Skip to main content
X Corp. Petitions to Escape FTC Order: What FailedCompliance & Monitoring
5 min readFor Legal and Compliance Teams

X Corp. Petitions to Escape FTC Order: What Failed

When X Corp. filed its petition to set aside the 2022 FTC settlement order on June 2, 2025, it wasn't just seeking regulatory relief. The company argued that the order no longer applies because "every individual responsible for the underlying failures has left the company" and Twitter itself no longer exists as a legal entity. The FTC opened a 30-day public comment period ending July 2, 2026.

This isn't a typical compliance story. It's a test of whether corporate transformation can reset regulatory accountability.

What Happened

In 2022, the FTC imposed a settlement order on Twitter following privacy and security failures. X Corp., the entity that acquired Twitter's operations, now argues the order should be set aside or modified to terminate at the end of 2026. The petition rests on four claims: the original company no longer exists, responsible individuals have departed, X Corp. has built "a world-class privacy and data-protection program," and the order imposes "millions of dollars in needless costs" that duplicate protections already required by other privacy regimes. X Corp. also argues that maintaining the order threatens First Amendment values and American leadership in artificial intelligence.

Timeline

2022: FTC issues settlement order against Twitter for privacy and security violations.

Date unknown: X Corp. acquires Twitter; corporate entity changes.

June 2, 2025: X Corp. files petition to set aside or modify the order.

June 2, 2025: FTC opens public comment period.

July 2, 2026: Comment period closes; FTC will vote on the petition afterward.

Which Controls Failed or Were Missing

The original settlement order addressed failures that X Corp.'s petition doesn't dispute. While the specific violations aren't detailed, settlement orders typically arise from breakdowns in fundamental privacy controls. Based on X Corp.'s defense that it now follows "domestic and international privacy regimes and industry-recognized frameworks," we can infer the original failures involved gaps that standard frameworks would have prevented.

The more interesting failure isn't technical. It's structural: X Corp. is arguing that regulatory accountability should reset when a company changes ownership and personnel. This position reveals a conceptual gap in how the company views compliance obligations. Settlement orders don't attach to individuals or corporate names. They attach to operations and data flows. If you acquire a company's data processing operations, you acquire its compliance obligations.

X Corp.'s claim that the order duplicates existing requirements misunderstands the purpose of consent orders. They exist precisely because baseline requirements weren't sufficient to prevent the original violation. The order likely imposes enhanced monitoring, third-party assessments, or specific architectural controls that go beyond what GDPR Article 32 or CCPA Section 1798.150 would require.

What the Relevant Standard Requires

The FTC Act Section 5 prohibits unfair or deceptive practices. When a company settles an FTC investigation, the resulting order becomes a binding legal requirement separate from any underlying statute. These orders typically remain in force for 20 years and survive corporate restructuring.

For comparison, GDPR Article 83(3) allows supervisory authorities to impose corrective measures that remain in effect regardless of management changes. The UK Data Protection Act Section 149 gives the Information Commissioner's Office similar powers. Canadian PIPEDA Section 11 authorizes the Privacy Commissioner to audit compliance for extended periods following a finding of non-compliance.

The principle is consistent across jurisdictions: regulatory obligations follow the data and the processing operations, not the corporate letterhead or the individuals on the org chart.

X Corp.'s petition also claims the order threatens innovation in artificial intelligence. This argument implies the order restricts data use in ways that baseline privacy laws don't. That's the point. If your company violated trust badly enough to trigger an FTC settlement, you don't get to argue that enhanced scrutiny of your AI training data is an unfair burden. You earned that scrutiny.

Lessons and Action Items for Your Team

Document your compliance posture before M&A. If you're acquiring a company with an active consent order, regulatory obligations transfer with the assets. During due diligence, request copies of all settlement orders, consent decrees, and ongoing supervisory authority engagements. Budget for compliance costs as part of the acquisition price.

Don't assume new management resets the clock. Replacing your privacy team or hiring a new Chief Privacy Officer doesn't satisfy existing regulatory obligations. When you inherit a consent order, treat it as a permanent architectural constraint until the supervisory authority formally releases you.

Map consent order requirements separately from baseline compliance. Your GDPR Article 30 record of processing activities should include a column for enhanced requirements imposed by orders or undertakings. These aren't duplicative. They're additive. If your consent order requires quarterly third-party assessments and GDPR only requires periodic review, you conduct quarterly assessments.

Challenge orders through the proper channels, not through rebranding. If you believe an order is outdated, file a petition with supporting evidence of changed circumstances. Don't argue that corporate restructuring makes the order inapplicable. The FTC has seen that argument before. So has every other supervisory authority.

Track the cost of non-compliance, not the cost of compliance. X Corp. argues the order imposes "millions of dollars in needless costs." Calculate what the original violation cost in terms of user trust, regulatory attention, and reputational damage. Settlement orders are expensive because violations are expensive. If your team is arguing that enhanced monitoring is too costly, you're having the wrong conversation.

The FTC will vote on X Corp.'s petition after the comment period closes. Regardless of the outcome, the petition itself is instructive. It shows what happens when a company treats regulatory accountability as negotiable rather than structural. Your compliance program should assume that every obligation you incur today will follow your data for 20 years, regardless of who owns the company or who runs the privacy team.

If you can't afford enhanced scrutiny, don't violate trust in the first place.

You Might Also Like