{"id":39795,"date":"2023-06-13T09:34:54","date_gmt":"2023-06-13T07:34:54","guid":{"rendered":"https:\/\/zuniclaw.com\/the-biggest-data-protection-fine-to-date-meta-can-t-catch-a-break\/"},"modified":"2025-05-15T10:14:41","modified_gmt":"2025-05-15T08:14:41","slug":"meta-gdpr-fine","status":"publish","type":"post","link":"https:\/\/zuniclaw.com\/en\/meta-gdpr-fine\/","title":{"rendered":"The Biggest Data Protection Fine To Date \u2013 Meta Can\u2019t Catch a Break"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"39795\" class=\"elementor elementor-39795 elementor-33659\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8e00608 e-flex e-con-boxed e-con e-parent\" data-id=\"8e00608\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2149a23b elementor-widget elementor-widget-text-editor\" data-id=\"2149a23b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"av_textblock_section av-23ouy8n-23dde5ba856095cf1631d4da87e70424\"><div class=\"avia_textblock linkz\"><p>On the five-year anniversary of the enforcement of the EU\u2019s General Data Protection Regulation (GDPR), Ireland\u2019s Data Protection Commission (DPC) issued a decision punishing famous company Meta for violating the rules on the international transfer of personal data on an unprecedented scale.<\/p><p>Let us remind you that Meta has already been fined several times by the same authority for failing to comply with the provisions of the GDPR. The company has not yet digested the <a href=\"https:\/\/zuniclaw.com\/en\/meta-and-gdpr\/\">previous fine from a few months ago<\/a> (their highest one at the time), which was imposed for collecting and processing data through Facebook and Instagram services for targeted advertising without proper legal ground. The new fine of 1.2 billion euro is three times higher than the previous one.<\/p><p>This fine even exceeds the fine imposed on Amazon by the Luxembourg National Commission for Data Protection (<a href=\"https:\/\/cnpd.public.lu\/en.html\" target=\"_blank\" rel=\"noopener\">CNDP<\/a>) back in July 2021 in the amount of 746 million euro, also for non-compliance with personal data protection regulations, making it currently the top-ranking penalty in this field.<\/p><\/div><\/section><div class=\"hr av-6liqoy-601e76812ac5929c2b8b370ab0376f5a hr-invisible avia-builder-el-9 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div class=\"av-special-heading av-18xydwi-af41b59dc41b7a7541ad9f95e5e66e23 av-special-heading-h2 blockquote modern-quote modern-centered avia-builder-el-10 el_after_av_hr el_before_av_textblock \"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">What Meta\u2019s Actions Were Worth a Fine of 1.2 Billion Euros?<\/h2><\/div><section class=\"av_textblock_section av-lisrotvb-56e490aad66bc363730cd805b15076cc\"><div class=\"avia_textblock linkz\"><p>\u00a0<\/p><p>The short answer is that Meta transferred Facebook users\u2019 personal data from the EU to the United States without <a href=\"https:\/\/gdpr-info.eu\/art-46-gdpr\/\" target=\"_blank\" rel=\"noopener\">providing appropriate safeguards<\/a>.<\/p><p>In order to detect precisely where the problem arose, it is necessary to first understand the legal framework of international data transfer. If you want to learn more about the international transfer of data, you can do that on our latest blog International transfer of data \u2013 Are you compliant?<\/p><p>Firstly, GDPR sets conditions for the transfer of data to third countries from the European Union. Data can be freely transferred to other countries if EU authorities have assessed that the legislation of the recipient\u2019s country provides adequate protection. Since the United States is not on the list of countries considered to offer equal data protection as EU member states, additional conditions must be met for such transfers to take place.<\/p><p>The agreement previously concluded between the EU and the US known as <a href=\"https:\/\/zuniclaw.com\/en\/eu-us-privacy-shield\/\">Privacy Shield has ceased to apply<\/a> because the Court of Justice of the European Union has deemed that this agreement doesn\u2019t give enough security to the information transmitted from Europe to the US. Although the new agreement (Privacy Shield 2.0), which would provide better data protection, is expected to be adopted soon, data controllers currently cannot rely on any international agreement for their data transfers across the Atlantic.<\/p><p>A weaker level of data protection prescribed by the laws of a country such as the US can be compensated by contracts concluded between data controllers, processors, and\/or recipients which include SCCs (<a href=\"https:\/\/zuniclaw.com\/en\/standard-contractual-clauses\/\">Standard Contractual Clauses<\/a>) and Data Transfer Impact Assessment (DTIA).<\/p><p>However, Meta Platforms Ireland Limited has transferred personal data in accordance with the transfer and processing agreement concluded with its US equivalent, Meta Platforms, Inc. which incorporated the European Commission\u2019s 2021 Standard Contractual Clauses (SCCs), and it was still found to be in breach of the GDPR. The agreement between those two companies even included a Data Transfer Impact Assessment (DTIA) which determined the risks and consequences of such a transfer.<\/p><p>You must be wondering what exactly is wrong with this transfer of Facebook users\u2019 data if Meta implemented the measures mentioned above.<\/p><p>Namely, in 2020, the European Court of Justice issued the Schrems II judgment<a href=\"https:\/\/zuniclaw.com\/en\/meta-gdpr-fine\/#_ftn1\" name=\"_ftnref1\">[1]<\/a> that tightened the rules of data transfer to third countries. This judgment established that SCCs are still considered good practices, but these clauses are not enough anymore. Data controllers must understand that they can\u2019t just rely on a signed paper, but they must inform themselves of the recipient country\u2019s degree of compliance with the GDPR.