FULLTEXT DEL 3 AV 3

10-Q – 2025-10-30 – meta-20250930.htm

Föregående del · Dokumentindex

We are engaged in ongoing privacy compliance and oversight efforts, including in connection with our modified consent order with the FTC, requirements of the GDPR and UK GDPR, and other current and anticipated regulatory and legislative requirements around the world, such as U.S. state privacy laws, youth social media laws, the ePrivacy Directive, DMA, DSA, OSA, EU AI Act, the Korean Personal Information Protection Act, and the Indian Digital Personal Data Protection Act. In particular, we are maintaining a comprehensive privacy program in connection with the FTC consent order that includes substantial management and board of directors oversight, stringent operational requirements and reporting obligations, prohibitions against making misrepresentations relating to user data, a process to regularly certify our compliance with the privacy program to the FTC, and regular assessments of our privacy program by an independent third-party assessor, which has been and will continue to be challenging and costly to maintain and enhance. These compliance and oversight efforts are increasing demand on our systems and resources, and require significant new and ongoing investments, including investments in compliance processes, personnel, and technical infrastructure. We continually reallocate resources internally to assist with these efforts, and this has had, and will continue to have, an adverse impact on our other business initiatives. In addition, these efforts require substantial modifications to our business practices and make some practices such as product and ads development more difficult, time-consuming, and costly. As a result, we believe our ability to develop and launch new features, products, and services in a timely manner has been and will continue to be adversely affected. Further, our privacy compliance and oversight efforts have required, and we expect will continue to require, significant time and attention from our management and board of directors. The requirements of the FTC consent order and other privacy-related laws and regulations are complex and apply broadly to our business, and from time to time we notify relevant authorities of instances where we are not in full compliance with these requirements or otherwise discover privacy issues, and we expect to continue to do so as any such issues arise in the future. In addition, regulatory and legislative privacy requirements are constantly evolving and can be subject to significant change and uncertain interpretation. For example, we are subject to restrictions and requirements under the DMA, including in areas such as the combination of data across services and product design, which will likely be subject to further interpretation and regulatory engagement.

The FTC initiated an administrative proceeding against us alleging, among other things, deficient compliance with the FTC consent order and seeking substantial modifications to the requirements of the consent order, including a prohibition on our use of minors' data for any commercial purposes, changes to the composition of our board of directors, and significant limitations on our ability to modify and launch new products. We are challenging the FTC's administrative proceeding. If the
86

Table of Contents

challenge is unsuccessful and the FTC is able to impose the proposed order in its current form, it would limit our ability to provide certain features and services, engage in certain business practices, require us to further increase the time, resources, and costs we spend on compliance and oversight efforts, and would adversely affect our business and financial results.

If we are unable to successfully implement and comply with the mandates of the FTC consent order (including any future modifications to the order), GDPR and UK GDPR, U.S. state privacy laws, youth social media laws, ePrivacy Directive, DMA, DSA, or other regulatory or legislative requirements, or if any relevant authority believes that we are in violation of the consent order or other applicable requirements, we may be subject to regulatory or governmental investigations or lawsuits, which may result in significant monetary fines or damages (including for loss of control of data without other damage), judgments, penalties, or other remedies, and we may also be required to make additional changes to our business practices. Any of these events could have a material adverse effect on our business, reputation, and financial results.
We may incur liability as a result of information retrieved from or transmitted over the internet or published using our products or as a result of claims related to our products, and legislation regulating content on our platform may require us to change our products or business practices and may adversely affect our business and financial results.

We have faced, currently face, and will continue to face claims and government and regulatory inquiries relating to information or content that is published or made available on our products, including claims, inquiries, and investigations relating to our policies, algorithms, and enforcement decisions with respect to such information or content. In particular, the nature of our business exposes us to claims and inquiries related to defamation, dissemination of misinformation or news hoaxes, deceptive and fraudulent advertising, sanctions, discrimination, harassment, intellectual property rights, rights of publicity and privacy, personal injury torts, laws regulating hate speech or other types of content, on- or offline safety and well-being (such as acts of violence, terrorism, improper promotion or distribution of pharmaceuticals and illicit drugs, human exploitation, child exploitation, illegal gaming, and other fraudulent or otherwise illegal activity), products liability, consumer protection, and breach of contract, among others. For example, over the last several years we have seen an increase in claims brought by or on behalf of younger users, including claims related to well-being issues based on allegedly harmful content that is shared on or recommended by our products. In addition, we have been subject to litigation alleging that our ad targeting and delivery practices constitute violations of anti-discrimination laws.

