Case study answers
Possible Responses (Case Study - Facebook and Cambridge Analytica)
3 slides · 1 min read · Domain 2
Possible Responses (Case Study: Facebook and Cambridge Analytica)
1. How could Facebook have better managed the requirements related to third-party apps, such as to prevent unauthorized access to user data?
- Facebook could have implemented stricter vetting processes for third-party apps, ensuring they adhere to data protection standards and ethical use of acquired information. Regular audits and evaluations of app compliance could have been established to verify ongoing adherence to requirements.
2. What data security restrictions could have been put in place to limit the extent of data accessed by third-party apps on Facebook's platform?
- Facebook could have enforced the principle of least privilege, restricting the types and volume of user data accessible to third-party apps. Implementing granular controls and employing advanced permission models would have helped minimize the risk of unauthorized access.
3. In what ways did Facebook fail to adequately safeguard user privacy during the Cambridge Analytica incident?
- Facebook fell short in ensuring user privacy by not effectively monitoring and controlling how user data was handled by third-party apps. Enhanced transparency about data usage and implementing mechanisms for users to have better control over their privacy settings could have mitigated the risks.
4. How could Facebook have improved its practices regarding the retention, categorization, and possession of user data to prevent misuse by third-party entities?
- Facebook should have implemented rigorous data life cycle management policies, including defined retention periods and secure deletion mechanisms. Additionally, categorizing data based on sensitivity and clearly defining ownership and permissible uses would have added layers of protection against potential misuse by third parties.
