Meta Platforms Ireland Limited

company

We found 7 decisions about Meta Platforms Ireland Limited from DPC, the latest dated 12 December 2024.

Fine, Reprimand, Order to comply — 12 December 2024
Data Protection Commission — €251 million

Background to the Inquiries The breach arose from MPIL’s use of user tokens in connection with certain features on the Facebook platform. User tokens are coded identifiers that can be used to verify the user of a platform or utility, and to control access to particular platform features and personal data of the user and their contacts. In 2017 MPIL introduced a new video uploading feature. When used in conjunction with Facebook’s ‘View As’ feature (which allows a user’s page to be viewed as another user would see it) and the ‘Happy Birthday Composer’, the video uploader would generate a fully permissioned user token that gave full access to the Facebook profile of that other user. That token could then be used to exploit the same combination of features on other accounts, allowing access to multiple users’ profiles and the data accessible through them. Between 14 and 28 September 2018 unauthorised persons used scripts to exploit this vulnerability and gained access to approximately 29 million Facebook accounts globally, of which approximately 3 million were based in the EU/EEA. Facebook security personnel were alerted to the vulnerability by an anomalous increase in video upload activity and removed the functionality that caused the vulnerability shortly thereafter. MPIL notified the DPC of the breach on 28 September 2018. The DPC commenced inquiries to investigate compliance with aspects of the GDPR. Summary of Findings: IN-18-10-1 Number Article of the GDPR Findings 1 Article 33(3) MPIL’s breach notification did not include information about the breach that MPIL could and should have included.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 26 September 2024
Data Protection Commission — €91 million

Background to the Inquiry Process MPIL uses cryptographic and encryption techniques when storing users’ passwords, and does not store the individual characters that make up a password. On 21 March 2019, MPIL informed the DPC that it had inadvertently stored certain passwords of social media users in ‘plaintext’ on its internal systems. On 24 April 2019, the DPC commenced an own-volition inquiry in response to this issue. Summary of Findings Number Article of the GDPR Findings 1 Article 4(12) The Data Protection Commission found that each of the instances of plaintext password logging, as identified by MPIL on 7 January 2019 and 31 January 2019, constituted a personal data breach within the meaning of Article 4(12) GDPR. 2 Article 33(1) The Data Protection Commission found that MPIL infringed Article 33(1) GDPR by failing to notify a personal data breach to the Data Protection Commission without undue delay and within 72 hours of the discovery on 31 January 2019 of the passwords stored in plaintext. 3 Article 33(5) The Data Protection Commission found that MPIL infringed Article 33(5) GDPR on two occasions by failing to document the personal data breach discovered on 7 January 2019 and by failing to document the personal data breach discovered on 31 January 2019. 4 Article 5(1)(f), 32(1) The Data Protection Commission found that MPIL did not comply with the requirements of Article 5(1)(f) GDPR and Article 32(1) GDPR (in particular having regard to Article 32(1)(b)) by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Order to comply — 12 May 2023
Data Protection Commission

the DPC found that these arrangements did not address the risks to the fundamental rights and freedoms of data subjects that were identified by the CJEU in its judgment. The inquiry was initially commenced in August 2020, and was subsequently stayed by Order of the High Court of Ireland, pending the resolution of a series of legal proceedings, until 20 May 2021. Following a comprehensive investigation, the DPC prepared a draft decision dated 6 July 2022. Notably, it found that: The data transfers in question were being carried out in breach of Article 46(1) GDPR; and In these circumstances, the data transfers should be suspended. Under a cooperation procedure mandated by the GDPR (Article 60), the draft decision prepared by the DPC was submitted to its peer regulators in the EU/EEA, also known as Concerned Supervisory Authorities (“CSAs”). The nature of the processing under examination by the inquiry was such that all other EU/EEA Supervisory Authorities were engaged as CSAs for the purpose of the cooperation procedure. On the question of Meta Ireland’s non-compliance with the GDPR, and the DPC’s proposal to make an order to suspend the data transfers, the CSAs agreed with the DPC’s decision. A small number (four) of the 47 CSAs raised objections in relation to the corrective power that the DPC proposed to exercise by way of the draft decision. Within this subset of CSAs, all four CSAs took the view that Meta Ireland should be subject to an administrative fine for the infringement that was found to have occurred.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine — 31 December 2022
Data Protection Commission — €210 million

introduction of the GDPR, existing (and new) users were asked to click “I accept” to indicate their acceptance of the updated Terms of Service. (The services would not be accessible if users declined to do so). Meta Ireland considered that, on accepting the updated Terms of Service, a contract was entered into between Meta Ireland and the user. It also took the position that the processing of users’ data in connection with the delivery of its Facebook and Instagram services was necessary for the performance of that contract, to include the provision of personalised services and behavioural advertising, so that such processing operations were lawful by reference to Article 6(1)(b) of the GDPR (the “contract” legal basis for processing). The complainants contended that, contrary to Meta Ireland’s stated position, Meta Ireland was in fact still looking to rely on consent to provide a lawful basis for its processing of users’ data. They argued that, by making the accessibility of its services conditional on users accepting the updated Terms of Service, Meta Ireland was in fact “forcing” them to consent to the processing of their personal data for behavioural advertising and other personalised services. The complainants argued that this was in breach of the GDPR. Following comprehensive investigations, the DPC prepared draft decisions in which it made a number of findings against Meta Ireland. Notably, it found that: 1.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 25 November 2022
Data Protection Commission — €265 million