The potential risks relating to any of the foregoing types of claims are currently enhanced in certain jurisdictions outside the United States where our protection from liability for third-party actions may be unclear or where we may be less protected under local laws than we are in the United States. For example, in April 2019, the European Union passed a directive (the European Copyright Directive) expanding online platform liability for copyright infringement and regulating certain uses of news content online, which the EU member states have since implemented into their national laws. In addition, the European Union revised the European Audiovisual Media Service Directive to apply to online video-sharing platforms, which member states are implementing. Additionally, in June 2025, the Brazilian Supreme Court partially invalidated the country's intermediary liability framework, which previously limited platform responsibility for third-party content. The new court-established liability framework requires platforms to remove unlawful content upon private notice and to implement adequate measures to prevent and remove illegal ads and content related to certain crimes under local law, resulting in civil liability in case of non-compliance. As a result, we anticipate making product and operational changes to our content reporting processes in Brazil and may face increased litigation and/or regulatory enforcement. In the United States, in 2023, the U.S. Supreme Court heard oral argument in a matter in which the scope of the protections available to online platforms under Section 230 of the Communications Decency Act (Section 230) was at issue, but it ultimately declined to address Section 230 in its decision. There also have been, and continue to be, various other litigation concerning, and state and federal legislative and executive efforts to remove or restrict, the scope of the protections under Section 230, as well as to impose new obligations on online platforms with respect to commerce listings, user access and content, including electoral-related and AI-generated content, counterfeit goods and copyright-infringing material, and our current protections from liability for third-party content in the United States could decrease or change. We could incur significant costs investigating and defending such claims and, if we are found liable, significant damages.

We could also face fines, orders restricting or blocking our services in particular geographies, or other judicial or government-imposed remedies as a result of content hosted on our services. For example, legislation in Germany and India has resulted, and may result in the future, in the imposition of fines or other penalties for failure to comply with certain content removal, law enforcement cooperation, and disclosure obligations. Numerous other countries in Europe, the Middle East, Asia-Pacific, and Latin America are considering or have implemented similar legislation imposing liability or potentially significant penalties, including fines, service throttling, or advertising bans, for failure to remove certain types of
87

Table of Contents

content or follow certain processes. For example, we have been subject to fines and may in the future be subject to other penalties in connection with social media legislation in Turkey, and we have been subject to fines and service blocking and prohibition in Russia. Content-related legislation also has required us, and may require us in the future, to change our products or business practices, increase our costs, or otherwise impact our operations or our ability to provide services in certain geographies. For example, the European Copyright Directive requires certain online services to obtain authorizations for copyrighted content or to implement measures to prevent the availability of that content, which may require us to make substantial investments in compliance processes. Member states' laws implementing the European Copyright Directive may also require online platforms to pay for content. In addition, our products and services are subject to restrictions and requirements, and we are subject to increased compliance costs, and potential fines or other penalties in the event of non-compliance, as a result of the Digital Services Act in the European Union, which started to apply to our business as of August 2023, and other content-related legislative developments such as the Online Safety and Media Regulation Act in Ireland and the Online Safety Act in the United Kingdom. Certain countries and U.S. states have also implemented or proposed legislation that may require us to pay publishers for certain news content shared on our products. For example, as a result of such legislation in Canada, we have ended the availability of news content for Canadian users on Facebook and Instagram. In the United States, changes to the protections available under Section 230 or the First Amendment to the U.S. Constitution or new state or federal content-related legislation or investigations may increase our costs or require significant changes to our products, business practices, or operations, which could adversely affect user growth and engagement.

Any of the foregoing events could adversely affect our business and financial results.
Payment-related activities may subject us to additional regulatory requirements, regulatory actions, and other risks that could be costly and difficult to comply with or that could harm our business.

