Your Data, Their Rules: Read What You Signed
| Law, Business & Power Correspondent --- $18 billion.
By Harvey Specter Jr. | Law, Business & Power Correspondent
---
$18 billion. Write that number out longhand and it stops looking like a settlement — it starts looking like an admission. Meta just agreed to pay that figure to resolve child safety lawsuits across the United States, and buried inside the deal are two provisions that most people will miss because they're too busy reacting to the number. First: Meta must restrict how long young users can scroll. Second: those users — and their parents — cannot simply toggle off the safety settings Meta installs. The platform built the rules. You don't get to opt out of them once the regulator is watching.
This is not a privacy settlement. This is a structural consent order wearing a privacy settlement's clothes. And if you understand that distinction, you understand exactly what is about to change — not just in California, not just in America, but inside every boardroom from Brussels to Valletta where a company is still treating user data like an unlocked cabinet.
Here is what the law actually says, not in America but in the EU, which is where most of you reading this operate or consume. The General Data Protection Regulation — Regulation (EU) 2016/679 — does not permit you to bury consent inside terms that a reasonable person cannot understand. Article 7 is explicit: consent must be freely given, specific, informed, and unambiguous. Article 8 tightens it further for children under 16: parental consent is not optional, it is mandatory, and the burden of proof sits entirely with the data controller. Not with the parent. Not with the child. With the company that built the product.
Meta spent years designing systems that made it difficult to say no and invisible to say yes. The $18 billion is not a fine for collecting data. It is the price of designing systems that knew exactly what they were doing and kept doing it. The distinction matters because it tells you what the next enforcement wave looks like. Regulators are no longer interested in whether you had a privacy policy. They are interested in whether the architecture of your product was designed to circumvent the protections your privacy policy claimed to provide.
I have seen this pattern before in a different context — not in tech, but in contracts. A landlord presents a lease with seventeen clauses. Clause four gives with one hand. Clause fourteen takes with the other. The tenant signs because nobody reads clause fourteen. The landlord knows nobody reads clause fourteen. That knowledge, that intentional design around the gap between what people read and what they signed, is the same structure Meta built at planetary scale. And that structure, in EU law, is not protected by the signature. It is challenged by it.
The Oura sleep-tracking lawsuit running in parallel asks a quieter but equally sharp question: when a company markets AI-powered precision, what does it owe you when the precision fails? Under EU consumer protection law — specifically the Unfair Commercial Practices Directive 2005/29/EC — a misleading representation about a product's technical capability is an unfair practice regardless of whether the company intended to mislead. Intent is irrelevant. The gap between what was marketed and what was delivered is the entire case.
This matters for Malta specifically because we sit inside the EU enforcement architecture. The Malta Competition and Consumer Affairs Authority has powers under that Directive. Any company selling a wearable, an app, or an AI-powered service in Malta and marketing it with precision claims it cannot substantiate is not operating in a legal grey area. It is operating in a lit room with the curtains open.
The move the other side always makes in these cases is to point to the terms of service. They will show you clause nineteen, which says the device provides "estimated" data and makes "no warranty of accuracy." They will argue you consented to the limitation. Here is what that argument misses: if your marketing says "precise sleep tracking" and your terms say "estimated data," you have a contradiction that no consumer could reasonably resolve. EU law does not require you to read the footnotes in order to be protected from the headline.
The practical takeaway is one sentence worth saving: if you run a business that collects user data, markets AI-powered features, or targets anyone under 16 in Malta or anywhere in the EU, audit your consent flows against Article 7 and Article 8 of the GDPR before someone else does it for you — because the company that audits itself writes the memo; the company that doesn't writes