Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCambridge Analytica was a privacy scandal, but privacy was only the entry point. The documented case also involved inferred personality and political profiles, weak oversight of a platform’s developer ecosystem, questions about platform power and competition, and political advertising that could be difficult for the public to inspect. Official findings establish data harvesting, voter profiling and targeted messaging; they do not establish that Cambridge Analytica determined the result of an election.
What data was collected, and how?
Facebook’s earlier Graph API allowed a third-party app to obtain information about the person using it and, under the model then in place, information about that person’s Facebook friends after authorization. In its 2018 investigation, the UK Information Commissioner’s Office (ICO) concluded that Facebook had not taken sufficient steps to stop apps collecting data in ways that breached data-protection law. The ICO also reviewed evidence that Cambridge Analytica wanted to use pre-existing app access to friend data to build models for US electoral campaigns. The ICO’s report to Parliament is the primary account of that finding.
The app at the centre of the story was called “This Is Your Digital Life.” The ICO’s public account says information collected through the app was shared with political campaigners. That made the exposure broader than the people who deliberately installed an app: the older access model could bring friends’ information into the dataset as well.
“You aren’t necessarily aware that when you tell me what music you listen to or what TV shows you watch, you are telling me some of your deepest and most personal attributes.”
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.#1 Best Overall
Notary Privacy Guard Suitable for Journal of Notarial Events
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notaries Public' confidential information
- GLBA and HIPAA require strict confidentiality policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
Christopher Wylie, quoted by the ICO from Campaign Magazine, February 2018
What the FTC found Cambridge Analytica did
In a 2019 opinion and final order, the US Federal Trade Commission (FTC) found that Cambridge Analytica used deceptive practices to harvest personal information from tens of millions of Facebook users for voter profiling and targeting. That wording is the FTC’s finding, not an independent estimate that should be detached from its source. The FTC’s announcement says the app collected Facebook User IDs even though users were told that their names and other identifying information would not be collected.
The FTC also found deceptive representations about Cambridge Analytica’s participation in the EU–US Privacy Shield framework. The company had filed for bankruptcy in 2018 and did not respond to the FTC complaint or motion for summary judgment, but the commission still issued an opinion and final order.
The order prohibited the company from misrepresenting how it protected personal information or its Privacy Shield participation. It also required protections or deletion for covered data, including personal information collected through the GSRApp. Those are the legal requirements in that FTC order; they are not a finding that the firm changed an election result.
Free tools Windows power users keep installed
One-click scans. No signup required.
How microtargeted political advertising worked
Microtargeting is best understood as a chain from raw signals to a narrowly delivered message:
- Collection: an app and associated data access supplied information about users and, under the old Facebook model, their friends.
- Modelling: analysts combined available information into profiles or predictions about people’s characteristics, interests or political behaviour.
- Segmentation: campaigns could divide an electorate into small groups rather than address everyone with one public message.
- Delivery: an advert could be shown to a selected audience, making the message and the size of the audience harder for outsiders to see.
The ICO describes the broader campaign context as detailed pictures of online lives being used to target small groups of voters with specific advertisements. The official record therefore supports the existence of profiling and targeted messaging, while leaving the effectiveness of any particular advert a separate question.
The ICO report discusses an academic claim that as few as 68 Facebook “likes” could predict characteristics and traits including ethnicity and political affiliation. This is a reported claim by academics, not a guarantee that 68 likes will accurately identify every person or that Cambridge Analytica’s models made such predictions reliably.
Why the affair goes beyond individual privacy
Inferences can be sensitive even when they were never disclosed
A person may knowingly provide a “like” or answer an app question without stating a political affiliation, ethnicity or psychological trait. A model can nevertheless infer an attribute from patterns across many data points. The House of Commons Digital, Culture, Media and Sport (DCMS) Committee supported considering legal protections for inferred data and the models used to make inferences about individuals. The committee’s point was a policy concern: power and potential harm can arise from the profile produced from data, not only from the original information a person typed.
Rank #3
That does not mean every inference is accurate. An inferred label can be wrong, outdated or applied to someone who never consented to being assessed in that way.