Several of our products offer Payments functionality, including enabling our users to purchase tangible, virtual, and digital goods from merchants and developers that offer applications using our Payments infrastructure, send money to other users, and make donations to certain charitable organizations, among other activities. We are subject to a variety of laws and regulations in the United States, Europe, and elsewhere, including those governing anti-money laundering and counter-terrorist financing, money transmission, stored value, gift cards and other prepaid access instruments, electronic funds transfer, virtual currency, consumer protection, charitable fundraising, economic sanctions, and import and export restrictions. In addition, we could become subject to new consumer protection laws and regulations that may be adopted or amended, including those related to payments activity as well as sharing, collection, and use of payments-related data. Depending on how our Payments products evolve, we may also be subject to other laws and regulations including those governing gambling, banking, and lending. In some jurisdictions, the application or interpretation of these laws and regulations is not clear. We have received certain payments licenses in the United States and other jurisdictions for our regulated Payments-related products and activities. These licenses increase flexibility in how our use of Payments may evolve, help mitigate regulatory uncertainty, and will generally require us to demonstrate compliance with many domestic and foreign laws in relation to our licensed Payments products and activities. Our efforts to comply with these laws and regulations could be costly and result in diversion of management time and attention and may still not guarantee compliance. In the event that we are found to be in violation of any such legal or regulatory requirements, we may be subject to monetary fines or other penalties such as a cease and desist order, or we may be required to make product changes, any of which could have an adverse effect on our business and financial results.

In addition, we are subject to a variety of additional risks as a result of Payments transactions, including: increased costs and diversion of management time and attention and other resources to address bad transactions or customer disputes; potential fraudulent or otherwise illegal activity by users, developers, employees, or third parties; restrictions on the investment of consumer funds used to transact Payments; and additional disclosure and reporting requirements. We have also launched payments functionality on certain of our applications and may in the future undertake additional payments initiatives, including as part of our metaverse efforts, which may subject us to many of the foregoing risks and additional licensing requirements.

Risks Related to Data, Security, Platform Integrity, and Intellectual Property

Security breaches, improper access to or disclosure of our data or user data, other hacking and phishing attacks on our systems, or other cyber incidents could harm our reputation and adversely affect our business.

Our industry is prone to cyber-attacks by parties seeking unauthorized access to our data or users' data or to disrupt our ability to provide service or otherwise harm us. Our products and services involve the collection, storage, processing, and
88

Table of Contents

transmission of a large amount of data. Any failure to prevent or mitigate security breaches and improper access to or disclosure of our data or user data, including personal information, content, or payment information from users, or information from marketers, could result in the loss, modification, disclosure, destruction, or other misuse of such data, which could harm our business and reputation and diminish our competitive position. In addition, computer malware, viruses, social engineering (such as spear phishing attacks), scraping, and general hacking continue to be prevalent in our industry, have occurred on our systems, and will occur on our systems in the future. We also regularly encounter attempts to create false or undesirable user accounts, purchase ads, or take other actions on our platform for purposes such as spamming, spreading misinformation, or other illegal, illicit, or otherwise objectionable ends. As a result of our prominence, the size of our user base, the types and volume of personal data and content on our systems, and the evolving nature of our products and services (including our efforts involving new and emerging technologies), we believe that we are a particularly attractive target for such breaches and attacks, including from nation states and highly sophisticated, state-sponsored, or otherwise well-funded actors, and we experience heightened risk from time to time as a result of geopolitical events. Our efforts to address undesirable activity on our platform also increase the risk of retaliatory attacks. Such breaches and attacks may cause interruptions to the services we provide, degrade the user experience or otherwise adversely affect users, cause users or marketers to lose confidence and trust in our products, impair our internal systems, or result in financial harm to us. Our efforts to protect our company data or the information we receive, and to prevent or disable undesirable activities on our platform, may also be unsuccessful due to software bugs, misconfigurations, vulnerabilities, or other technical malfunctions; employee, contractor, or vendor error or malfeasance; social engineering or other cyber-attacks directed towards our personnel or their access; misuse of company data or systems by our personnel; defects or vulnerabilities in our vendors' information technology systems or offerings; government exploitation or surveillance; breaches of physical security of our facilities, technical infrastructure, or other equipment; or other threats that evolve. In addition, other parties may attempt to fraudulently or maliciously induce employees, contractors, vendors, or users to disclose information in order to gain access to our data or our users' data. Our AI initiatives and other efforts to develop and launch new features, products, and services in a timely manner may introduce additional risks and vulnerabilities that are not fully mitigated. Cyber-attacks continue to evolve in sophistication and volume, and inherently may be difficult to detect for long periods of time. Although we have developed systems and processes that are designed to protect our data and user data, to reduce the risk of data loss or misuse, to disable undesirable accounts and activities on our platform, and to reduce the risk of or detect security breaches, such measures will not provide absolute security, and we cannot assure you that we will be able to react in a timely manner to any cyber-attacks or other security incidents, or that our remediation efforts will be successful. Our business and operations span numerous geographies around the world and involve thousands of employees, contractors, vendors, developers, partners, and other third parties. At any given time, we face known and unknown cybersecurity risks and threats that are not fully mitigated, and we discover vulnerabilities in our security efforts.

