Ireland: Meta fined $18.6m for breaking EU's GDPR
- Reference: 1647433834
- News link: https://www.theregister.co.uk/2022/03/16/meta_gdpr_fine/
- Source link:
Ireland's Data Protection Commission (DPC) imposed the fine on Meta Platforms Ireland, formerly Facebook Ireland, following its inquiry into 12 data breach notifications over the six-month period between 7 June 2018 and 4 December 2018.
The inquiry found Meta Platforms infringed Articles 5(2) and 24(1) of the GDPR, the EU's General Data Protection Regulation.
[2]
The social media giant "failed to have in place appropriate technical and organizational measures which would enable it to readily demonstrate the security measures that it implemented in practice to protect EU users' data, in the context of the twelve personal data breaches," according to a DPC statement.
[3]
[4]
A Meta spokesperson said: "This fine is about record-keeping practices from 2018 that we have since updated, not a failure to protect people's information. We take our obligations under the GDPR seriously, and will carefully consider this decision as our processes continue to evolve."
Meta's offending data practice involved "cross-border" processing. As such the DPC worked with all of the other European supervisory authorities to come to a consensus. Therefore, the DPC's decision represents the joint view of the Irish authority and its counterpart across the EU.
[5]
The fine though may be small change for Meta which accrued $32.6bn ad revenue in calendar Q4, its last reported quarter. It posted net profit of $10.3bn, albeit lower than $11.2bn a year earlier.
[6]EC fines Facebook €110m for 'misleading' data on WhatsApp deal
[7]EU, US close to replacing defunct Privacy Shield II
[8]Americans far more willing to hand over personal data
[9]France says Google Analytics breaches GDPR when it sends data to US
Last year WhatsApp, a [10]Meta company since 2014 , [11]was fined €225m by the DPC under GDPR rules . The messaging firm said it intended to appeal the decision, saying the fine was "entirely disproportionate."
The case was about how WhatsApp acted on transparency obligations within data protection law with regard to the provision of information and the transparency of that information to both users and non-users of WhatsApp's service. This includes information provided to data subjects about the processing of information between WhatsApp and other Facebook companies."
In a separate case, [12]Google and Facebook were fined by French watchdog Commission Nationale de l'Informatique et des Libertés (CNIL) for the position of GUI button to permit immediate acceptance of cookies while not offering the user an equivalent to refuse them as easily. Google was fined €150m while Facebook got a €60m penalty. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2022/02/03/facebook_q4_2021/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjIXw4eVqQAvRzM@I3sCkQAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjIXw4eVqQAvRzM@I3sCkQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjIXw4eVqQAvRzM@I3sCkQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjIXw4eVqQAvRzM@I3sCkQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2017/05/18/ec_fines_facebook_110m_for_wrong_info/
[7] https://www.theregister.com/2022/03/02/new_hope_for_privacy_shield/
[8] https://www.theregister.com/2022/02/23/americans_willing_data/
[9] https://www.theregister.com/2022/02/10/google_analytics_gdpr_breach/
[10] https://www.theregister.com/2014/10/07/facebook_finalizes_whatsapp_gobble/
[11] https://www.theregister.com/2021/09/02/whatsapp_to_appeal_irish_gdpr_fine/
[12] https://www.theregister.com/2022/01/06/cnil_facebook_google_cookie/
[13] https://whitepapers.theregister.com/
Re: "Meta has received an $18.6m (€17m) fine"
In that regard, Russia had the right idea last year although perhaps not for the right reasons: unless the bigwigs - or in cases like this, at least the country PHBs - are made criminally accountable for these situations, nothing will ever change.
Re: "Meta has received an $18.6m (€17m) fine"
The problem with data protection law is that it's enforced by the same government that is offering the company financial incentives to locate there.
Imagine if employment law was enforced by the chamber of commerce.
Re: "Meta has received an $18.6m (€17m) fine"
In ye olden times, we called it a swear jar.
Indeed
The $ has indeed dropped behind the Euro now.
'the fine was "entirely disproportionate."'
Correct, the fine should have been 10 x as much: €2,250 million
What a huge fine.
It must have felt like being slapped in the face with a wet lettuce leaf.
"Meta has received an $18.6m (€17m) fine"
Once again, coffee money. Penalties of this nature and order are just a cost of 'doing business'. Real enforcement would require monitored and audited change of behaviour with criminal sanctions for failure to comply. The biggest problem with data protection law is that it's penalties are administrative only and therefore have no real teeth, as has been seen in the many cases where the offending organisation has negotiated its penalty downward, or even failed to pay up without further penalty.