Facebook Let Other Companies Read Your Private Messages (Update: Netflix Responds)

Update 1:39 PM ET: We've added an official statement from Netflix.

Facebook is involved in yet another scandal, after revelations that its data-sharing partnerships with numerous companies gave it access to private messages.

Credit: Shutterstock

(Image credit: Shutterstock)

New York Times investigation, drawing from hundreds of pages of internal company documents, has revealed that the social network shared user information with other companies, often in contradiction of its own rules and without the consent of the users themselves. In some cases, companies had access to these data years after it was supposed to have been revoked.

MORE: Facebook's Photo Bug: How to See If You Were Exposed

Although many companies are listed in the piece, it's Netflix and Spotify that have been highlighted as being able to access, and even delete, private messages.

In Netflix's case, this came in the form of a recommendation tool. This tool sent Facebook friends messages, via Messenger or Netflix, and was deactivated in 2015 after a year of operating due to a lack of popularity. Netflix has stated in response:

"Over the years we have tried various ways to make Netflix more social. One example of this was a feature we launched in 2014 that enabled members to recommend TV shows and movies to their Facebook friends via Messenger or Netflix. It was never that popular so we shut the feature down in 2015. At no time did we access people’s private messages on Facebook, or ask for the ability to do so."

Spotify was another company, according to the report, that was able to read, write or delete users' private Facebook Messenger messages and see the identities of those participating within the chat.

According to the NYT, Facebook's director of privacy and public policy, Steve Satterfield, said that all of these partnerships are within the rules, both of user privacy and the 2011 agreement with the U.S. Federal Trade Commission about only sharing user data with users' permission.

Satterfield also said that Facebook had made errors in its handling of these partnerships, which allowed continued use of data after the formal agreements had ended, and that it was currently working to terminate many of them.

MORE: How to Stop Facebook From Sharing Your Data

A separate statement said that Facebook had found no evidence of abuse of data by any of its partners. It also published a blog post, explaining the functions of the partnerships, and repeating that none of its actions were against the FTC settlement or in violation of user agreements, and that many of these had been shut down.

The company also noted that "our integration partners had to get authorization from people. You would have had to sign in with your Facebook account to use the integration offered by Apple, Amazon or another integration partner". In other words, if you'd signed into Spotify via your Facebook account — as Spotify required when it first was launched in the United States — Facebook believed you had implicitly consented to Spotify's reading your messages.

It's been a rough year for Facebook, to say the least. While the Cambridge Analytica scandal was the first and largest wake-up call to the platform's billions of users regarding possibly abuses of private information, other transgressions have continued to surface. Most recently, the company itself announced that a bug in its photo API had inadvertently exposed the private (non-timeline) photos of 6.8 million users.

TOPICS
Richard Priday
Assistant Phones Editor

Richard is based in London, covering news, reviews and how-tos for phones, tablets, gaming, and whatever else people need advice on. Following on from his MA in Magazine Journalism at the University of Sheffield, he's also written for WIRED U.K., The Register and Creative Bloq. When not at work, he's likely thinking about how to brew the perfect cup of specialty coffee.

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 22 (#650)
  • Dark Lord of Tech
    Of course they do FACEBOOK is DARPA...A government data collection tool , opened after LIFE LOG failed and was closed down. Settings don't matter.
    Reply