In addition, some of our developers or other partners, such as those that help us measure the effectiveness of ads, may receive or store information provided by us or by our users through mobile or web applications integrated with our products. We provide limited information to such third parties based on the scope of services provided to us. However, if these third parties or developers fail to adopt or adhere to adequate data security practices, or in the event of a breach of their networks, our data or our users' data may be improperly accessed, used, or disclosed.

We regularly experience such cyber-attacks and other security incidents of varying degrees, and we incur significant costs in protecting against or remediating such incidents. In addition, we are subject to a variety of laws and regulations in the United States and abroad relating to cybersecurity and data protection, including the GDPR and EU member state laws implementing the EU Cybersecurity Directive (NIS2), as well as obligations under our modified consent order with the FTC. As a result, government authorities, affected users, or other parties could initiate legal or regulatory actions against us in connection with any actual or perceived security breaches, improper access to or disclosure of data, or other cybersecurity issues, which has occurred in the past and which could cause us to incur significant expense and liability or result in orders or consent decrees forcing us to modify our business practices. Such incidents or our efforts to remediate such incidents may also result in a decline in our active user base or engagement levels. Any of these events could have a material and adverse effect on our business, reputation, or financial results.
Intentional misuse of our services and user data and other undesirable activity by third parties on our platform could adversely affect our business.

We have experienced, and expect to continue to experience, intentional misuse of our services and user data by third parties, as well as other undesirable, illicit, or high-risk activity on our platform. We are making significant investments in privacy, safety, security, and content and advertising review efforts to combat these activities, including investigations and audits of platform applications, as well as other enforcement efforts. We have discovered and announced, and anticipate that
89

Table of Contents

we will continue to discover and announce, additional incidents of misuse of user data or other undesirable or illicit activity by third parties or malfeasant internal actors. We will not discover all such incidents or activity, whether as a result of our data or technical limitations, including our lack of visibility over our encrypted services, the scale of activity on our platform, the allocation of resources to other projects, or other factors, and we may be notified of such incidents or activity by the independent privacy assessor required under our modified consent order with the FTC, government authorities, the media, or other third parties.

Such incidents and activities include the use of user data or our systems in a manner inconsistent with our terms, contracts or policies, the existence of hacked, false or undesirable user accounts, election interference, improper advertising practices, activities that threaten people's safety or well-being on- or offline (such as acts of violence, terrorism, improper promotion or distribution of pharmaceuticals and illicit drugs, human exploitation, child exploitation, and illegal gaming), instances of spamming, surveillance, scraping, data harvesting, unsecured datasets, or spreading misinformation, or other fraudulent or otherwise illegal activity. From time to time we are unsuccessful in our efforts to enforce our policies or otherwise prevent or remediate any such incidents. We may also be subject to increased risk as a result of changes to our content policies and enforcement efforts which we began to implement in January 2025 to further free expression on our platform and mitigate over-enforcement of certain of our content policies.

Consequences of any of the foregoing developments include negative effects on user trust and engagement, harm to our reputation and brands, changes to our business practices in a manner adverse to our business, and adverse effects on our business and financial results. Such developments have subjected, and may in the future subject, us to additional litigation and regulatory inquiries, which could subject us to monetary penalties and damages, divert management's time and attention, and lead to enhanced regulatory oversight.
Our products and internal systems rely on software and hardware that is highly technical, and any errors, bugs, or vulnerabilities in these systems, or failures to address or mitigate technical limitations in our systems, could adversely affect our business.

Our products and internal systems rely on software and hardware, including software and hardware developed or maintained internally and/or by third parties (including public cloud providers, AI services, open source software, and the operating systems and browsers which users rely on to run our applications and access our systems), that is highly technical and complex. In addition, our products and internal systems depend on the ability of such software and hardware to store, retrieve, process, and manage immense amounts of data. The software and hardware on which we rely has contained, and will in the future contain, errors, bugs, or vulnerabilities, and our systems are subject to certain technical limitations that may compromise our ability to meet our objectives. Some errors, bugs, or vulnerabilities inherently may be difficult to detect and may only be discovered after the code has been released for external or internal use. Errors, bugs, vulnerabilities, design defects, or technical limitations within the software and hardware on which we rely, or human error or malfeasance in using such systems, have led to, and may in the future lead to, outcomes including a negative experience or other adverse effects for users and marketers who use our products, compromised ability of our products to perform in a manner consistent with our terms, contracts, or policies, delayed product introductions or enhancements, targeting, measurement, or billing errors, compromised ability to protect the data of our users and/or our intellectual property or other data, or reductions in our ability to provide some or all of our services. For example, we make commitments to our users as to how their data will be collected, used, shared, and retained within and across our products, and our systems are subject to errors, bugs and technical limitations that may prevent us from fulfilling these commitments reliably. In addition, any errors, bugs, vulnerabilities, or defects in our systems or the software and hardware on which we rely, failures to properly address or mitigate the technical limitations in our systems, or associated degradations or interruptions of service or failures to fulfill our commitments to our users, have led to, and may in the future lead to, outcomes including damage to our reputation, loss of users, loss of marketers, loss of revenue, regulatory inquiries, litigation, or liability for fines, damages, or other remedies, any of which could adversely affect our business and financial results.
If we are unable to protect our intellectual property, the value of our brands and other intangible assets may be diminished, and our business may be adversely affected.

We rely and expect to continue to rely on a combination of confidentiality, assignment, and license agreements with our employees, consultants, and third parties with whom we have relationships, as well as trademark, copyright, patent, trade secret, and domain name protection laws, to protect our proprietary rights. In the United States and internationally, we have filed various applications for protection of certain aspects of our intellectual property, and we currently hold a significant number of registered trademarks and issued patents in multiple jurisdictions and have acquired patents and patent applications from third parties. Third parties may knowingly or unknowingly infringe our proprietary rights, third parties may challenge
90

Table of Contents

proprietary rights held by us, and pending and future trademark and patent applications may not be approved. In addition, effective intellectual property protection may not be available in every country in which we operate or intend to operate our business. In any or all of these cases, we may be required to expend significant time and expense in order to prevent infringement or to enforce our rights. Although we have generally taken measures to protect our proprietary rights, there can be no assurance that others will not offer products or concepts that are substantially similar to ours and compete with our business. In addition, we regularly contribute software source code under open source and other permissive licenses and have made other technology we developed available under such licenses, and we include open source software in our products. Additionally, our AI is trained on data sets that may include open source software and the outputs of our AI may be subject to open source license restrictions or obligations. As a result of our open source contributions and the use of open source in our products, we may license or be required to license or disclose code and/or innovations that turn out to be material to our business and may also be exposed to increased litigation risk. If the protection of our proprietary rights is inadequate to prevent unauthorized use or appropriation by third parties, the value of our brands and other intangible assets may be diminished and competitors may be able to more effectively mimic our products, services, and methods of operations. Any of these events could have an adverse effect on our business and financial results.

We are currently, and expect to be in the future, party to patent, trademark, and copyright lawsuits and other intellectual property rights claims that are expensive and time consuming and, if resolved adversely, could have a significant impact on our business, financial condition, or results of operations.

Companies in the internet, technology, and media industries own large numbers of patents, copyrights, trademarks, and trade secrets, and frequently enter into litigation based on allegations of infringement, misappropriation, or other violations of intellectual property or other rights, including in novel areas such as those relating to AI training and AI outputs. In addition, various "non-practicing entities" that own patents and other intellectual property rights often attempt to aggressively assert their rights in order to extract value from technology companies. Furthermore, from time to time we may introduce or acquire new products, including in areas where we historically have not competed, or introduce new features for existing products, which could increase our exposure to intellectual property claims from competitors, non-practicing entities, and other rights holders.

From time to time, we receive notice from patent, copyright, and trademark holders and other parties alleging that certain of our products and services, trademarks, or user content, infringe their intellectual property rights or that certain employees may have misappropriated trade secrets from their former employers. We presently are involved in a number of intellectual property lawsuits, and as we face increasing competition and develop new products and services, we expect the number of intellectual property claims against us to grow. For example, we and other companies are, and expect to continue to be, the subject of litigation in the United States, Europe, Canada, and elsewhere alleging copyright infringement in connection with the acquisition, distribution, and use of copyrighted materials for AI training as well as potential reproduction of copyrighted materials in AI outputs, including cases addressing the applicability of the fair use defense in the United States. There can be no assurances that favorable final outcomes will be obtained in these cases. In addition, plaintiffs may seek, and we may become subject to, preliminary or provisional rulings in the course of any such litigation, including potential preliminary injunctions requiring us to change or cease some or all of our operations. We may decide to settle such lawsuits and disputes on terms that are unfavorable to us. Similarly, if any litigation to which we are a party is resolved adversely, we may be subject to an unfavorable judgment that may not be reversed upon appeal. The terms of such a settlement or judgment may require us to change or cease some or all of our operations or pay substantial amounts to the other parties, including statutory damages to large numbers of copyright holders. For certain jurisdictions, including the United States, statutory damages for copyright liability are calculated on a per work basis. In addition, we may have to seek a license to continue practices found to be in violation of a third party's rights, which may not be available on reasonable terms, or at all, and may significantly increase our operating costs and expenses. As a result, we may also be required to develop alternative non-infringing technology or practices, or branding or discontinue the practices or branding. The development of alternative non-infringing technology, branding or practices could require significant effort and expense, could result in less effective technology, branding or practices or otherwise negatively affect the user experience, or may not be feasible. We have experienced unfavorable outcomes in such disputes and litigation in the past, and our business, financial condition, and results of operations could be materially and adversely affected as a result of an unfavorable resolution of the disputes and litigation referred to above.
91

Table of Contents

Risks Related to Ownership of Our Class A Common Stock
The trading price of our Class A common stock has been and will likely continue to be volatile.

The trading price of our Class A common stock has been, and is likely to continue to be, volatile. Since shares of our Class A common stock were sold in our initial public offering in May 2012 at a price of $38.00 per share, our stock price has ranged from $17.55 to $796.25 through September 30, 2025. In addition to the factors discussed in this Quarterly Report on Form 10-Q, the trading price of our Class A common stock has in the past fluctuated and may in the future fluctuate significantly in response to numerous factors, many of which are beyond our control, including:
• actual or anticipated fluctuations in our revenue and other operating results for either of our reportable segments;
• the financial projections we may provide to the public, any changes in these projections, or our failure to meet these projections;
• actions of securities analysts who initiate or maintain coverage of us, changes in financial estimates by any securities analysts who follow our company, or our failure to meet these estimates or the expectations of investors;
• additional shares of our stock being sold into the market by us, our existing stockholders, or in connection with acquisitions, or the anticipation of such sales;
• investor sentiment with respect to our competitors, our business partners, and our industry in general;
• announcements by us or our competitors of significant products or features, technical innovations, acquisitions, strategic partnerships, joint ventures, or capital commitments;
• announcements by us or estimates by third parties of actual or anticipated changes in the size of our user base, the level of user engagement, or the effectiveness of our ad products;
• changes in operating performance and stock market valuations of technology companies in our industry, including our developers and competitors;
• price and volume fluctuations in the overall stock market, including as a result of trends in the economy as a whole;
• the inclusion, exclusion, or deletion of our stock from any trading indices, such as the S&P 500 Index;
• media coverage of our business and financial performance;
• lawsuits threatened or filed against us, or developments in pending lawsuits;
• adverse government actions or legislative or regulatory developments relating to advertising, competition, content, privacy, or other matters, including interim or final rulings by tax, judicial, or regulatory bodies;
• trading activity in our share repurchase program; and
• other events or factors, including those resulting from war, incidents of terrorism, pandemics, and other disruptive external events, or responses to these events.

In addition, the stock markets have experienced extreme price and volume fluctuations that have affected and continue to affect the market prices of equity securities of many technology companies. We are currently subject to securities litigation in connection with our platform and user data practices and the misuse of certain data by a developer that shared such data with third parties in violation of our terms and policies; the disclosure of our earnings results for the second quarter of 2018; a former employee's allegations and release of internal company documents beginning in September 2021; and the disclosure of our earnings results for the fourth quarter of 2021. We may experience more such litigation following future periods of volatility. Any securities litigation could subject us to substantial costs, divert resources and the attention of management from our business, and adversely affect our business.
92

Table of Contents

The dual class structure of our common stock has the effect of concentrating voting control with our CEO and certain other holders of our Class B common stock; this will limit or preclude your ability to influence corporate matters.

