DigitalMANIPULATIVE

Privacy Zuckering

What it is

Tricking people into sharing more about themselves than they intended — through defaults set to public, settings scattered across a maze, upbeat framing of disclosure, and silent changes to what “private” means.

How it works

Brignull coined the term in 2010 after Facebook's December 2009 changes, which reset fields that had been visible to friends so that they were visible to everyone, and pitched the change as giving users more control. The pattern combines several levers. Defaults do the heavy lifting: whatever the setting is at sign-up is what most accounts will keep. Framing casts disclosure as connection (“help friends find you”) and privacy as isolation. The privacy maze — what the EDPB calls it — scatters the relevant controls across many screens so that a full lockdown costs an hour most people will not spend. And the illusion of control works against the user: Brandimarte, Acquisti and Loewenstein found that giving people more control over publishing led them to disclose more, because control over the act displaced attention from what others could then do with the information. The Norwegian Consumer Council's 2018 report Deceived by Design documented Facebook and Google steering users toward the intrusive choice at each step. The FTC's 2011 consent order with Facebook, over telling users information would stay private while it did not, and the 2019 $5 billion order for violating it, mark the legal history of the term's namesake.

Real-world examples

  • Facebook's December 2009 privacy overhaul, which the Electronic Frontier Foundation's timeline of Facebook's privacy policy and Matt McKeon's 2010 visualisation both show shifting default visibility from friends toward everyone; the FTC's 2011 consent order followed.
  • Google's location settings: a 2018 Associated Press investigation found location stored under “Web & App Activity” even when “Location History” was off, which ended in a $391.5 million settlement with 40 US states in 2022.
  • Venmo's default-public transaction feed, through which journalists in 2021 located President Biden's account and contacts in minutes — a default few users knew they had.
  • The Norwegian Consumer Council's 2018 report Deceived by Design: at each step of a settings review, Facebook and Google presented the privacy-intrusive option as the default and the alternative as a loss.

Historical case studies

The FTC's $5 billion Facebook order

2019FTC Enforcement

The Federal Trade Commission found that Facebook had violated a 2012 privacy order by presenting users with settings that suggested they could limit their information to friends while apps used by those friends could still collect it, by asking for phone numbers for account security and then using them for advertising, and by turning on facial recognition by default for tens of millions of users while implying it was opt-in. The $5 billion penalty was the largest ever imposed for a privacy violation, and the order created an independent privacy committee on the company's board.

Source →

Twitter's security phone numbers

2013–2019FTC / DOJ Enforcement

From 2013 to 2019 Twitter asked users for phone numbers and email addresses to secure their accounts, for two-factor authentication and account recovery, and then also used the data to let advertisers match users to their own marketing lists. More than 140 million people supplied the information on the stated security basis. In 2022 the company paid a $150 million civil penalty for violating an earlier FTC order and for misrepresenting its compliance with EU and Swiss privacy frameworks. A request framed as protection had worked as data collection for advertising.

Source →

Ethical guidelines

  • Private by default; sharing is the choice the user makes, not the one they must undo — the GDPR's data-protection-by-default rule (Article 25) says so in law.
  • Put all privacy controls in one place, reachable in two taps, with a plain statement of who can see each item.
  • Never change the visibility of existing content or settings without an explicit, separate choice; a “new privacy experience” that widens exposure is a breach of the earlier promise.
  • Frame both options neutrally: “visible to friends” and “visible to everyone”, not “connect with the world” and “limit your experience”.

How to defend against it

  • Assume every new account is public until you have checked, and do the privacy settings at sign-up rather than “later”; use the platform's “view as public” or “privacy checkup” feature to see what a stranger sees.
  • Set specific known defaults: Venmo transactions to private, Google Web & App Activity and Location History off or auto-deleting, Facebook past posts limited, contact syncing off.
  • When a platform announces a “new privacy experience” or “simplified settings”, treat it as a prompt to re-audit, not as reassurance; screenshot your settings before and after.
  • Use the rights that exist: request your data and its deletion under the GDPR (EU/UK) or the CCPA (California), and opt out of data brokers, who resell what the defaults exposed.
  • Separate identities: an alias e-mail and minimal profile for services you do not need to be found on, so that a default set to public exposes little.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Brignull, H. (2023). Deceptive Patterns: Exposing the Tricks Tech Companies Use to Control You. Testimonium Ltd
    The origin of the term privacy zuckering in the 2010 taxonomy and its definition.
  2. Forbrukerrådet (Norwegian Consumer Council) (2018). Deceived by Design: How Tech Companies Use Dark Patterns to Discourage Us from Exercising Our Rights to Privacy. Forbrukerrådet report, June 2018
    Documentation of defaults, framing, and placement steering Facebook and Google users toward privacy-intrusive settings.
  3. Brandimarte, L., Acquisti, A., & Loewenstein, G. (2013). Misplaced Confidences: Privacy and the Control Paradox. Social Psychological and Personality Science, 4(3), 340-347
    The finding that more control over publishing information increases disclosure — the control paradox that privacy-settings interfaces exploit.
  4. Federal Trade Commission (2011). In the Matter of Facebook, Inc. — Decision and Order. FTC Docket No. C-4365, consent order announced November 2011
    The finding that Facebook told users information would be kept private while making it public, and the resulting order.
Last reviewed
Suggest a correction

Detect Privacy Zuckering in any text

Paste any message, email, or article into our free Manipulation Detector to see if Privacy Zuckering or other techniques are being used on you.

Related Articles