Privacy case study report
Table of Contents
Stakeholders directly or indirectly affected in the case
Application of frameworks to interpret conflicts
Explanation of privacy issues and evaluation of safeguards
Introduction
The Cambridge Analytica Facebook Scandal is one of the most intriguing privacy violations that has been perpetrated through social media and data misuse (BBC, 2018). Cambridge Analytics harvested personal data from millions of Facebook users through the personality quiz app. More than 20000 users have installed the application. It had collected data from users and their friends due to Facebook’s permissive API policies. The report will identify all stakeholders directly or indirectly affected in the case. The report will consider the application of different frameworks to interpret conflicts.
Stakeholders directly or indirectly affected in the case
The Cambridge Analytica Facebook Scandal provides illustration of how privacy violations affect a wide network of stakeholders. It has been analysed through the primary and secondary stakeholder framework. The primary stakeholders are those stakeholders who share direct engagement within the organisation or whose interests are immediately affected by its actions. On the other hand, the secondary stakeholders are the individuals who are indirectly affected by the actions of the organisation or who possess an interest in the organisation’s activities without being involved.
Facebook users
In this case, the primary stakeholder group is represented by the Facebook users. This is because the personal data of Facebook users was harvested and processed without proper consent and has been directly affected by the incident. These individuals has provided personal data to the platform under the assumption that it would be utilised within ethical and defined social networking constraints. On the contrary, the extraction and transfer of this data to the third party applications and Cambridge Analytica has transpired without meaningful informed consent. The impact on these stakeholders have been multifaceted. One of the first impacts is the clear violation of informational privacy since users did not provide consent to the extraction or downstream utilisation of their information for political profiling. This is because Facebook took the consent of users in collecting their data from the app, however, it did not inform the users about the usage of their data for political purposes. This resulted in a false sense of control which had undermined the user's autonomy.
Another impact has been highlighted by the manipulative targeting of the users. The psychographic profiling has been implemented by Cambridge Analytica to shape political promotion campaigns which are in alignment with the emotions, attitudes and voting behaviour. This has casted an air of uncertainty about the cognitive autonomy since individuals were influenced without awareness. This has altered democratic participation. In addition to that, the psychological and reputational impact has been immense for the Facebook users. User’s personal preferences and behavioural patterns were exposed. This has been responsible in creating risks of stigma or judgement.
Facebook is another primary stakeholder since they have directly engaged in facilitating the data flow that has enabled the scandal. Facebook is accountable for taking the responsibility for the privacy breach since their platform has the APIs that has allowed the data access to the third party developers for data misuse. One of the major impacts have been the financial losses. This is because Facebook has faced a financial loss of after the regulators have imposed a $ 5billion fine for the Cambridge Analytical Scandal (BBC, 2019). There has been a sharp decline in the market valuation of Facebook after the public exposure of the Cambridge Analytica Scandal since the valuation has dipped by $75 billion. This event has also impacted their corporate image since Facebook has come across increased scrutiny and legal infringement from the regulatory bodies (Cherney, 2018). More than 66% of the users do not trust Facebook after the legal proceedings in the Cambridge Analytica Scandal (Weisbaum, 2018). In addition to that, their operational strategy has also been impacted since their business model which has depended on the data driven advertising has come under ethical and legal evaluation.
Cambridge Analytica
Cambridge poses as a primary stakeholder since it has posed as an entity which has utilised the data for political consulting. This stakeholder is highly responsible for the privacy violation since their business model was established on their competence of collecting and analysing large volumes of personal data to establish insights for targeted political campaigns. The short term impact for Cambridge Analytica was beneficial since the company reaped the financial benefits by leveraging data analytics to other targeted political campaigns strategies. However, the long term impacts were extremely negative since the company faced severe reputational damage, legal investigations across multiple jurisdictions and eventual bankruptcy.
