Articles & Research

Timeline

Cambridge Analytica and GDPR: 2018's reckoning on personal data

The Cambridge Analytica scandal broke weeks before the EU's GDPR took effect, crystallising a global debate over how personal data should be governed.

Priya Chandrasekaran

Head of Public Policy, American Computer Society

May 2018 · 7 min read

The United States Capitol dome at golden hour
The United States Capitol dome at golden hour

In March 2018, reporting revealed that Cambridge Analytica had harvested the data of tens of millions of Facebook users without proper consent. Two months later the EU's General Data Protection Regulation came into force. Together they marked a turning point in how the profession thinks about data stewardship.

A data-harvesting scandal goes public

In mid-March 2018, The Guardian, The New York Times and Britain's Channel 4 reported that Cambridge Analytica, a political consultancy, had obtained data from as many as 87 million Facebook profiles via a personality-quiz app built by academic researcher Aleksandr Kogan. The data had been collected years earlier under Facebook's then-permissive API rules, which allowed apps to pull data on users' friends without those friends' direct consent.

The revelations triggered a public reckoning, including testimony from Facebook chief executive Mark Zuckerberg before the US Congress in April 2018 and before the European Parliament shortly after.

“Data collected legally under a platform's own rules could still be a profound ethical failure.”

GDPR takes effect

On 25 May 2018 the European Union's General Data Protection Regulation came into force, replacing the 1995 Data Protection Directive. GDPR imposed strict requirements on consent, data minimisation, breach notification and the right to erasure, with fines of up to 4 percent of global annual turnover for serious violations.

Although GDPR had been adopted in 2016, giving companies a two-year transition period, its effective date landed amid the Cambridge Analytica fallout, giving regulators and the public a vivid real-world example of exactly the kind of data misuse the regulation was designed to prevent.

The combination accelerated data-protection legislation elsewhere, including California's Consumer Privacy Act, signed in June 2018 and effective in 2020, and prompted major platforms to overhaul consent and data-access practices well beyond the EU.

A professional reckoning, not just a legal one

For technologists the episode was uncomfortable because the underlying data collection had been technically permitted by Facebook's platform rules at the time. The scandal illustrated that lawful use of an API is not the same as ethical use of personal data, and that engineers who build data pipelines share responsibility for how that data can be repurposed downstream.

The Society's position

The Society regards 2018 as the year data ethics became a mainstream professional concern rather than a niche compliance topic.

  • Build privacy-by-design and data minimisation into system architecture from the outset, not as a retrofit.
  • Treat platform terms of service as a floor, not a ceiling, for ethical data use.
  • Support strong, enforceable data-protection regulation, including comparable US federal privacy legislation.
  • Ensure engineers understand their personal accountability when designing systems that process personal data at scale.
Public policyCybersecurityArtificial intelligence

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member