<\/p><p>In this case, DPC in cooperation with the European Data Protection Board (EDPB) and other European Concerned Supervisory Authorities (CSA) has decided that all the efforts that Meta has done were not adequate to protect the rights and freedoms of the people whose personal data was being transferred.<\/p><p><a href=\"https:\/\/zuniclaw.com\/en\/meta-gdpr-fine\/#_ftnref1\" name=\"_ftn1\"><\/a><\/p><\/div><\/section><section class=\"av_textblock_section av-lisrylr1-8a7e53f3435a8abb327c2378b41de74e\"><div class=\"avia_textblock linkz\"><p>In a nutshell, the supervisory authorities found that:<\/p><ul><li>The level of protection of the US law is not equivalent to the level provided by EU law;<\/li><li>The inadequate protection provided by the US law cannot be compensated with the use of SCCs nor Meta\u2019s measures set out in the TIA;<\/li><li>Meta did not fulfill the criteria to rely on the derogations provided in the GDPR regarding data transfer.<\/li><\/ul><p><a href=\"https:\/\/zuniclaw.com\/en\/meta-gdpr-fine\/#_ftnref1\" name=\"_ftn1\"><\/a><\/p><\/div><\/section><div class=\"hr av-npo8n6-c93310a1567e715fd327154e90bb441d hr-invisible avia-builder-el-13 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div class=\"av-special-heading av-lisro5hk-67b3d1b01a6f6c0344eb34fb3b7e2d2c av-special-heading-h2 blockquote modern-quote modern-centered avia-builder-el-14 el_after_av_hr el_before_av_textblock \"><h2>\u00a0<\/h2><h2 class=\"av-special-heading-tag\">Consequences and Meta\u2019s Response<\/h2><\/div><section class=\"av_textblock_section av-lisrpln2-bca7397b0876a60c759886c2faf31462\"><div class=\"avia_textblock linkz\"><p>In its <a href=\"https:\/\/edpb.europa.eu\/system\/files\/2023-05\/final_for_issue_ov_transfers_decision_12-05-23.pdf\" target=\"_blank\" rel=\"noopener\">decision<\/a>, Ireland\u2019s data protection authority <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/Data-Protection-Commission-announces-conclusion-of-inquiry-into-Meta-Ireland\" target=\"_blank\" rel=\"noopener\">has ordered Meta to<\/a>:<\/p><ul><li><strong>Pay a fine of 1.2 billion euros<\/strong> for its breach of GDPR;<\/li><li>to within the period of <strong>6 (six) months<\/strong> from the date on which the decision is notified to Meta bring processing operations into compliance with GDPR, by <strong>ceasing the unlawful processing, including storage<\/strong>, in the US of personal data of EEA (European Economic Area) users transferred in violation of the GDPR;<\/li><li><strong>suspend any future transfer<\/strong> of personal data to the US within the <strong>period of five months<\/strong> starting from the date the DPC\u2019s decision is issued to Meta Ireland.<\/li><\/ul><\/div><\/section><section class=\"av_textblock_section av-liss0ey4-c75aa525ed80dc266366279861973e08\"><div class=\"avia_textblock linkz\"><p>\u00a0<\/p><p>Meta has announced in its <a href=\"https:\/\/about.fb.com\/news\/2023\/05\/our-response-to-the-decision-on-facebooks-eu-us-data-transfers\/\" target=\"_blank\" rel=\"noopener\">response to DPC\u2019s decision<\/a> that the company will appeal against the decision it considers unfair and excessive. Also, Meta\u2019s officials stated that there won\u2019t be any immediate disruption of the provision of Facebook services in Europe. In Meta\u2019s response, one of the main talking points was how Facebook\u2019s case was singled out when other organizations which are providing their services on European territory are using the same legal mechanism.<\/p><p>Meta\u2019s argument that many other companies also use similar measures when transferring data to third countries bears some truth. Therefore, it could be said that Meta was just the first scapegoat and that this decision serves as a warning to everyone who needs to make additional efforts to ensure that the protection of personal data is maintained at the same level even when transferred to other continents.<\/p><p>Although many companies operating both in Europe and the US are hopeful that the new Privacy Shield 2.0 will soon come into effect, currently it is just wishful thinking rather than a reality that one needs to align their business with.<\/p><\/div><\/section>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>On the five-year anniversary of the enforcement of the EU\u2019s General Data Protection Regulation (GDPR), Ireland\u2019s Data Protection Commission (DPC) issued a decision punishing famous company Meta for violating the rules on the international transfer of personal data on an unprecedented scale. Let us remind you that Meta has already been fined several times by [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":66869,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[126,83,84],"class_list":["post-39795","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-privacy-data-protection-en","category-novosti","category-privatnost-i-zastita-podataka"],"_links":{"self":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/comments?post=39795"}],"version-history":[{"count":3,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39795\/revisions"}],"predecessor-version":[{"id":66879,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39795\/revisions\/66879"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media\/66869"}],"wp:attachment":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media?parent=39795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/categories?post=39795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}