Secondary Stakeholders
Politicians
Politicians that have engaged with Cambridge Analytics has been categorised as the indirect beneficiaries of the data exploitation. However, their relation with the scandal exposed them to ethical scrutiny and reputational risks. The application of targeted political messaging based on the improperly obtained data has raised concern about the fairness and transparency of electoral procedures. This has been responsible in retrograding the public faith in the democratic institutions. One of the major impact is reflected by the potential legal consequences that are faced by the political organisations. The presidential campaigns of politicians such as Donald Trump and Ted Cruz received severe legal backlash from the regulatory bodies such as Federal Trade Commission after their involvement in the Cambridge Analytics scandal (Patrick Svitek, 2018). Another major impact on the political orgarnisation is the reputational risks that are associated with unethical campaigning. More than 50% of the citizens have cited the political campaign as unethical after the exposure of Cambridge Analytics scandal (Emma Graham-Harrison, 2018).
Governments
Goverments is also categorised as the secondary stakeholder in the case. They were affected because they were responsible for upholding data privacy and data protection, however, the scandal exposed gaps in the existing data protection laws. In addition to that they are tasked with responsibility to respond to public outrage and restore trust in digital systems. This has incurred a significant impact on the government in terms of the data regulation. This has compelled the government to bring in the stronger enforcement of the General Data Protection Regulation. In addition to that, the incident has also influenced the government to increase their surveillance and oversight on the social media platforms.
Friends of the affected users
The friends of the users are the secondary stakeholders since they have never interacted with application and still felt the adverse effect of the breach because their data was also collected indirectly. One of the major impact on the friends of the users is the loss of trust on Facebook since they have never provided any form of consent to Facebook in collecting their data.
One of the critical insights from the case is the interconnected nature of impacts. The design decision of Facebook to allow broad API access has triggered the chain reaction which has affected millions of users and several institutions (Sharma, 2018). Individual privacy violations can aggregate into societal risks in instances where the data is subjected to large scale behavioural influence. In addition to that, the scandal demonstrates how the power asymmetry between the users and the corporations has amplified harm. The users has been restricted in their capacity of protecting their data whereas the organisations has possessed advanced capabilities to exploit the data.
Application of frameworks to interpret conflicts
The Contextual Integrity theory emphasises on the efficiency of the information flow in adhering to the context specific norms that govern distribution and appropriateness (Malkin, 2022). This principle of the theory has been violated by the Cambridge Analytica Facebook Scandal. This is because the users on Facebook was able to share personal information with the explicit expectation of the data being used as a facilitator of the interpersonal communication within the social working network context, however, the transfer of this data to the Cambridge Analytica for political profiling represents a significant breach of the Contextual Integrity theory in terms of distribution norms. In addition to that, the information, which was appropriate for the social context was repurposed with an inclination towards economic and political domain without the awarenes or consent. This serves as a definite violation of the contextual integrity theory as the norms which dictates the original context were disregarded.
The framework has been effective in demonstrating the conflict that persists between the transparency and autonomy. The users were not provided with the adequate transparency in terms of the data usage. Therefore, the autonomy was subject to compromise since they could not make informed decisions about their participation. The consent did not align with the contextual expectation of the users, despite of an attempt to procure consent through the application. The theory has suggested that the true transparency must be implemented with the contextual relevance. In the context, the absence of alignment between the actual data practices and actual data practices have resulted in the violation of the trust that have extended beyond the individual harm to affect the legitimacy of the platform.
The conflict that persists between the privacy protection and usability another conflict that is highlighted by the contextual integrity theory (Barth et al., 2016). The ease of use and developer accessibility has been prioritised by Facebook’s design which provides third party applications with the scope of access sensitive user data with minimal restrictions. This approach might have elevated innovation and user experience, however, the approach has undermined the contextual norms that should have restricted data flows. This lapse in privacy protection is driven by the violation of the contextual integrity theory since the theory suggest that usability should not be prioritised over the significance of protecting entrenched informational norms (Sivan-Sevilla & Poudel, 2024).Therefore, it is analysed that the systems should be designed to preserve the integrity of the context and enable functionality when it comes to addressing the conflict between privacy protection and usability.
