Unpacking the record $17 billion Meta settlement, plus U.S. Privacy Summit updates

In the latest Privacy Huddle, Colleen Barry is joined by Alysa Hutnik, Partner at Kelley Drye, to unpack the proposed $17 billion Meta settlement. They cover what state AGs are asking of Meta on teen privacy, which parts of the order travel to brands that are not Big Tech, and what's new on the U.S. Privacy Summit agenda six weeks out.

  • Regulatory FinesState Privacy LawsPrivacy Regulations
  • Episode 103
  • September 4, 2026
  • Host: Colleen Barry
  • Guests: Alysa Hutnik

Summary

On August 26, California Attorney General Rob Bonta and a coalition of U.S. state attorneys general announced a proposed $17 billion settlement with Meta. The states allege that Instagram and Facebook were designed with features that drive compulsive use by children and teens. The package, paid to states over ten years, also calls for product changes including daily time limits, overnight blocks, and limits on certain reaction mechanics.

The settlement is more than a Big Tech headline. It is a lengthy, regulator-blessed blueprint that privacy teams can borrow for teen and children's privacy, and for standing up governance in newer areas such as age assurance, risk assessments, and automated decision-making. Novel pieces include how to test and audit age-assurance error rates, user-design restrictions aimed at addictive behavior, and a requirement to keep testing whether those protections actually work, rather than filing a one-time compliance report.

Privacy teams should read the order even if they do not market to minors. Under-18 users are a much larger population than COPPA's under-13 set, and state AG offices that just closed a multi-year Meta matter now have bandwidth for the next letters. Pressure-test age assurance, purpose-limited identity data, and product features against this settlement, and treat it as a living library of issue-spotting prompts for product and engineering counsel.

Transcript

Colleen

Hi, Elisa. How are you doing today?

Alysa

Hi. Good to see you.

Colleen

Likewise. Here we are again, another episode of the privacy huddle. We've taken a little hiatus, folks, but it's for good reason. Elisa and I have been jammed up planning this incredible US privacy summit coming up, and, you know, we're only capable of so much. Right? So we had to take a hiatus for a few weeks, but we're back. And it's at an exciting time because we have some great updates on the summit. The agenda is now live so y'all can see the session. So registrations have been rolling in, Alisa. I'm getting excited. Six weeks out. How are you feeling?

Alysa

I'm super excited, and particularly also just seeing who's registering. Like, you can tell that there's a hunger for good on point content, and so that's just the best feedback. I think it's gonna be such a diverse, really interesting audience and that, you know, it promotes a whole lot of energy just in and of itself.

Colleen

I think so too. It's been fun to see. You know, of course, we ask how did you hear about the event, and it's a mix of attended last year and then heard I should have attended last year and all that kind of stuff, which is great. I know you've talked about this conference, our second annual US privacy summit as kind of the anti conference. What do you mean by that? In case brand leaders are on the fence about coming, what do you mean?

Alysa

Well, I mean, I've sat in so many conferences myself, you know, as the privacy sprees that we do. And I feel like we don't get to the heart of of sticky issues fast enough. Right? Like, we're often starting at kind of, let me tell you the landscape and zoom out quite a bit. And so I wanted it to just, like, what do I wanna know? If I'm sitting in the audience, like, where do I wanna get to right away and who are just different voices that we don't hear from all the time to be able to get a viewpoint, really ask some of those hard questions. So that's that's the idea. You know, it's we're aspirational, but I I think that's really the structure of it. And, it's a fresh take on a privacy conference.