Our Class B common stock has ten votes per share and our Class A common stock has one vote per share. Holders of our Class B common stock, including our founder, Chairman, and CEO, together hold a majority of the combined voting power of our outstanding capital stock, and therefore are able to control the outcome of all matters submitted to our stockholders for approval so long as the shares of Class B common stock represent at least 9.1% of all outstanding shares of our Class A and Class B common stock. This concentrated control will limit or preclude your ability to influence corporate matters for the foreseeable future.

Transfers by holders of Class B common stock will generally result in those shares converting to Class A common stock, subject to limited exceptions, such as certain transfers effected for estate planning or charitable purposes. The conversion of Class B common stock to Class A common stock will have the effect, over time, of increasing the relative voting power of those holders of Class B common stock who retain their shares in the long term. If, for example, Mr. Zuckerberg retains a significant portion of his holdings of Class B common stock for an extended period of time, he could, in the future, continue to control a majority of the combined voting power of our outstanding capital stock.
Our status as a "controlled company" could make our Class A common stock less attractive to some investors or otherwise harm our stock price.

Because we qualify as a "controlled company" under the corporate governance rules for Nasdaq-listed companies, we are not required to have a majority of our board of directors be independent, nor are we required to have a compensation committee or an independent nominating function. In the future we could elect not to have a majority of our board of directors be independent or not to have a compensation committee or an independent nominating function. Accordingly, should the interests of our controlling stockholder differ from those of other stockholders, the other stockholders may not have the same protections afforded to stockholders of companies that are subject to all of the corporate governance rules for Nasdaq-listed companies. Our status as a controlled company could make our Class A common stock less attractive to some investors or otherwise harm our stock price.
Delaware law and provisions in our certificate of incorporation and bylaws could make a merger, tender offer, or proxy contest difficult, thereby depressing the trading price of our Class A common stock.

Our status as a Delaware corporation and the anti-takeover provisions of the Delaware General Corporation Law may discourage, delay, or prevent a change in control by prohibiting us from engaging in a business combination with an interested stockholder for a period of three years after the person becomes an interested stockholder, even if a change of control would be beneficial to our existing stockholders. In addition, our current certificate of incorporation and bylaws contain provisions that may make the acquisition of our company more difficult, including the following:
• until the first date on which the outstanding shares of our Class B common stock represent less than 35% of the combined voting power of our common stock, any transaction that would result in a change in control of our company requires the approval of a majority of our outstanding Class B common stock voting as a separate class;
• we currently have a dual class common stock structure, which provides Mr. Zuckerberg with the ability to control the outcome of matters requiring stockholder approval, even if he owns significantly less than a majority of the shares of our outstanding Class A and Class B common stock;
• when the outstanding shares of our Class B common stock represent less than a majority of the combined voting power of common stock, certain amendments to our certificate of incorporation or bylaws will require the approval of two-thirds of the combined vote of our then-outstanding shares of Class A and Class B common stock;
• when the outstanding shares of our Class B common stock represent less than a majority of the combined voting power of our common stock, vacancies on our board of directors will be able to be filled only by our board of directors and not by stockholders;
• when the outstanding shares of our Class B common stock represent less than a majority of the combined voting power of our common stock, our board of directors will be classified into three classes of directors with staggered three-year terms and directors will only be able to be removed from office for cause;
93

Table of Contents

• when the outstanding shares of our Class B common stock represent less than a majority of the combined voting power of our common stock, our stockholders will only be able to take action at a meeting of stockholders and not by written consent;
• only our board chair, our chief executive officer, our president, or a majority of our board of directors are authorized to call a special meeting of stockholders;
• advance notice procedures apply for stockholders to nominate candidates for election as directors or to bring matters before an annual meeting of stockholders;
• our certificate of incorporation authorizes undesignated preferred stock, the terms of which may be established, and shares of which may be issued, without stockholder approval; and
• certain litigation against us can only be brought in Delaware.
94

