The Irish Data Protection Commission (DPC) has issued a €251 million fine to Meta Platforms Ireland Limited following investigations into a significant data breach that occurred in 2018.
The breach exposed the personal information of 29 million Facebook users worldwide, including three million within the European Union (EU) and European Economic Area (EEA).
The breach involved unauthorized third parties exploiting user tokens on the Facebook platform, granting access to a wide range of personal data.
The categories of personal data compromised included users’ full names, email addresses, phone numbers, locations, dates of birth, places of work, religion, gender, timeline posts, group memberships, and even data about children.
Key GDPR Infringements and Fines
The DPC identified multiple violations of GDPR:
- Failure to Notify Adequately: Meta did not provide all required information in its breach notification, resulting in a €8 million fine under Article 33(3) GDPR.
- Inadequate Documentation: Meta failed to properly document the breach and remediation efforts, leading to a €3 million fine under Article 33(5).
- Poor System Design: Meta was found to have violated Article 25(1) GDPR by not integrating data protection principles in the design of its processing systems, resulting in a €130 million fine.
- Default Data Protection Lapses: Under Article 25(2), Meta failed to ensure that only necessary personal data was processed by default, leading to a €110 million fine.
DPC Deputy Commissioner Graham Doyle emphasized the serious risks posed by such breaches, highlighting the exposure of sensitive information, including religious and political beliefs, and the potential for misuse of such data.
Broader Implications
This latest fine adds to Meta’s growing list of penalties from the DPC, including a €91 million fine earlier this year and a record €1.2 billion fine last year for transferring EU user data to the US.
As the lead privacy regulator for many tech giants based in Ireland, the DPC continues to play a pivotal role in the EU’s crackdown on big tech.
Meta has announced plans to appeal the decision, reiterating its commitment to data security and its industry-leading measures to protect users.
The DPC has confirmed that it will publish the full decision and related information in due course.
Ensure Compliance with DPM
This case serves as a critical reminder for organizations to prioritize compliance with data protection regulations like GDPR.
Businesses can significantly reduce privacy-related risks and ensure adherence to these stringent standards by leveraging solutions like Data Privacy Manager (DPM).
Designed as an innovative SaaS platform, DPM automates privacy processes and fosters cross-departmental collaboration, offering a visual dashboard to provide continuous insights into all processing activities.
With its comprehensive suite of products and modules, DPM simplifies the complexities of compliance, helping organizations safeguard their data and maintain trust.
