Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 2843

Facebook, Inc., Consumer Privacy User Profile

U.S. District Court for the Northern District of California

The Facebook, Inc., Consumer Privacy User Profile litigation was centralized before Judge Vince Chhabria in the Northern District of California in June 2018, consolidating claims that Facebook improperly allowed third-party applications and business partners to access user profile data — and the data of users' social-media connections — without adequate notice or consent, part of the broader public scrutiny of the platform's data-sharing practices that intensified that year. Eight years on, the docket carries 33 pending actions, a durable population for a consumer-privacy MDL of this age.

What drives the docket's continued activity is the scale and complexity of the underlying conduct record: Facebook's data-sharing architecture involved numerous third-party partnerships and application programming interfaces developed over many years, and mapping which specific data flows and disclosures apply to a given claim requires substantial factual development. The core legal theories — under various state privacy and consumer-protection statutes, as well as common-law claims — have been extensively tested through motion practice and settlement negotiation over the docket's history, even as individual claims continue to work through the remaining framework.

This docket is a instructive example of how a single, high-profile data-practices controversy can generate a durable, multi-year MDL even without an ongoing stream of new triggering events, because the factual complexity of mapping historical data-sharing practices to individual claims takes years to fully litigate. Criterica Intelligence's platform tracks this kind of complexity-driven duration pattern — distinguishing dockets that remain active due to factual complexity from those still facing open liability questions — across every active MDL. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
What is this MDL about?

Claims that Facebook allowed third-party applications and business partners to improperly access user profile data, and that of users' connections, without adequate consent, part of the broader 2018 scrutiny of the platform's data-sharing practices.

Why does this docket remain active eight years after centralization?

The scale and complexity of Facebook's historical data-sharing architecture — numerous third-party partnerships and data flows — requires substantial factual development to map to individual claims, extending the docket's active life even as core legal theories have been tested.

Have the core liability theories in this docket been resolved?

Largely tested, yes — class-certification arguments and the applicable statutory frameworks have been extensively litigated and, in various tracks, addressed through settlement negotiation over the docket's history.

What does this docket illustrate about technology-sector privacy MDLs?

That factual complexity in mapping historical data practices to individual claims, not just open legal questions, can be a primary driver of a docket's duration — a pattern Criterica Intelligence tracks across comparable technology-sector litigation.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →