News: 1618471570

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Irish privacy watchdog sticks GDPR probe into Facebook after that online giveaway of 533 million profiles

(2021/04/15)


Ireland’s Data Protection Commission this week launched an investigation into whether Facebook failed to adequately protect users' personal info – and whether it fell foul of GDPR – when a package of 533 million profiles was given away for free online.

Phone numbers, email addresses, birthdays, and marital status had been offered on a cyber-crime forum for all, it emerged this month. The data was harvested in 2019 by miscreants who exploited a security shortcoming to scrape the info from people's Facebook profiles.

[1]

Facebook [2]previously told El Reg it patched up the security hole that same year. The data was flogged online in 2020, and was made available for free this year.

Zuck it up: Facebook hit with triple whammy of legal probes, action in Canada, US, Ireland [3]READ MORE

[4]

Now, Ireland’s data privacy watchdog believes “one or more provisions” of the GDPR and the Data Protection Act 2018 may have been, or are still being, violated by the Silicon Valley giant when it comes to the personal data of Facebook users.

“Accordingly, the commission considers it appropriate to determine whether Facebook Ireland has complied with its obligations, as data controller, in connection with the processing of personal data of its users by means of the Facebook Search, Facebook Messenger Contact Importer and Instagram Contact Importer features of its service, or whether any provision(s) of the GDPR and/or the Data Protection Act 2018 have been, and/or are being, infringed by Facebook in this respect,” it [5]said in a statement on Wednesday.

“We are cooperating fully with the IDPC in its enquiry, which relates to features that make it easier for people to find and connect with friends on our services,” a Facebook spokesperson told The Register . “These features are common to many apps and we look forward to explaining them and the protections we have put in place.”

[6]

It’s not the first time Facebook has caught the attention of the watchdog. [7]In 2019 , the commission investigated whether the antisocial media giant had trampled over GDPR when it [8]logged hundreds of millions of user account passwords in plain text on its servers. Companies can be [9]fined up to €20 million ($24.1m), or up to four per cent of their previous year’s global annual revenues, depending on which is higher, if they have violated GDPR. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YHgOvukP4UlNsSrY5qRt4QAAAAs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/04/05/facebook_data_dump_update/

[3] https://www.theregister.com/2019/04/26/facebook_sued_again/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YHgOvukP4UlNsSrY5qRt4QAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.dataprotection.ie/en/news-media/press-releases/dpc-launches-inquiry-facebook-relation-collated-dataset-facebook-user-personal-data-made-available

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YHgOvukP4UlNsSrY5qRt4QAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2019/04/26/facebook_sued_again/

[8] https://www.theregister.com/2019/03/21/facebook_passwords/

[9] https://gdpr-info.eu/issues/fines-penalties/

[10] https://whitepapers.theregister.com/

Doctor Syntax

"Phone numbers, email addresses, birthdays, and marital status "

At the same time the IDPC might ask FB and the rest why birthdays and marital status is held. I understand that there may be requirements to know that an individual is over a certain age but that's simply a Boolean parameter, a date is not required.

Perhaps el Reg could also ask them. Lately Google has taken to nagging about needing a date of birth on "my" phone account alleging this to be a legal requirement but somehow overlooking any citation of the statute or explaining why it things this can only be satisfied by a date. Given that no actual name is attached to the account it's a little OTT but it seems, at least for the time being, satisfied with the date of the start of the Unix epoch .

a pressbutton

"why birthdays and marital status is held"

...So you can target your adverts a bit less inefficiently?

Finally a way to tax FB?

Anonymous Coward

"or up to four per cent of their previous year’s global annual revenues,"

An artist should be fit for the best society and keep out of it.