The contracts based or the right based ethics theory have offered a diverse perspective by focusing on the implicit and explicit agreements that exist between the parties (Inusah
& Gawu, 2021). In the context of digital platform, the users forge a type of social contract with the service providers that allows the sharing of data in the exchange of social platform services such AI picture customisation and social quiz apps. This contract consists of implicit expectations that are based on fairness, transparency and respect for users (Smith et al., 2019). In the context, the Cambridge Analytica scandal, this contract was fundamentally breached.
The ethical grounds of the contract was violated despite of the fact that the Facebook’s terms of service might had technical provisions of permitting certain data sharing practices. The actions of the data being subjected to use in terms of political manipulation was not expected by the users. This serves as a key limitation of possessing solitary dependence on formal consent mechanisms. The contracts based ethics theory implies the importance of far agreements that are based on the mutual understanding instead of carrying out exploitation of the information asymmetries. In this context, Facebook and Cambridge Analytica has carried out such exploitation since they possessed higher degree of knowledge and control over the data practices in comparison to the users. This resulted in the information asymmetry and created an imbalance which undermined the legitimacy of the consent.
The contracts based right theory has demonstrated the conflict between the business interests and ethical responsibility of Facebook. This is because Facebook business model has reflected a significant extent of dependence on data informed advertising which have incentivised extensive sensitive data collection and sharing without evaluating the purpose of the third party application in using the collected data (Cabañas, 2020). In the context of the contractual perspective, the company has the responsibility of upholding the trust that is placed on the Facebook by its users. The decision to prioritise the developer engagement and growth at the cost of data governance has been perceived as a breach of this duty by Facebook in accordance to the theory. Similar instances can be related to Cambridge Analytica since their usage of data has also been deemed as a violation to the implicit contract. This is because it was informed in the consent approval that data would not utliised to cause harm to individuals or society. Therefore, the Contract Theory demonstrate the scandal as a failure of Facebook and Cambrige analytica to strike a balance between business interest and ethical obligations.
The comprehensive theory of privacy has offered a wider perspective by considering privacy as a multidimensional concept that encompasses information control, decisional autonomy and protection from harm. In the aspect of informational domain, the users lost control over their personal data, which was processed and collected without meaningful consent. In terms of decisional perspective, the utilisation of psychographic profiling to target political messages served as an interference to the individual’s capacity of making independent choices. This has raised concerns about manipulation since the targeting strategies had the schematics of exploiting the psychological vulnerabilities. In the domain of the harm based perspective, the societal risks have been elevated by the scandal. This has included the degradation of trust in democratic institution and the amplification of political polarisation. Therefore, Facebook and Cambridge Analytica scandal has compromised all of these dimensions in Facebook and Cambridge Analytica scandal.
This theory has recognised that privacy is characterised by the secrecy of information and the ability of the individual to exercise control on the data usage.
The comprehensive theory has also been beneficial in explaining the conflict between innovation and regulation. The development of novel data informed capabilities that has the capacity of creating business value are characterised by technical innovation (Eriksson
& Heikkilä, 2023). However, these innovations have also been responsible for bringing in threats to autonomy and privacy. In this context, the capacity of Cambridge Analytica in analysing large datasets and generating behavioural insights has represented significant technological progression. However, the absence of proper safeguards has provided a scope in using these capabilities as a means of causing harm by manipulating political opinions of their users. The theory has suggested that innovation must be set with balance mechanism that provide protection from exploitation and assure that technological progress does not come at the cost of fundamental rights. In addition to that, the tension between the collective risk and individual benefit is another conflict that is highlighted by this framework. Some users might have reaped benefits from the personalised services, however, the cumulative effect of data misuse has been termed as detrimental to the society as a whole. The scandal has demonstrated how individual level data practices can scale into a systemic predicament that impacts the integrity of elections and public discourse adversely. Therefore, the theory signifies the need of ethical considerations to address the conflict between collective risk and individual benefit.
