Skip to main contentSkip to navigationSkip to navigation
Meta's logo at the company's headquarters in Menlo Park, California
The data appeared on a hacking website last year. Photograph: Godofredo A Vásquez/AP
The data appeared on a hacking website last year. Photograph: Godofredo A Vásquez/AP

Meta fined €265m over data protection breach that hit more than 500m users

This article is more than 1 year old

Facebook, Instagram and WhatsApp owner has been fined nearly €1bn by EU since September 2021

Facebook’s owner has been fined €265m (£230m) by the Irish data watchdog after a breach that resulted in the details of more than 500 million users being published online.

The Data Protection Commission (DPC) said Meta had infringed two articles of the EU’s data protection laws after details of Facebook users from around the world were scraped from public profiles in 2018 and 2019.

The data appeared on a hacking website last year, prompting an investigation by the DPC, which is responsible for regulating Meta across the EU. The watchdog said a “significant” number of the users were from the EU.

In addition to the fine, it “imposed a reprimand and an order” requiring Meta to “bring its processing into compliance by taking a range of specified remedial actions within a particular timeframe”.

In a statement Meta said: “We made changes to our systems during the time in question, including removing the ability to scrape our features in this way using phone numbers. Unauthorised data scraping is unacceptable and against our rules.”

The punishment brings the total amount of fines imposed on Meta by the DPC to nearly €1bn since September last year. In September Meta was fined €405m for letting teenagers set up Instagram accounts that publicly displayed their phone numbers and email addresses, while in March the watchdog fined Meta €17m for further GDPR breaches and in September last year it fined Meta’s WhatsApp €225m over “severe” and “serious” infringements of GDPR.

However, one legal expert questioned whether strong enforcement of the EU’s General Data Protection Regulation would have the deterrent effect that it intended.

“By any measure, these are significant fines,” said David Hackett, head of data protection in the Ireland office of law firm Addleshaw Goddard. “GDPR envisaged the imposition of such fines in part to serve as a deterrent to other companies which might consider breaching the law. We are likely to see increased debate about whether such fines actually influence corporate behaviour or if some companies simply see them as an added cost of doing business.”

The DPC regulates Apple, Google, TikTok and other technology platforms owing to the location of their EU headquarters in Ireland. It currently has 40 inquiries open into such companies, including 13 involving Meta.

skip past newsletter promotion

The Irish regulator said in a statement that other relevant EU regulators agreed with the decision issued on Monday after it shared a draft ruling with them last month under the bloc’s “one-stop shop” system of regulating large multinationals.

More on this story

More on this story

  • Meta value falls $190bn as investors react to plan to increase spending on AI

  • Terror watchdog condemns WhatsApp for lowering UK users’ minimum age to 13

  • Anger from campaigners as WhatsApp lowers age limit to 13 in UK and EU

  • Facebook and Instagram: Meta services hit by widespread outages

  • Facebook rules allow altered video casting Biden as paedophile, says board

  • Mark Zuckerberg to receive $700m from Meta dividends

  • Meta revenue soars as it pivots to AI and announces dividends for investors

  • Meta is the world’s ‘single largest marketplace for paedophiles’, says New Mexico attorney general

  • Instagram to scan under-18s’ messages to protect against ‘inappropriate images’

Most viewed

Most viewed