Facebook and the Cambridge Analytica Scandal: Privacy and Personal Data Protections in Canada
Bibliographic record
Abstract
In 2018, the Cambridge Analytica/Facebook scandal made front page news, a data breach that allowed a third-party -Cambridge Analytica -access to the personal data of millions in several countries, including over 600,000 Canadians.The scandal brought to light privacy issues to regulator and in the aftermath, Canada conducted an investigation into this unsanctioned use of data.This thesis explores the details of that scandal and the resulting Canadian investigation by the Standing Committee on Access to Information, Privacy and Ethics (ETHI) and the Office of the Privacy Commissioner (OPC), as well as drawing on information from the 2009 Canadian Internet Policy and Public Interest Clinic (CIPPIC) complaint with the OPC, and the Broadcasting and Telecommunications Legislative Review (BTLR).These public records are used to provide a lens through which to explore topics of privacy and personal data protection in Canada and what they might mean in a social media platform context.This thesis explores the different regulatory mechanisms and makes some recommendations to improve personal data protection and privacy regulations in Canada, including behavioral and structural regulatory solutions that might mitigate similar such scandals in the future.Facebook users, including over 600,000 people in Canada (ETHI, 2018, p. 9).This scandal ignited a flurry of activity by governments around questions of data protection and privacy, resulting in numerous public inquiries to assess how this unsanctioned use of data occurred and to mitigate this from occurring again (Winseck and Puppis, 2019).Many of the inquiries touched on a wide range of issues about social media, not only focusing on the Cambridge Analytica scandal, which resulted in broader investigations about social media in general.The United Kingdom, Canadian parliamentary inquiries, and the International Grand Committee led by the United Kingdom with representatives from 14 countries, however, focused solely on the scandal.These three inquiries provide a very detailed record of what happened, and in this thesis, I refer to these to inform my analysis.Prior to this scandal, governments had expressed concerns about privacy and data protection on social media platforms, 2 but the Cambridge Analytica scandal marked a tipping point in terms of social media regulation.The scandal exemplifies how the very foundation of social media platforms, the data that they collect, aggregate, and employ to provide tailored services to users and options for marketing to advertisers, can be exploited for less than positive and ethical goals (ETHI, 2018, p. vii).This is especially the case with respect to a platform as widely used and well-known as Facebook, which usual platform business model that ended in 2015, where third-party applications were permitted to collect and retain user information.Cambridge Analytica however reused data collected for one purpose in unanticipated ways, beyond what would be the "reasonable expected use" by a third-party application.2 Some examples of growing government attention to social media regulation can be found in the 2009 CIPPIC Complaint with the Office of the
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.006 | 0.017 |
| Meta-epidemiology (narrow) | 0.000 | 0.001 |
| Meta-epidemiology (broad) | 0.000 | 0.001 |
| Bibliometrics | 0.002 | 0.005 |
| Science and technology studies | 0.050 | 0.019 |
| Scholarly communication | 0.020 | 0.003 |
| Open science | 0.002 | 0.005 |
| Research integrity | 0.004 | 0.007 |
| Insufficient payload (model declined to judge) | 0.009 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".