The contextual integrity has stated the significance of upholding the informational norms and the perils of context collapse whereas the contracts based ethics has focused on the needs for fairness and mutual understanding in data relationship. In addition to that, the comprehensive theory of privacy sheds light on the problems of autonomy, harm and societal impact. Therefore, the inferences that are drawn from these theories provide an extensive insight about the understanding of these ethical failures in the Facebook and Cambridge Analytica scandal.
The collective inference from these framework also imply that the core ethical problem was the breakdown of trust across multiple dimension in addition to the misuse of data. The users trusted Facebook to offer protection to their data, however Facebook failed to respect their trust by selecting design choices and data governance mechanism that was unable to restrict the access to sensitive data. Cambridge Analytica has exploited the user trust for driving strategic gain which have aggravated the harm further (Schneble et al., 2018). The resulting conflicts between the usability and security, innovation and accountability demonstrate the complication of ethical decision making in digital environments.
Identification of relevant principles in professional codes of ethics and evaluation of mitigations and controls that can address privacy issues
The Facebook and Cambridge Analytica scandal has emerged as a failure of the professional ethical standards in computing and information systems in addition to the corporate governance. The professional bodies in the form of Association for Computing Machinery (ACM), Institute of Electrical and Electronics Engineers (IEEE), Australian Computer Society (ACS) and British Computer Society (BCS) has offered ethical frameworks which directs the responsible conduct in the design, management and deployment of digital systems. The analysis of the case against these codes has helped the identification where ethical obligations had been subjected to violation and the manner in which the appropriate mitigations and controls could address such privacy issues.
The ACM Code of Ethics have emphasised several principles that bear direct relevance to this case. One of the most significant principle is the principle 1.2 of ACM Code of Ethics “obligation to avoid harm” which has included protection of individuals from unauthorised data usage and assuring that the computing systems do not have negative impact on user’s wellbeing (ACM, 2025). In the Cambridge Analytica case, the harm has occurred at both the individual and societal level. The data exploitation without the informed consent has led to the manipulation and loss of autonomy. Another key principle of the ACM is “to respect privacy”. This necessitates the collection of data through the trained professionals and put it to use in a manner that conforms to the user expectations. This principle has been subject to violation in the case of Facebook and Cambridge Analytica scandal since the data which was collected for social networking intentions had been repurposed for political profiling. The ACM has also stressed about the importance of the transparency and honesty which has been missing in the Facebook and Cambridge Analytica scandal since these firms failed to communicate the data usage practices to the users
The Public principle of IEEE Code of Ethics has reiterated the safeguarding public interest by protecting the public data and avoiding the use of deceptive practices (IEEE, 2025). This has signified the professionals to delve into their honesty and state realistic claims on their system capabilities. In the case of Facebook and Cambridge Analytica scandal, the absence of the transparency in terms of data flows and potential for manipulation by targeted political campaigns has demonstrated their inability to respect these standards. The IEEE framework has also highlighted the importance of accountability. This was lacking in the Facebook and Cambridge Analytica case since responsibility was diffused between the Facebook and Cambridge Analytica which led to non-transparency in the instructions of data governance.
The 4.5.2 principle of ACS Code of Ethics has focused on the prioritisation of public interest which requires the professionals to prioritise the well-being of the society at the expense of the solitary personal or organisational gain by preserving the integrity and security of the information of others (Australian Computer Society, 2025). This principle bears significant relevance to the societal impacts such as risks to the democratic processes that are left by the Facebook and Cambridge Analytica scandal. The principle of ACS has also emphasise on drawing alignment with honesty and professional development. The principle has implied that the ethical implications of the works should be evaluated by the professionals before taking actions on data centric processes. This principle has also been violated by developers at Facebookm and Cambridge Analytica since Facebook allowed the large scale data harvesting without considering the ethical implications of data harvesting in the absence of adequate safeguards and Cambrige Analytica has established targeted political campaign without considering the potential ethical risks of data manipulation for politcal and economic gains.
The BCS Code of Conduct has reinforced the principle of “The duty to protect the public interest” (BCS, 2025). The principle states that the privacy should be respected and the systems should be operated responsibly. This principle has been violated in the Facebook and Cambridge Analytica scandal since Facebook failed to operate their API system responsibly by allowing third party applications to access the sensitive user data. In addition to that, the principle has also stated the importance of integrity and has required professionals to take responsibility for their actions and the consequences of their action. In the case of Facebook and Cambridge Analytica scandal, this aspect of the principle has also been violated since they have been lacking in terms of proactive oversight and delayed response to known risks.
Several mitigation and control can be applied across the regulatory, technical and governance dimensions in an attempt to address the privacy issues. The regulatory measures serves the crucial purpose of establishing the minimum standards for data protection. The enforcement of comprehensive framework such as GDPR has been effective since it has demonstrated its prowess of implementing strict legal requirements that include provisions for informed consent and data minimisation. The expansion of the similar regulations at the international level that would assist in the provision of consistent protection for users irrespective of the jurisdictional constraints. The firms must resort to the development of transparent data governance policies. This policies should offer definitive guidelines for data collection, usage and sharing. These policies should also be responsible in explaining the limitation on data usage purposes. In the Facebook and Cambridge Analytica scandal, the lack of strict purpose limitation has allowed the data to be repurposed with intentions that are in direct violation to the user expectations (Ghorashi, et al., 2023). Therefore, the application of the robust policies which are responsible for limiting the secondary use of data would result in the significant reduction of the threats that are associated with the data misuse. The application of design based approaches in the form of privacy by design are critical for integrating the ethical considerations into technological systems. This approach ensures that the system architecture is designed by considering the privacy protection. One such approach is that the API access would be limited by default and its access would necessitate explicit and granular consent for data sharing (Welzel et al., 2025). This multi-fold approach would prevent the large scale extraction of user data. The privacy by design will also include the implementation of user centric functionalities in the form of transparent consent interfaces and real time data usage notifications. This is responsible for enhancing transparency and motivating the users to make informed choices. Data minimisation is an effective control in terms of addressing these issues since it aligns with ethical principles and regulatory requirements. The firms can decrease the probable implications that are incurred by data misuse by collecting only data that are necessary for specific function. In the Facebook and Cambridge Analytica scandal, the excessive data collection and wider access permissions have created opportunities for exploitation. The restriction of data collectin to essential information only would have drastically reduced the scope of the problem.
The application of comprehensive governance practices are essential in ensuring the oversight and accountability (Sari, 2023). The establishment of dedicated data ethics committee within the firm can offer the opportunity of carrying out individual evaluation of data practices that identify potential risk before their occurrence. The frequent privacy impact assessment must be executed for assessing the effectiveness of the new features or collaborations in terms of their impact on the user data. These assessments have enabled proactive risk management and ensure the integration of the ethical considerations into decision making procedures. The cybersecurity models that mitigates the technical and ethical vulnerabilities should also be implemented within the risk management frameworks (Almaayah & Sulaiman, 2024)
. This will involve deployment of strict access control and execution of the regular audits of third party applications. This would also include the monitoring data flows for anomalies. The insufficient tracking by Facebook has allowed data to be transferred and used without detection in Facebook and Cambridge Analytica case. The strengthening of the cybersecurity measures would play a key role in elevating the firm’s capacity of detecting and responding to such activities.
