EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
X Corp. has petitioned the FTC to set aside or modify a 2022 consent decree that requires regular compliance reporting and stemmed from the company using account-security data — phone numbers and email addresses — for targeted advertising, resulting in a $150 million fine. The EFF and allied groups have filed comments urging the FTC to reject the petition.
Why this matters: X collected phone numbers and email addresses from 140 million users under the pretense of account security, then used that data to sell ads. That is not a technicality. It is a straightforward bait-and-switch on people who handed over personal information to protect their accounts. The consent decree exists because of that. Now X is asking regulators to let it walk away from oversight, partly on the basis that it rebranded. A name change does not erase what the company did or who got hurt. The FTC should say no.
Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.