Meta Security and Privacy – Insights for Business Users

As an official reseller of Meta hardware and software, we consider it important to inform business users about how Meta handles privacy, data protection and security within their XR products. On this page, we provide an overview of the key principles and security measures as applied by Meta in, among others, the Meta Quest product line.

Data Protection and Legislation

Meta invests heavily in protecting customer data and offers features that help comply with international laws such as the GDPR. More information can be found in Meta’s official security whitepapers.

Download the Whitepaper

Transparency around Customer Data

Meta makes a clear distinction between customer data (B2B) and consumer data (B2C). Customer data is not sold and is only shared with subprocessors when necessary for service provision and contractually stipulated.

The use of customer data is limited to the agreed purpose and legal basis, as described in processing agreements, product terms, technical whitepapers, and relevant certifications/attestations. Data collected through business Horizon products is not used for advertising purposes or commercial profiling.

Meta publishes periodic transparency reports that provide insight into policy enforcement, government requests, and the protection of intellectual property. It also reports on developments that may limit access to Meta technologies.

  • Data Minimization & Retention Periods: only data necessary for the purpose.
  • Access Control: role-based access and the least-privilege principle.
  • Encryption: encryption during transport and at rest where applicable.
  • Logging & Audit: management and audit capabilities to track access and changes.
  • Rights of Data Subjects: options for data portability and deletion/access requests.

More information about Meta's transparency can be found in the Transparency Center.

Control of External Applications

External applications in the Meta Horizon Store must comply with strict quality and privacy guidelines. Developers are bound by the Meta Platform Terms and the Developer Policy, which include requirements for data processing, security, and transparency. Meta can remove apps or developers that violate these rules.

The Facebook Developers Terms determine how Meta's APIs, SDKs, and data may be used. Developers must handle user information carefully and prevent abuse. More info: https://developers.facebook.com/terms.

The Meta Horizon Policy Rules require that apps are safe, comply with content standards, and undergo a verification process. Non-compliance can lead to app removal. More info: https://developers.meta.com/horizon/policy/.

  • App Review: safety and privacy check
  • Data Security: encryption and access control required
  • Policy Compliance: enforcement through audits and monitoring

Certifications

Meta has various certifications that demonstrate their processes meet international standards for information security and data protection. These certifications are periodically checked by independent auditors.

Certification Issued by Download
ISO/IEC 27001 EY Download PDF
ISO/IEC 27018 Schellman Download PDF
SOC 2 External Audits Not Publicly Available
SOC 3 External Audits Download PDF
GDPR (General Data Protection Regulation) EU Regulation Download Whitepaper
Transparency Report Meta Platforms, Inc. View Report
ISO/IEC 27701 Schellman Available Upon Request

Security Settings, Methods, and Guidelines

Meta offers various layers of security: from settings and technology to strict guidelines for developers and administrators.

Security Settings
Security Settings

From PIN protection and network settings to log files and remote wiping: Meta offers tools to securely manage devices.

Security Methods
Security Methods

Built-in OS protection, encryption, sandboxing, and continuous audits protect the system from attacks.

Meta Guidelines
Meta Guidelines

From physical access control to incident response – Meta has strict guidelines for secure operations.

Valued by Leading Organizations

Meta provides XR solutions to leading companies and institutions worldwide. Customers include:

Customer Logos Meta

Do you have questions about securely deploying Meta Quest devices in your organization? Please contact our team – we are happy to think along with you about the right hardware and software solutions for your situation.

Contact Unbound XR →