The transparency mechanisms are essential key component of effective mitigation. This could include dashboards that display data sharing activities and allow individuals to revoke permissions with ease.
Explanation of privacy issues and evaluation of safeguards
The Facebook and Cambridge Analytica case has highlighted several core aspects of privacy failure and has offered a transparent explanation on the large scale harm that surfaces from routine data practices (Bareebe, 2022). The most crucial issues that has emerged are lack of informed consent, secondary data misuse, power asymmetry and behavioural manipulation. The evaluation of the safeguard that has higher degree of effectiveness in terms of mitigating the problem has been highlighted. The analysis has been structured in the attempt of demonstrating the ethical reasoning that shares linkage to each issue.
One of the most critical privacy issue in the case is the failure of informed consent (Hu, 2026). Facebook users entered into technical agreement of sharing the data while interacting with the social media platform and third party applications, however, this consent was not informed with absolute transparency. Users were unaware that their information and their friend’s data could be subjected to extraction and utilisation for political profiling. In terms of ethical perspective, this lack of awareness has demonstrated a violation of autonomy since users were deprived of their capacity to make knowledge decisions about their personal information. The problem has arisen from the insufficient consent mechanisms since it has depended on the complex terms and conditions that have obscured the ethical scope in data usage. The most effective safeguard for this issue is characterised by the implementation of user centric and consent architectures. The ethical reasoning that has been developed in terms of autonomy necessitates the consent to be based on explicit, revocable and granular. This provides an indication that the users would have the capacity to understand the type of collected data and the purpose of data usage. This will also play a key role in identifying the stakeholders with whom data is being shared. The application of the layered consent interfaces, which is responsible in illustrating the essential information and allowing users to explore details, can assist in easier comprehension of the complicated user agreement terminologies and prevent in overwhelming the users (Noain-Sánchez, 2016). In addition to that, the consent should be a continuous process instead of a one off activity. This has enabled the individuals to alter the preferences as circumstances change. The prevalence of such measures share alignment with the ethical principles and regulatory expectations which assures that the consent is meaningful instead of being symbolic.
The secondary data misuse has emerged as a critical issue in the Facebook and Cambridge Analytica case (Leong et al., 2022). This is because the information was collected with no malicious intentions, however, it was repurposed to serve unethical and manipulative intentions without user approval. In the context of Facebook and Cambridge Analytica case, the data that had been shared by the user within the social media network was utilised for political targeting. This poses as a complete violation to the contextual expectations and trust. This issue has highlighted the importance of purpose limitation which surfaces as a principle that is key to data protection regulations and ethical frameworks. The prominence of ethical concern is significant since the user expectations on the data usage were undermined and constituted as breach of trust. The data governance policies are essential in this case since it mitigates the issue comprehensively (Panagiotis et al., 2024). The firms must set up transparent boundaries for data usage. It is then followed by the enforcement of the transparent boundaries through technical controls. The data should not be subjected to repurpose with the obtaining of new consent. The prevalence of any form of deviation from the intended purpose must be evaluated with extensive ethical frameworks. The implementation of data tracking and tagging system can assure the usage of information within the authorised contexts. These safeguards will be responsible in preventing misuse and reinforcing accountability since firms can illustrate compliance with legal and ethical standards.
The power asymmetry is another fundamental aspect of the case that have prevailed between the users and firms (Ducuing, 2025). Facebook and Cambridge Analytica possessed extensive knowledge, resources and technical capabilities whereas the users had restricted realisation about the data processing and data usage. The presence of such imbalance has enabled the exploitation of personal information and undermined the fairness of the data ecosystem. The ethical reasoning is grounded on justice and fairness that such symmetries must be addressed with the prevention of exploitation and ensure that individuals are not disadvantaged. The safeguards to mitigate power asymmetry involve the transparency mechanisms and user empowerment tools. The reduction of information gaps can be assisted by the provision of accessible information about data flows, third party access and potential risks to the users (Wachnik et al., 2021). The user dashboards that demonstrate real time data usage and provide the individuals with the scope of controlling permissions are significantly effective in enhancing agency. In addition to that, the independent oversight bodies and regulatory frameworks play a crucial role in balancing power.