Colleen

Yeah. I hope so too, and that's certainly the feedback we've gotten. So I'm feeling good. Think with the agenda update this week so, folks, we'll drop the link in the comments so you can peruse it yourself. But we've already announced a number of speakers ranging from in house privacy council to regulators from state AG offices, the FTC, Cal privacy. So we've announced lots of speakers that are on the site, but now we've actually gone into sessions. And so as Alisa said, we're really trying to hit on a mix of, one, updates from these regulators. Like, let's hear from Cal privacy. Let's hear from states outside California and what those AGs are grappling with. So we've really tried to make it a mix of content coming from the people enforcing the laws as well as more operational type panels with in house counsel talking about what they're grappling with when it comes to litigation and team privacy and AI governance and, you know, the woes of your marketing teams and how what they're dealing with. So we hopefully, it's very kind of hard hitting issues that you're dealing with day to day in your role is the goal. So, yeah, folks. Hopefully, you'll check that out. Let's get to today's topic, which speaking of issues that we are grappling with every day, Elise and I knew we had to do a huddle breaking down this historic seventeen billion dollar settlement against Meta. So that's what we wanna talk about today. Just spend some time breaking down what happened, what are the takeaways for privacy professionals, especially in house counsel, and kinda where do we go from here? What kind of blueprint does this give us to to refocus how we think about children and teen privacy in our day to day? So let's get into it. I wanna start with just making sure everyone is on the same page. In case you missed the news, right, August twenty sixth, California attorney general Rob Bonta announced with the coalition of a number of US state AGs proposed seventeen billion dollar settlement with Meta. Right? So what they essentially did was alleging among other things that the company has designed and deployed harmful features on Instagram and Facebook that drive compulsive use by children and teens. So it's up to seventeen billion to states over ten years, and there's a number of product changes, right, that they're suggesting that Meta take into account across these platforms from daily time limits, overnight blocks, bans on showing different kind of reactions and things, but all in the name of making it a safer environment for teens and children to be on social media. So we've seen actions against big tech companies before. This one is certainly a very big one. And I think when we see a settlement of this size, especially against big tech, it can be, I don't know, kind of hard to parse out. Like, should I dismiss it? It's meta. I don't need to worry about that versus are there things I should take away from my company, my brand, my business? Alisa, can you start to unpack your thoughts on this settlement and what books can take away?

Alysa

Sure. So one, you know, as you are wrestling with the business over a latest use case, often a question will be, well, what is the risk? And I think as we see and continue to see these different markers across a variety of types of companies, right, it's not just big tech. We're seeing some big numbers on the board. And so I think that goes to materiality. I think to be able to say, know, when they say, what is the risk? Well, it spans up to seventeen billion potentially, you know, depending on the facts. And so I think that catches attention in a way perhaps some of the early CCPA settlements, for example, may not have really kind of paused and really prompted the business to take a moment. So I think that that's really important. I think the other really big factor is you have a settlement that is, I mean, it's a treatise. Right? It is a fairly hefty document. I think there is always a whole lot of models built into those settlements that you can take and apply both to the subject matter. So here, we're talking about teen privacy, kids privacy, safety, online safety, feature use. But there's a lot of structure in there that you could apply to governance and auditing on any type of data focused practice that I think is just good governance and you can speak to. It was inspired by essentially a regulatory blessed set of structures. So I think as you read, as one were to read that settlement, really thinking, what can I borrow? Where are analogies here that could apply to other tough areas like risk assessments or automated decision making? How do I stand up a whole new program where there's not existing infrastructure to do that? So I always think that's really interesting. Then I think maybe the heart of it is just the UA team crowd. Like, this is both an age issue, so it's an identity, either verification or assurance. And so what is sufficient? And we're dealing with that across the board with so many different state laws. But then the product design, the differential journey depending on what age you're in, you know, is one thing when we're dealing with COPPA, but really the u eighteen prompts a whole other series of discussions and builds with the business. And I think, gosh, I again, you know, I feel for the privacy community because those are the same folks who are often dealing with the business teams on product design. And so we gotta work on our our spin so it doesn't sound like we're, you know, always giving the bad news. It's how can we make this, you know, a positive? But, yeah, lots lots to take from it.

Colleen

Yeah. No doubt. And it's interesting hearing you talk about takeaways for other areas outside team privacy because I do think it's easy to look at this and assume that maybe you don't need to read the order or really digest it in detail if you have a business that's not marketing or collecting data for younger people. But you're suggesting there's takeaways for other areas. Is it more of the same? Right? We see a lot of the same themes being repeated in these settlements. Is it more of the same, or are there new things that you see?

