Meta Platforms is confronting one of the most consequential privacy penalties ever sought against a technology company in the United States, after New Mexico asked a state judge to impose between $35 billion and $40 billion in penalties over misleading statements concerning Facebook users’ data.
The dispute traces back to the Cambridge Analytica scandal, in which personal information belonging to as many as 87 million Facebook users was harvested through a third-party application without their consent. New Mexico’s lawsuit, filed in 2021, argued that Meta misrepresented who could access users’ information and how the platform handled privacy, misinformation and harmful content.
26 Statements Found Misleading
The scale of the verdict is particularly significant. Jurors examined 29 statements made by Meta and its leadership and concluded that 26 were misleading. Based on the audiences for those statements, the jury calculated more than 43 million violations of New Mexico’s consumer-protection law.
State law permits penalties of up to $5,000 per violation. Applying that maximum mechanically would produce a vastly larger theoretical figure. New Mexico instead proposed $35–$40 billion, with its lawyers arguing that a substantial but lower amount would better withstand constitutional scrutiny over excessive penalties.
Meta strongly disputes that calculation. The company has urged Judge Francis Mathew to cap penalties at approximately $3.45 billion, arguing that New Mexico failed to demonstrate that consumers were actually deceived and maintaining that Meta does not sell users' personal data. The company also argues that the state's proposed penalty is disproportionate to the conduct examined at trial.
The Bigger Issue Is Accountability
The importance of this case extends beyond the eventual dollar amount. Traditionally, privacy enforcement has often focused on an identifiable data breach, unauthorized disclosure or measurable consumer injury. Here, the dispute puts considerable weight on what a digital platform told consumers about its practices.
That distinction matters. Privacy is increasingly becoming an issue not simply of protecting databases but of proving that corporate representations, consent mechanisms, third-party access controls and actual data-processing practices are aligned.
The case also illustrates how seemingly routine statements can create enormous cumulative exposure when consumer-protection statutes calculate violations across millions of users. For large digital platforms, therefore, privacy communication can become a financial and governance risk alongside cybersecurity itself.
A Warning for the AI Era
The implications become even broader as technology companies expand into generative AI and autonomous agents. AI systems can collect, infer, combine and act upon enormous volumes of personal information. Organizations may therefore have to demonstrate not merely that data is encrypted or protected, but why it was collected, whether valid consent existed, who accessed it, what an AI system inferred from it and how resulting decisions were made.
This makes privacy governance increasingly inseparable from AI governance. Consent records, data lineage, purpose limitation, third-party controls, audit trails and evidence of compliance are becoming critical components of enterprise technology architecture.
The New Mexico case is also part of wider legal pressure on Meta. In a separate New Mexico proceeding concerning alleged harms to young users, a court in August ordered Meta to pay $567 million into a youth mental-health fund and imposed platform changes; Meta said it would appeal.
Judge Mathew is expected to determine the penalty in the privacy case later in October. Until that ruling, the $35–$40 billion figure remains New Mexico's request, not an amount Meta has been ordered to pay.
Whatever the final figure, the broader message for technology companies is already clear: data privacy is moving from a compliance checklist toward measurable corporate accountability. In the AI economy, what companies promise about data may become almost as important as how securely they store it.