Conclusion
The findings of the report indicate that the Facebook and Cambridge Analytica case has been driven by the issues of the absence in informed consent, secondary data misuse, power asymmetry and behavioural manipulation. The outcomes of the report indicate that each of these issues has revealed a different dimension of the privacy problem and has highlighted the importance of targeted safeguards. The evaluation has demonstrated that effective privacy protection requires the combination of user centric, design, strict governance and ethical commitment. The case has illustrated that privacy is a fundamental ethical concern that must be addressed through comprehensive and coordinated efforts.
Reference List
ACM. (2025). ACM Code of Ethics and Professional Conduct. Retrieved from https://www.acm.org/code-of-ethics
Almaayah, M., & Sulaiman, R. B. (2024). Cyber risk management in the internet of things: Frameworks, models, and best practices. STAP Journal of Security Risk Management, 2024(1), 3-23. https://doi.org/10.54517/cte3118
Australian Computer Society. (2025). Australian Computer Society Code of Ethics. Retrieved from https://teaching.csse.uwa.edu.au/units/CITS3200/ethics/acs-ethics.htm
Bareebe, R. (2022). The Cambridge Analytica scandal and its impact on Meta. URL: https://www. researchgate. net/publication/368666866_The_ Cambridge_Analyti ca_Scandal_and_Its_Impact_on_Meta/references (date of access: 04.12. 2024).
Barth, A., Datta, A., Mitchell, J. C., & Nissenbaum, H. (2016, May). Privacy and contextual integrity: Framework and applications. In 2006 IEEE symposium on security and privacy (S&P'06) (pp. 15-pp). IEEE. https://doi.org/10.1109/SP.2006.32
BBC. (2018) Facebook fined £500,000 for Cambridge Analytica scandal. (2018). Retrieved from https://www.bbc.com/news/technology-45976300
BBC. (2019). Facebook “to be fined $5bn over Cambridge Analytica scandal. Retrieved from https://www.bbc.com/news/world-us-canada-48972327
BCS (2O25). CODE OF CONDUCT FOR BCS MEMBERS. Retrieved from https://www.bcs.org/media/2211/bcs-code-of-conduct.pdf
Cabañas, J. G., Cuevas, Á., Arrate, A., & Cuevas, R. (2020). Does Facebook use sensitive data for advertising purposes?. Communications of the ACM, 64(1), 62-69. https://doi.org/10.1145/3426361
Cherney, A (2018). Facebook valuation drops $75 billion in week after Cambridge Analytica scandal Retrieved from https://www.marketwatch.com/story/facebook-valuation-drops-75-billion-in-week-after-cambridge-analytica-scandal-2018-03-23
Ducuing, C. (2025). Data protection without romance: The power asymmetries that the GDPR does counter. Utrecht Law Review, 21(2). https://utrechtlawreview.org/articles/1124/files/68dd0d27e63ea.pdf
Emma Graham-Harrison. G. (2018). Revealed: 50 million Facebook profiles harvested for Cambridge Analytica in major data breach. (2018). Retrieved from https://www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election
Eriksson, T., & Heikkilä, M. (2023). Capabilities for data-driven innovation in B2B industrial companies. Industrial Marketing Management, 111, 158-172. https://doi.org/10.1016/j.indmarman.2023.04.005
Ghorashi, S. R., Zia, T., Bewong, M., & Jiang, Y. (2023). An analytical review of industrial privacy frameworks and regulations for organisational data sharing. Applied Sciences, 13(23), 12727. https://doi.org/10.3390/app132312727?urlappend=%3Futm_source%3Dresearchgate.net%26utm_medium%3Darticle