Alysa

I thought there were some new things in here because I think, you know, when you have some tried and true practices that run into opt out, for example, I think we see the same kind of language about what we expect from an opt out. But when we're dealing with newer issues, which are challenging. Right, age assurance is a challenging issue. I don't think we have a single standard. And there's a lot of, you know, I would say maybe criticisms depending on what you're using on both sides of the issue. There was a lot of interesting information in here in terms of when, how, error rates, how do you test it, how do you review, how are you auditing it. I think that's a pretty interesting piece to just take away, you know, of an evolving technology, but where we are more and more gonna have an expectation of deploying that. Like, how do you get a confidence level that is reasonable? Of course, I also look at that and I think of, gosh, there's other ways we can do that. What about bias in automated decision making? You know? So it gave a good structure there that I thought was really helpful and novel. I think there were there's a lot of user design restrictions and considerations, right, to I think the idea was to stop some of the addictive behavior. Some of those feature designs are it's an online safety type of question, which I think in a variety of circumstance, you could build and really think about. And this was not a point in time set of injunctive terms. There was a lot of testing, evaluation, is it working? And that's something it's not like I said it. Forget it. I met the settlement requirements. I can put it in a compliance report at the end of the year. There's a dynamic ongoing cadence to testing some of these features and protections to see if they're working. I thought that was pretty interesting.

Colleen

Yeah. Which that is continues to show that these enforcers have technologists on staff and are actually dictating or recommending what you're doing at a data workflow level and an identity level beyond just checking the policy, right, and whatnot. Very interesting. Do you think so back to your point about takeaways for product and engineering teams, is that a recommendation you would have for in house counsel kind of figuring out how to get this in a digestible format to present or show your engineering teams as kind of some proof points for what you should have in place?

Alysa

Yeah. For sure. So, I mean, I kinda think of the repository as you take when COPPA when the FTC amended the COPPA rule, there was a lot of really helpful information about certain features, right, to to keep in mind auto play. And, you know, just certain features like that's a running library of user features to consider. This settlement document gives a whole lot of other feature interactions, engagement, timing, communication, details that I think go into that library of issues. And that when you're if you're product counsel and you're you're working on sanding something up or the next version of something, I think really just we issue spot as lawyers. And we can look around the corner only so much. And so having some of these examples and even if you're not look, you're not the profile of the target here, but you're you're making a household product or you're making a product where there's, you know, a good chance, like teens or a vulnerable population, even like an elderly population might be using. I think there's some really important prompts here that that are helpful to think about. And it doesn't mean they apply to everything, but I think consideration of those go into just really prudent, thoughtful counseling.

Colleen

And tell me if I'm wrong here, but it feels to me like especially with the tools we have at our disposal today, AI tools, we're in an easy place to take something like this and develop a detailed prompt about what you're dealing with and connect the dots to what applies.

Alysa

Right. I mean, you can't just deal with human memory clearly at this point. Like, it's great, and I hope not to be out of a job. But, like, I think to be able to take all of these settlements, the complaints, the allegations, and really have that as a living library where you can get some interrogate and get some insights out because it goes to risk. Right? It goes to how can we mitigate risk? Like understanding certain it's always the totality of the facts. But if there are certain facts that start leaning into one way, to be able to pull out a case example really quickly and be able to look at it and say, Okay, well, how did we mitigate that? You know, what what were the issue facts there that were really bad that were we can address? You know, we can have something slightly different. I think that's an interesting and exciting time, particularly beyond privacy. Right? Consumer I've said this plenty of times, but there's so many consumer protection, just unfair and deceptive trade practice type cases that are so helpful at the core to a lot of the issues we're facing today.

Colleen

Yeah. I know that the Ketch product team was especially excited to see the detail in this order just because, you know, as many may know, if they're regular listeners, one of our recent product updates, the Ketch agent network, which is this multilayer multi agent orchestration layer that goes across the whole platform. One of the biggest areas of data we're ingesting is all the regulations, all the settlements so that when pros are kind of using the agent network and catch and surfacing insights, we're pulling some of these orders and able to say, oh, based on this, your risk tolerance you know, think about this when you decide where you wanna sit. And so to have this kinda, like, detailed meat on the bone from the enforcers is incredibly helpful to triangulating the things.

Alysa

Right. Yeah.

