X seeks to erase years of FTC privacy oversight
Visual status: no verified article image is available. The reporting remains text-first.
X Corp seeks to erase years of FTC privacy oversight. That is the core aim of its May 15 petition to set aside or modify a 2022 consent decree that binds the company to report its handling of user data back to the agency and maintain privacy safeguards after years of missteps tied to data used for targeted advertising. The filing underscores a central tension in modern privacy enforcement: can a corporate makeover reset a long tail of obligations, and who gets to decide when the obligations end?
The 2022 order did not arrive in a vacuum. It was a renewal of a longstanding settlement that began after a 2011 finding that the company failed to secure user data and misrepresented its protection measures. The settlement barred the company from further misrepresentations, required the establishment of safeguards for user data, and obligated the company to provide periodic reporting on its security posture for two decades. The renewal in 2022 extended those obligations to 2042, creating a formal, time-bound compliance framework that regulators argue is designed to deter future lapses and give users a sense of ongoing protection.
The petition in question argues that X has changed its privacy and information security program under new leadership, with a redesigned staff and a philosophy centered on privacy. The filing states that these changes amounted to a substantive overhaul, one that should allow the FTC to set aside or modify the existing decree. That argument hinges on a standard claim often made after a corporate rebrand or leadership transition: a new regime, not the old one, should govern today’s operations. The company notes a new privacy program and personnel as evidence that it is no longer operating under the prior model.
But the petition has clear opponents. The Electronic Frontier Foundation and allies Demand Progress Education Fund, the National Consumers League, and the Electronic Privacy Information Center have urged the FTC to reject the request. Their stance rests on a simple premise: the consent decree is not a relic of the past, but a binding instrument that governs ongoing conduct. They argue that the order reflects real commitments to report and safeguard user data and that the posture of the company should be judged by its current practices, not assumptions about a post restructure.
For compliance officers and tech leaders watching this case, the stakes are practical. The decree establishes a compliance deadline regime anchored in regular reporting to the FTC and a framework for safeguarding data that traces back to a 2011 settlement and a 2022 renewal. The enforcement mechanism is the consent decree itself, a binding agreement with the FTC that imposes ongoing oversight. If the FTC denies the petition, X would continue to shoulder those obligations through 2042, preserving the horizon for continued audits, public disclosures, and potential corrective actions if lapses recur. If the FTC grants the petition, the clock could be reset, potentially shortening the compliance horizon and altering the scope of reporting and safeguards required.
Two to four practitioner insights emerge from this moment. First, the case reinforces that a corporate restructuring does not automatically erase decades of promise to protect user data; regulators will evaluate whether new leadership meaningfully changes behavior or simply markets a renewed posture. Second, for privacy and security teams, the case highlights the importance of robust, demonstrable program changes rather than reputational assurances, since the FTC and privacy groups will scrutinize current practices and not just tone. Third, the decision will influence how future consent decrees are drafted and renewed, particularly around the sequencing of leadership changes and enforceable commitments. Fourth, observers should watch how the FTC handles the open comments period and any subsequent ruling, because the direction could set a precedent for how strictly enforcement persists after a corporate reboot.
The outcome will shape not only X’s path but a broader view of how long consent decrees can bind large platforms to protect user data, even as corporate leadership changes. The moment tests whether a new privacy program can truly outpace a legacy decree or whether enforcement will continue to anchor corporate behavior long after a rebrand.
- EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be RejectedEFF Updates / Independent source / Published JUL 02, 2026 / Accessed JUL 06, 2026