Comment from Pate II, William

William Pate IIOpposeIndividual
Summary: The commenter opposes X Corp.'s petition to set aside or modify the 2022 FTC consent order, arguing that the company has not met the legal standards for relief. They contend that the order remains necessary due to X Corp.'s history of data breaches, its merger with xAI, and the fact that the company's core business and data architecture remain unchanged despite the change in ownership.
Here's a clean, copy-pasteable version under 5,000 characters: IN THE MATTER OF TWITTER, INC. — DOCKET NO. C-4316 Comment in Opposition to Petition of X Corp. to Set Aside or Modify Decision and Order I submit this comment in opposition to X Corp.'s petition to set aside or modify the May 2022 consent order. The Commission should deny the petition. A full comment with citations is attached. The legal standard is not met. Section 5(b) requires either changed conditions of fact or law, or a public-interest showing. X Corp. meets neither. On successor liability: The order explicitly binds "successors and assigns." X Corp. is the surviving entity from Twitter's March 2023 merger into X Corp. — a fact the petition itself confirms. A successor cannot extinguish a consent order by pointing to its own successor status. National Comics Publications, the case X Corp. cites, involved successors who had moved into genuinely different business areas. X Corp. does exactly what Twitter did: social media, user data, targeted advertising. The regulated architecture is identical. On Yeh v. Twitter: This is the petition's strongest argument, and it fails for three reasons. First, the California Supreme Court granted review (No. S295210), making the Court of Appeal's opinion non-final and non-precedential. Second, a state court's UCL analysis does not resolve a federal Section 5 deceptiveness claim, which turns on whether the collection context misled consumers at the point of interaction — not whether a complete reading of the privacy policy contained technically accurate language. Third, the FTC itself was party to the underlying factual findings, which were accepted by the Department of Justice and a federal district court. The appropriate challenge was appeal of the consent order, not collateral attack through state private litigation applying different legal standards. On regulatory redundancy: The order provides tools no other regime replicates: direct FTC breach notification, independent assessments approved by the Associate Director for Enforcement, and federal contempt authority. The petition's reliance on GDPR compliance is undermined by the Irish Data Protection Commission's 2024 formal inquiry into X Corp.'s use of user data to train the Grok AI model without adequate consent — evidence that X Corp. does not treat existing regulatory frameworks as self-executing. On the First Amendment: The 2022 Order does not restrict any editorial decision X Corp. makes. It requires privacy program maintenance, audits, data-access controls, and breach notification. Moody v. NetChoice is inapplicable. The remedy for overreaching demand letters is a protective order, which X Corp. pursued — not termination of the underlying decree. On AI competitiveness: In re Rytr set aside an order that banned a specific AI service. This order bans nothing. It imposes process requirements on data handling. The xAI-X merger — creating a combined entity with strong commercial incentives to train AI on user data — makes the order's privacy review requirements more relevant, not less. Using users' contact information, collected under the pretext of account security, to train a commercial AI model is precisely the kind of undisclosed secondary use the order was designed to prevent. On the $16.6 million compliance cost: This equals roughly eleven percent of the $150 million civil penalty X Corp. paid for the underlying violations, and a fraction of a percent of X.AI Holdings Corp.'s post-merger valuation exceeding $100 billion. Compliance costs proportionate to the scale of the violation do not satisfy the Reader's Digest public-interest test. Affirmative grounds for maintaining the order: Two post-acquisition data breaches — 200 million records in 2023 and 2.8 billion profiles in 2025 — affected data categories the order directly covers. Multiple federal courts found that DOGE, directed by X Corp.'s controlling owner, likely violated the Privacy Act by accessing sensitive federal databases without authorization. The DOJ's own 2023 filing in this litigation stated that Musk "exercised granular control of X Corp., at times directing employees in a manner that may have jeopardized data privacy and security." The Commission should not defer to a petition from the same enterprise whose controlling owner's approach to data privacy has generated repeated judicial findings of violations across multiple organizations. The order runs through 2042 because the Commission concluded that a repeat offender required sustained oversight. X Corp. is four years into that period. Nothing in the petition establishes that the concerns underlying that judgment have been resolved. The Commission should deny the petition in its entirety. A full comment with citations and analysis is attached.

View on Regulations.gov