Table of Contents

Item 2. Unregistered Sales of Equity Securities and Use of Proceeds
a) Sales of Unregistered Securities
On August 4, 2025, in connection with our acquisition of all of the outstanding shares of a company, we issued 646,779 shares of our Class A common stock as consideration to the shareholders of the acquired company. The shares were issued in a transaction not involving a public offering pursuant to an exemption from registration set forth in Section 4(a)(2) of the Securities Act.
c) Issuer Purchases of Equity Securities
The following table summarizes the share repurchase activity for the three months ended September 30, 2025:

Total Number of Shares Purchased Average Price Paid per Share (2)
Total Number of Shares Purchased as Part of Publicly Announced Programs (1)
Approximate Dollar Value of Shares that May Yet Be Purchased Under the Programs (1)

(in thousands) (in thousands) (in millions)
July 1 - 31, 2025 4,201  $ 717.26  4,201  $ 25,213 
August 1 - 31, 2025 243  $ 756.02  243  $ 25,029 
September 1 - 30, 2025 —  $ —  —  $ 25,029 
Total 4,444  4,444 

____________________________________
(1) On November 18, 2016, we announced that our board of directors had authorized a share repurchase program of our Class A common stock, which commenced in January 2017 and does not have an expiration date. The timing and actual number of shares repurchased depend on a variety of factors, including price, general business and market conditions, and other investment opportunities, and shares may be repurchased through open market purchases or privately negotiated transactions, including through the use of trading plans intended to qualify under Rule 10b5-1 under the Exchange Act. See Note 10 — Stockholders' Equity in Part I, Item 1 of this Quarterly Report on Form 10-Q for additional information related to share repurchases.
(2) Average price paid per share includes costs associated with the repurchases but excludes the 1% excise tax accrued on our share repurchases as a result of the Inflation Reduction Act of 2022.

Item 5. Other Information

Rule 10b5-1 Trading Plans

On August 15, 2025 , Robert M. Kimmitt , a member of our board of directors , entered into a trading plan intended to satisfy the affirmative defense conditions of Rule 10b5-1(c) under the Securities Exchange Act of 1934, as amended. The trading plan provides for the sale of an aggregate of 3,500 shares of our Class A common stock. The plan will terminate on April 15, 2026 , subject to early termination for certain specified events set forth in the plan.
95

Table of Contents

Item 6. Exhibits

Exhibit
Number Incorporated by Reference Filed
Herewith
Exhibit Description Form File No. Exhibit Filing Date

31.1 Certification of Mark Zuckerberg, Chief Executive Officer, pursuant to Rule 13a-14(a)/15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002 .
X

31.2 Certification of Susan Li, Chief Financial Officer, pursuant to Rule 13a-14(a)/15d-14(a), as adopted pursuant to Section 302 of the Sarbanes-Oxley Act of 2002.
X

32.1# Certification of Mark Zuckerberg, Chief Executive Officer, pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002 .
X

32.2# Certification of Susan Li, Chief Financial Officer, pursuant to 18 U.S.C. Section 1350, as adopted pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
X

101.INS Inline XBRL Instance Document (the instance document does not appear in the Interactive Data File because its XBRL tags are embedded within the Inline XBRL document). X

101.SCH Inline XBRL Taxonomy Extension Schema Document. X

101.CAL Inline XBRL Taxonomy Extension Calculation Linkbase Document. X

101.DEF Inline XBRL Taxonomy Extension Definition Linkbase Document. X

101.LAB Inline XBRL Taxonomy Extension Labels Linkbase Document. X

101.PRE Inline XBRL Taxonomy Extension Presentation Linkbase Document. X

104 Cover Page Interactive Data File (formatted as inline XBRL and contained in Exhibit 101). X

# This certification is deemed not filed for purposes of Section 18 of the Securities Exchange Act of 1934, as amended (Exchange Act), or otherwise subject to the liability of that section, nor shall it be deemed incorporated by reference into any filing under the Securities Act of 1933, as amended, or the Exchange Act.
96

Table of Contents

SIGNATURES
Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this Quarterly Report on Form 10-Q to be signed on its behalf by the undersigned, thereunto duly authorized, in the City of Menlo Park, State of California, on this 29th day of October 2025.  

  META PLATFORMS, INC.

Date: October 29, 2025 /s/ SUSAN LI
Susan Li
Chief Financial Officer
(Principal Financial Officer)

Date: October 29, 2025 /s/ AARON ANDERSON
Aaron Anderson
Chief Accounting Officer
(Principal Accounting Officer)

97