Hu, M. (2020). Cambridge Analytica’s black box. Big Data & Society, 7(2), 2053951720938091. https://doi.org/10.1177/2053951720938091?urlappend=%3Futm_source%3Dresearchgate.net%26utm_medium%3Darticle
IEEE. (2025) Code of Ethics for Software Engineers. . Retrieved from https://www.computer.org/education/code-of-ethics
Inusah, H., & Gawu, P. S. (2021). The social contract theory and corporation moral obligation. E-LOGOS, 28(1), 4-16. https://doi.org/10.18267/j.e-logos.480
Leong, B., Dan Goldhaber, A. R. G., Stone, B., Gopi Shah Goda, A. S., & Richaa Hoysala, E. M. M. (2022). Why the recent Facebook/Cambridge Analytica data “breach” matters for students. Retrieved from https://www.brookings.edu/articles/why-the-recent-facebook-cambridge-analytica-data-breach-matters-for-students/
Malkin, N. (2022). Contextual integrity, explained: A more usable privacy definition. IEEE Security & Privacy, 21(1), 58-65. https://doi.org/10.1109/MSEC.2022.3201585
Noain-Sánchez, A. (2016). “Privacy by default” and active “informed consent” by layers: Essential measures to protect ICT users’ privacy. Journal of Information, Communication and Ethics in Society, 14(2), 124-138.
Panagiotis, E. K., Stelios, S., Sgantzos, K., & Baratsas, V. (2024) Optimizing Data Governance: Policies and Processes for Data Management in Public Administration and Large Organizations. 6th International Conference on Research in Business, Management and FinanceAt: Barcelona, Spain. https://doi.org/10.33422/6th.icrbmf.2023.09.105
Patrick Svitek, H. S. (2018). Ted Cruz says Cambridge Analytica told his presidential campaign its data use was legal. Retrieved from https://www.texastribune.org/2018/03/20/ted-cruz-campaign-cambridge-analytica/
Sari, R. (2023). Enhancing corporate governance through effective oversight and accountability. Advances: Jurnal Ekonomi & Bisnis, 1(6), 344-356. https://doi.org/10.60079/ajeb.v1i6.291
Schneble, C. O., Elger, B. S., & Shaw, D. (2018). The Cambridge Analytica affair and Internet‐mediated research. The EMBO Reports, 19(8), EMBR201846579. https://doi.org/10.15252/embr.201846579
Sharma, D. (2018). Poor API Design, not Security, was at the core of the Cambridge Analytica scandal. Retrieved from https://www.linkedin.com/pulse/poor-api-design-security-core-cambridge-analytica-scandal-dev-sharma/
Sivan-Sevilla, I., & Poudel, P. (2024). Web Privacy based on Contextual Integrity: Measuring the Collapse of Online Contexts. arXiv preprint arXiv:2412.16246. https://doi.org/10.48550/arXiv.2412.16246
Smith, N. C., Kimmel, A. J., & Klein, J. G. (2009). Social contract theory and the ethics of deception in consumer research. Journal of Consumer Psychology, 19(3), 486-496. https://doi.org/10.2139/ssrn.1336895
Wachnik, B., Pryciński, P., Murawski, J., & Nader, M. (2021). An analysis of the causes and consequences of the information gap in IT projects. The client’s and the supplier’s perspective in Poland. Archives of Transport, 60. https://doi.org/10.5604/01.3001.0015.6932
Welzel, C., Ostermann, M., Smith, H. L., Minssen, T., Kirsten, T., & Gilbert, S. (2025). Enabling secure and self determined health data sharing and consent management. npj Digital Medicine, 8(1), 560. https://doi.org/10.1038/s41746-025-01945-z
Zuckerberg’s apology tour has not done much to regain user trust. (2018). Retrieved from https://www.nbcnews.com/business/consumer/trust-facebook-has-dropped-51-percent-cambridge-analytica-scandal-n867011