Meta faces privacy probes from EU, India and workers
Photo by DTSoft Official on Pexels
Meta’s internal mouse‑tracking system is under investigation for potentially breaching EU data‑protection rules, while courts in India and a settlement in Kentucky add fresh pressure on the company’s privacy practices.
Reuters reported that Meta’s tool records employees’ cursor movements and could capture data originating outside the United States. The system, designed for productivity monitoring, may transmit that information to servers in jurisdictions that lack the same safeguards as the EU, raising a possible conflict with the General Data Protection Regulation (GDPR). The European Commission has not yet opened a formal case, but the allegation alone signals a regulatory risk that Meta has not publicly addressed.
EU scrutiny of employee monitoring
The EU complaint centers on whether Meta’s mouse‑tracking software respects the GDPR’s requirement for lawful, transparent processing of personal data. Under Article 6, a data controller must have a legitimate basis for any monitoring that can identify an individual. Critics argue that Meta has not provided employees with a clear opt‑out or an impact assessment, both of which are mandated by the regulation.
Meta’s internal policy documents, obtained by Reuters, describe the tool as a “performance‑enhancement utility.” The language does not mention cross‑border data flows, nor does it reference the GDPR’s “data minimisation” principle. If the system does indeed log keystrokes or screen coordinates that can be linked to a specific user, the practice could be classified as “profiling” under Article 4(4) of the GDPR, which carries additional compliance obligations.
Indian Supreme Court rebukes Meta and WhatsApp
In a separate front, the Supreme Court of India issued a stern statement on Tuesday, criticizing Meta Platforms and WhatsApp LLC for their privacy policy. The Court said it would not allow the companies to “exploit the personal data of Indians.” The remarks came during hearings on appeals filed by Meta and WhatsApp against a National Company Law Appellate Tribunal (NCLAT) judgment that upheld earlier restrictions on the firms’ data‑handling practices.
The Court’s observation does not constitute a binding order, but it signals that any future regulatory action could be backed by the nation’s highest judicial authority. Indian privacy law, anchored in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, requires explicit consent for processing sensitive personal data. The Supreme Court’s language suggests that the current consent mechanisms employed by Meta and WhatsApp may fall short of that standard.
Settlement over social‑media addiction in Kentucky
Meta’s legal exposure is not limited to overseas regulators. A Kentucky school district that sued the company for allegedly fostering social‑media addiction secured a $27 million settlement, according to Engadget. The district’s claim rested on the premise that Meta’s platforms were designed to keep minors engaged for prolonged periods, thereby impairing academic performance.
The settlement does not include an admission of wrongdoing, but it does require Meta to fund a series of digital‑literacy programs in the district. While the amount is modest relative to Meta’s global revenues, the case highlights a growing trend of local jurisdictions using civil litigation to enforce privacy‑related expectations.
AI smart glasses and hidden data workers
Meta’s upcoming AI‑enabled smart glasses have attracted scrutiny for the way they collect and process visual data. Investigations by Sweden’s Svenska Dagbladet and Göteborgs‑Posten revealed that a subcontractor in Nairobi, Kenya, employs thousands of annotators who label video streams captured by the glasses. Workers reported seeing footage of people in private settings – including bathrooms and bedrooms – without the subjects’ knowledge.
The reports quote a Nairobi employee: “In some videos you can see someone going to the toilet, or getting undressed. I don’t think they know, because if they knew they wouldn’t be recording.” The workers, employed by a firm called Sama, are tasked with drawing bounding boxes around objects and faces to improve the glasses’ computer‑vision models. The chain of custody for that data – from the wearer’s eyes to Meta’s training pipelines – raises questions about consent under both EU and Indian privacy frameworks.
Android tracking abuse linking Meta and Yandex
A joint research effort led by IMDEA Networks and Radboud University uncovered a separate privacy‑abuse vector that affects Android devices worldwide. The study found that native Meta apps such as Facebook and Instagram, as well as Yandex applications, open local servers on the device and listen on fixed ports. Through these channels, the apps receive web‑tracking data from Meta’s Pixel and Yandex Metrica scripts embedded on millions of websites.
The researchers documented that Meta’s Pixel has been using this technique since September 2024, while Yandex’s approach dates back to 2017. The Pixel is estimated to be present on 5.8 million sites; Yandex Metrica on 3 million. By bridging the local port to the logged‑in app, the trackers can attach a persistent identifier – such as the Android Advertising ID – to a user’s browsing history, effectively bypassing Android’s permission model and even Incognito mode.
Browser vendors have been notified, and Chrome plans to roll out a mitigation soon. Until that mitigation is live, the abuse remains technically feasible on any Android device that runs the implicated apps.
Financial fallout from privacy‑focused platform changes
Meta’s privacy challenges have translated into a measurable earnings impact. The company’s chief financial officer, David Wehner, told analysts that Meta expects to lose more than $10 billion in ad revenue, roughly 8 % of its annual income, as a direct consequence of Apple’s App Tracking Transparency (ATT) framework. The loss contributed to a 26 % drop in Meta’s share price after the latest earnings release.
While the ATT change primarily affects iOS users, the broader regulatory environment – including the EU investigation, the Indian Supreme Court remarks, and the Kentucky settlement – compounds the revenue pressure. Advertisers are increasingly demanding proof of compliance, and Meta’s ability to deliver granular audience segments may be eroded if further restrictions are imposed.
What to watch
The next quarter will reveal whether the European data‑protection authority opens a formal GDPR investigation into Meta’s employee‑tracking software. In India, the Supreme Court’s next order on the appeals could set a precedent for consent standards across the country’s digital services. Finally, the rollout of Chrome’s mitigation for local‑port tracking will be a litmus test for whether Meta can curb the Android abuse before additional lawsuits surface. Stakeholders should monitor these regulatory filings, as they will shape Meta’s privacy roadmap and its capacity to monetize user data.
All factual statements are drawn from the sources cited above.
Updates
- 2026-08-01 — What is a silicon carbon battery and is it the answer to smartphone battery life issues? (source)
Related Articles
Meta’s Smart Glasses Spark Privacy Outcry as Workers in Nairobi
Meta’s new AI glasses raise alarm over covert data collection and reveal a hidden workforce in Kenya, while open‑source tools aim to curb the privacy fallout.
AI tools spark legal and environmental pushback across tech
Reddit, Google, a Pennsylvania high school, and SpaceXAI each face scrutiny over AI misuse, misinformation, and regulatory violations.
AI funding spikes as trust tools spark legal and platform
Ellis AI lands $10M seed while AI‑generated trust fuels scams, a federal lawsuit, and Google’s quick feature rollback.