Colleen

What do you think about as I've been perusing the articles online, looking at what people are saying about this, of course, there's articles out there that are saying, is this really good for teens and children? Because now Meta has to collect more data. Now they have to use age assurance technology that flies more in the face of their privacy. Kinda more of the age old, like, you need data to respect it. Right? I mean, what do you think about that kind of criticism of the order?

Alysa

Well, there's always gonna be criticism, period. Right? I don't think we we're ever gonna satisfy everyone. But there's the concept, which you just raised, where in order to verify age or verify identity, you do need to collect certain kinds of information, certainly at the same time when we're in a data minimization strategy. So that has to get taken into account. And I see that baked into the settlement. But I think it raises the larger question for a lot of companies on truly how do you restrict data use? Because there are particular parameters around if you're collecting data, and we see it in the privacy laws too. If you're collecting data for identity verification, it shall only be used for those limited purposes. And that's one thing if it's the privacy compliance team handling the data rights. They can keep it in a silo. But I think some of know, when it's in the business environment, how do you have a data permit perspective where you can enforce it beyond policy, really be able to audit and track limitations of use. And so, you know, we have that in credit. We have that in certain other areas. I think we're just getting more and more buckets of data that you have to really lock down from additional commercial uses and have confidence that's in fact being respected.

Colleen

Yeah. Interesting. Well, as you say, there's so many takeaways for grappling with teen and children's privacy, but also these other issues. I have a feeling or prediction because I'm thinking back to when we hosted privacy state of the union in DC in January of this year. Children's privacy was, like, the thread that came up in every single session, and I'm I wouldn't be surprised if it happens again at the US privacy summit in October. It just seems to be so in the headlines and top of mind for folks.

Alysa

Just squishy area. It's a squishy area, and you know what? It's a lot of people. Under eighteen is a lot more people than under thirteen, and they use the Internet, and they use product, and they buy things. So yeah.

Colleen

Yeah. I think it'll be top of mind. I'm very excited. We folks, we have a dedicated session talking about team privacy and App Store harmonization and these issues on the agenda at summit with a moderator from the App Store side, Google, incredible panelists from companies dealing with this issue. So please check out the agenda. We'll be announcing these specific speakers in a couple weeks and really can't wait to get into it. The the other thing that bring that this settlement brings to mind, of course, is, right, this was a massive undertaking, multiple states, so many attorney general offices involved. I would think this frees up some bandwidth as you've suggested on the AG side for other cases, Alisa. Right? Are we is there

Alysa

That was the first thing I said.

Colleen

Right.

Alysa

The fur like, before I even got into substance, I'm like, gosh. That was a lot of attorneys across this country who were dedicated, who were so focused on this massive matter. What are they gonna do now? Like, they have they have a little bit more time, and yet we have more privacy laws. I think I think more companies may be getting letters.

Colleen

I think so too. Yeah. And in the meantime, they're hiring technologists. They're continuing to receive consumer complaints, so I would think there might be a backlog of things they're hoping to look into. We'll see.

Alysa

Right. Maybe, like, as that takeaway thought, I would just what are those high priority enforcement issues? And, again, just the urge to do a little bit of pressure testing on your own practices, you know, for anybody who's listening to this from a manage your risk.

Colleen

Yeah, folks. We did episode breaking down, like, privacy tabletop exercise. What does that look like? Maybe revisit that. Think about putting yourself in the consumer's shoes and your business and what would that look like today. Yeah. We'll see. Very interesting. Well, Elisa, pleasure chatting with you as always. Anything I've missed? Anything you would leave the audience with on this this very historic and interesting order?

Alysa

Well, we are approaching Labor Day, and I just always think, well, the summer has flown by. This the post Labor Day kind of race sprint to the end of the year, and I anticipate we're gonna see more enforcement actions that we're gonna learn from. So I would just say hydrate, catch your breath, do some fun reading over the weekend, and then, you know, come in bright and fresh to to buckle down and get a whole lot done for the fall.

Colleen

I love it. Good advice as always. Well, Alisa, thank you for joining me. Appreciate it, and we will see you next time.

Next step

See permissioning infrastructure in action

Walk through the platform with a Ketch architect, or launch the free CMP today.

Get Started Free

Get started in less than 5 min