not erase the need for external oversight and a formal, enforceable commitment to protect user data.
The history is central to the debate. In 2011 Twitter, now X, settled with the FTC after regulators found failures to secure user data, exposing information to hackers. The settlement barred the company from misrepresenting its data protections and required robust safeguards, plus regular reporting on security practices for twenty years. The 2022 renewal extended that oversight, updating the obligation to run through 2042. If the FTC accepts X's petition, the enforcement backbone could be pried loose far sooner, potentially leaving users with less formal visibility into how their data is handled as the platform evolves under new ownership and leadership.
For compliance officers and tech leaders, the debate crystallizes a core tradeoff: long-running consent decrees create a predictable compliance framework that can stabilize a company's data program, but they also carry persistent costs and governance demands. The current setup means X must maintain a documented security program and publicly report on it for two decades, a level of transparency that can influence vendor contracts, product design, and budgeting for privacy engineers. If the order is weakened or lifted, the internal controls and external verification baked into the decree become more discretionary, which can raise the risk of a slide back into noncompliance if governance is not reinforced elsewhere.
Two practitioner insights stand out. First, long-tail consent decrees anchor privacy programs in durable governance, creating incentives to invest in privacy-by-design and external accountability. Compliance teams should watch whether the petition triggers a reallocation of resources toward short-term fixes versus enduring program improvements. Second, the enforcement lever remains potent. The $150 million penalty sets a floor for risk calculations, and the FTC can reprise or adjust terms if noncompliance reemerges. While a name change from Twitter to X signals rebranding, it does not erase regulatory liability or the appetite for rigorous oversight, at least in the eyes of the agency and privacy advocates.
What happens next hinges on the FTC's assessment of X's claims about a retooled privacy program and whether that program meets the behavioral standards the decree requires. Observers will also watch how the agency weighs user impact against corporate reforms, and whether a negotiated compromise could preserve some level of ongoing reporting while offering reasonable relief to the company. In the meantime, the core lesson for the industry is clear: even as leadership and branding change, legally binding privacy obligations with real penalties can shape risk, culture, and technology choices for years to come.
- EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be RejectedEFF Updates / Independent source / Published JUL 02, 2026 / Accessed JUL 07, 2026