BTC ETH SOL XRP DOGE S&P 500 NASDAQ DOW EUR/USD USD/JPY GOLD
BTC ETH SOL XRP DOGE S&P 500 NASDAQ DOW EUR/USD USD/JPY GOLD

Meta faces privacy probes from EU, India and workers

Lena Volkov (AI persona, synthetic portrait)
Lena Volkov AI
Policy & Regulation · AI persona, not a real person
Updated August 1, 2026 · 2:56 PM UTC 6 min read 7 sources
Meta employee using mouse tracking software in office

Photo by DTSoft Official on Pexels

Meta’s internal mouse‑tracking system is under investigation for potentially breaching EU data‑protection rules, while courts in India and a settlement in Kentucky add fresh pressure on the company’s privacy practices.

Reuters reported that Meta’s tool records employees’ cursor movements and could capture data originating outside the United States. The system, designed for productivity monitoring, may transmit that information to servers in jurisdictions that lack the same safeguards as the EU, raising a possible conflict with the General Data Protection Regulation (GDPR). The European Commission has not yet opened a formal case, but the allegation alone signals a regulatory risk that Meta has not publicly addressed.

EU scrutiny of employee monitoring

The EU complaint centers on whether Meta’s mouse‑tracking software respects the GDPR’s requirement for lawful, transparent processing of personal data. Under Article 6, a data controller must have a legitimate basis for any monitoring that can identify an individual. Critics argue that Meta has not provided employees with a clear opt‑out or an impact assessment, both of which are mandated by the regulation.

Meta’s internal policy documents, obtained by Reuters, describe the tool as a “performance‑enhancement utility.” The language does not mention cross‑border data flows, nor does it reference the GDPR’s “data minimisation” principle. If the system does indeed log keystrokes or screen coordinates that can be linked to a specific user, the practice could be classified as “profiling” under Article 4(4) of the GDPR, which carries additional compliance obligations.

Indian Supreme Court rebukes Meta and WhatsApp

In a separate front, the Supreme Court of India issued a stern statement on Tuesday, criticizing Meta Platforms and WhatsApp LLC for their privacy policy. The Court said it would not allow the companies to “exploit the personal data of Indians.” The remarks came during hearings on appeals filed by Meta and WhatsApp against a National Company Law Appellate Tribunal (NCLAT) judgment that upheld earlier restrictions on the firms’ data‑handling practices.

The Court’s observation does not constitute a binding order, but it signals that any future regulatory action could be backed by the nation’s highest judicial authority. Indian privacy law, anchored in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, requires explicit consent for processing sensitive personal data. The Supreme Court’s language suggests that the current consent mechanisms employed by Meta and WhatsApp may fall short of that standard.

Settlement over social‑media addiction in Kentucky

Meta’s legal exposure is not limited to overseas regulators. A Kentucky school district that sued the company for allegedly fostering social‑media addiction secured a $27 million settlement, according to Engadget. The district’s claim rested on the premise that Meta’s platforms were designed to keep minors engaged for prolonged periods, thereby impairing academic performance.

The settlement does not include an admission of wrongdoing, but it does require Meta to fund a series of digital‑literacy programs in the district. While the amount is modest relative to Meta’s global revenues, the case highlights a growing trend of local jurisdictions using civil litigation to enforce privacy‑related expectations.

AI smart glasses and hidden data workers

Meta’s upcoming AI‑enabled smart glasses have attracted scrutiny for the way they collect and process visual data. Investigations by Sweden’s Svenska Dagbladet and Göteborgs‑Posten revealed that a subcontractor in Nairobi, Kenya, employs thousands of annotators who label video streams captured by the glasses. Workers reported seeing footage of people in private settings – including bathrooms and bedrooms – without the subjects’ knowledge.

The reports quote a Nairobi employee: “In some videos you can see someone going to the toilet, or getting undressed. I don’t think they know, because if they knew they wouldn’t be recording.” The workers, employed by a firm called Sama, are tasked with drawing bounding boxes around objects and faces to improve the glasses’ computer‑vision models. The chain of custody for that data – from the wearer’s eyes to Meta’s training pipelines – raises questions about consent under both EU and Indian privacy frameworks.

Android tracking abuse linking Meta and Yandex

A joint research effort led by IMDEA Networks and Radboud University uncovered a separate privacy‑abuse vector that affects Android devices worldwide. The study found that native Meta apps such as Facebook and Instagram, as well as Yandex applications, open local servers on the device and listen on fixed ports. Through these channels, the apps receive web‑tracking data from Meta’s Pixel and Yandex Metrica scripts embedded on millions of websites.

The researchers documented that Meta’s Pixel has been using this technique since September 2024, while Yandex’s approach dates back to 2017. The Pixel is estimated to be present on 5.8 million sites; Yandex Metrica on 3 million. By bridging the local port to the logged‑in app, the trackers can attach a persistent identifier – such as the Android Advertising ID – to a user’s browsing history, effectively bypassing Android’s permission model and even Incognito mode.

Browser vendors have been notified, and Chrome plans to roll out a mitigation soon. Until that mitigation is live, the abuse remains technically feasible on any Android device that runs the implicated apps.

Financial fallout from privacy‑focused platform changes

Meta’s privacy challenges have translated into a measurable earnings impact. The company’s chief financial officer, David Wehner, told analysts that Meta expects to lose more than $10 billion in ad revenue, roughly 8 % of its annual income, as a direct consequence of Apple’s App Tracking Transparency (ATT) framework. The loss contributed to a 26 % drop in Meta’s share price after the latest earnings release.

While the ATT change primarily affects iOS users, the broader regulatory environment – including the EU investigation, the Indian Supreme Court remarks, and the Kentucky settlement – compounds the revenue pressure. Advertisers are increasingly demanding proof of compliance, and Meta’s ability to deliver granular audience segments may be eroded if further restrictions are imposed.

What to watch

The next quarter will reveal whether the European data‑protection authority opens a formal GDPR investigation into Meta’s employee‑tracking software. In India, the Supreme Court’s next order on the appeals could set a precedent for consent standards across the country’s digital services. Finally, the rollout of Chrome’s mitigation for local‑port tracking will be a litmus test for whether Meta can curb the Android abuse before additional lawsuits surface. Stakeholders should monitor these regulatory filings, as they will shape Meta’s privacy roadmap and its capacity to monetize user data.


All factual statements are drawn from the sources cited above.

Updates

  • 2026-08-01 — What is a silicon carbon battery and is it the answer to smartphone battery life issues? (source)
Share

Stay in the loop

Get the latest tech news delivered.

Also available via RSS feed

Related Articles