Platform governance determined what developers could do
The privacy failure was also a governance failure. Facebook set the rules and technical permissions for third-party applications, yet the ICO concluded that it did not do enough to prevent unlawful collection. The question is therefore not only whether an individual clicked “authorize,” but whether the platform verified what an app would collect, monitored downstream use and protected people who had not authorised the app at all.
Elizabeth Denham, the Information Commissioner, explained the historical enforcement in testimony recorded by the committee:
“We fined Facebook because it allowed applications and application developers to harvest the personal information of its customers who had not given their informed consent—think of friends, and friends of friends—and then Facebook failed to keep the information safe.”
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Elizabeth Denham, as quoted in the House of Commons DCMS Committee report
Data practices raised competition and platform-power questions
The DCMS Committee treated the affair as a platform-power issue as well as a privacy issue. A platform that controls access to large social graphs, the advertising market and the rules for developers can influence who gets data, who can buy attention and what the public can observe. The committee’s report links those data practices to competition concerns; it did not reduce the problem to a consumer’s individual choice.
Political advertising was difficult to audit
Online microtargeting can make a political message visible only to a selected slice of voters. That weakens the traditional public record in which journalists, opponents and voters can inspect the same advertisement. The DCMS Committee recommended rules requiring clear identification of the source and sponsor of paid political advertising, plus a searchable public repository showing who paid, which organisations sponsored an advert and whom it targeted. These were parliamentary recommendations, not proof that every proposal became law.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What regulators and Parliament actually did
The actions below have different legal statuses. A regulator’s finding, a parliamentary conclusion and a proposed reform should not be treated as interchangeable.
| Actor and date | Action or conclusion | What it establishes |
|---|---|---|
| ICO investigation, 2018 | Found Facebook had not taken sufficient steps to prevent apps from collecting data contrary to data-protection law; examined Cambridge Analytica’s intended use of app-derived friend data. | A regulatory finding about Facebook’s safeguards and the data-analytics context. |
| ICO penalty reported by the DCMS Committee, 25 October 2018 | £500,000 fine against Facebook under the UK Data Protection Act 1998, the previous law; the committee described it as the maximum penalty then available. | A historical enforcement action, not today’s penalty limit or a final statement about later proceedings. |
| ICO action involving Professor David Carroll | An enforcement notice required Cambridge Analytica to respond to a subject-access request; the company’s failure to comply led to a prosecution. The committee said the ICO found serious breaches and would have issued a substantial fine had the company not been in administration. | The committee’s account of specific enforcement steps and their legal context. |
| FTC opinion and final order, 2019 | Found deceptive practices involving Facebook data and Privacy Shield representations; prohibited further misrepresentations and required protection or deletion of covered information. | A US consumer-protection finding and order concerning Cambridge Analytica’s conduct. |
The committee’s account of the ICO penalty and related actions appears in its 2019 final report. The ICO’s retrospective also describes the app and the campaign context in “Cambridge Analytica raids”.
Best Value
What the evidence does—and does not—show
- Established: app-mediated access exposed information about users and friends; regulators found deceptive harvesting and voter profiling; and official accounts describe targeted political messaging.
- Not established by these sources: that Cambridge Analytica determined the outcome of an election, “won” one, or caused a measurable change in voting results.
- Not established here: that the committee’s proposed advertising repository or other reforms were implemented everywhere, or that current platforms now operate in a particular way.
Keeping those boundaries matters. Saying “the data was used for profiling and targeting” is supported by the FTC and ICO records. Saying “the profiling changed the election” would add a causal conclusion those sources do not prove.
A better way to assess similar data scandals
The Cambridge Analytica case provides four questions that separate the issues instead of collapsing them into the word “privacy”:
- Consent and data protection: What did people agree to, whose information was collected, and were the disclosures accurate?
- Platform responsibility: Did the platform control developer access, verify downstream use and secure information belonging to non-users?
- Competition and power: Who controls the data, advertising access and technical rules, and can meaningful rivals or oversight bodies challenge that control?
- Political-ad transparency: Can the public identify who paid, which organisation sponsored a message and which audience received it?
Those questions explain why the affair remains bigger than a single unauthorised database. It connected personal information to prediction, prediction to political persuasion, and both to the governance of a powerful communications platform.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