INTRODUCTION ...................................................................................................................................... 4 B. LEGAL FRAMEWORK FOR THE INQUIRY AND THE DECISION ................................................................... 4 B.1 LEGAL BASIS FOR THE INQUIRY ............................................................................................................................. 4 B.2 DATA CONTROLLER ........................................................................................................................................... 5 B.3 LEGAL BASIS FOR THE DECISION ........................................................................................................................... 6 C. FACTUAL BACKGROUND ......................................................................................................................... 7 D. SCOPE OF THE INQUIRY ........................................................................................................................ 11 D.1 TEMPORAL SCOPE ........................................................................................................................................... 11 D.2 MATERIAL SCOPE ........................................................................................................................................... 11 E. ISSUES FOR DETERMINATION ............................................................................................................... 12 F. APPLICATION OF THE GDPR .................................................................................................................. 13 G. ASSESSMENT OF CERTAIN MATTERS CONCERNING ARTICLE 25 GDPR .................................................. 15 G.1 NATURE OF PROCESSING .................................................................................................................................. 16 G.2 SCOPE OF PROCESSING .................................................................................................................................... 17 G.3 CONTEXT OF PROCESSING................................................................................................................................. 17 G.4 PURPOSES OF PROCESSING ............................................................................................................................... 17 G.5 RISK ............................................................................................................................................................. 18 H. TECHNICAL AND ORGANISATIONAL MEASURES IMPLEMENTED BY MPIL ............................................. 30 I. FINDING REGARDING ARTICLE 25(1) GDPR ........................................................................................... 43 J. FINDING REGARDING ARTICLE 25(2) GDPR ........................................................................................... 54 K. CORRECTIVE POWERS ........................................................................................................................... 60 L. ORDER TO BRING PROCESSING INTO COMPLIANCE .............................................................................. 60 M. REPRIMAND.......................................................................................................................................... 61 N. ADMINISTRATIVE FINES ........................................................................................................................ 63 N.1 ARTICLE 83(2)(A): THE NATURE, GRAVITY AND DURATION OF THE INFRINGEMENT TAKING INTO ACCOUNT THE NATURE SCOPE OR PURPOSE OF THE PROCESSING CONCERNED AS WELL AS THE NUMBER OF DATA SUBJECTS AFFECTED AND THE LEVEL OF DAMAGE SUFFERED BY THEM................................................................................................................................................ 65 The Nature of the Infringements ................................................................................................................. 66 The Gravity of the Infringements ................................................................................................................ 67 The Duration of the Infringements .............................................................................................................. 68 N.2 ARTICLE 83(2)(B): THE INTENTIONAL OR NEGLIGENT CHARACTER OF THE INFRINGEMENT .............................................. 69 N.3 ARTICLE 83(2)(C): ANY ACTION TAKEN BY THE CONTROLLER OR PROCESSOR TO MITIGATE THE DAMAGE SUFFERED BY DATA SUBJECTS ............................................................................................................................................................. 72 N.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 2 September 2022
Data Protection Commission — €405 million

Introduction ........................................................................................................................................ 1 B. Background ......................................................................................................................................... 1 B.1 The Instagram service ................................................................................................................... 1 B.2 Issues referred to Facebook by [name] .................................................................................. 3 B.3 Issues referred to Supervisory Authorities by [name] ............................................................ 4 B.4 Introduction of “creator accounts” and modification of Instagram business accounts ............... 4 B.5 Supervisory engagement between the DPC and FB-I ................................................................... 6 C. Commencement and Scope of Inquiry ............................................................................................... 7 C.1 Inquiry actions to date .................................................................................................................. 7 C.2 Temporal scope of Inquiry ............................................................................................................ 9 C.3 Material scope of Inquiry .............................................................................................................. 9 C.4 Assessment of FB-I’s compliance with the GDPR, and consideration of corrective powers ...... 12 D. Preliminary legal and procedural issues ........................................................................................... 14 D.1 Competence of the DPC as lead supervisory authority .............................................................. 14 D.2 Procedural issues raised by FB-I prior to the Preliminary Draft Decision................................... 15 D.3 Purported DPC reliance on draft guidance ................................................................................. 16 D.4 Legal, factual and procedural issues raised by FB-I concerning the DPC assessment of the purpose of public by default processing............................................................................................ 18 Consideration of FB-I’s submissions on the DPC assessment of the purpose of processing ........ 19 Factual assessment of the purpose of public-by-default processing ........................................... 21 Procedural issues regarding the purpose of public-by-default processing .................................. 25 Preliminary conclusion on the purpose of public-by-default processing ..................................... 29 D.6 Assessment of “risk” in the context of the GDPR ....................................................................... 30 D.7 Purported failure on the part of the DPC to provide a “Statement of Facts” ............................ 31 E. Consideration of Article 6 GDPR .......................................................................................................

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Order to comply — 15 March 2022
Data Protection Commission — €17 million

The DPC has adopted a decision, imposing a fine of €17 million on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) (“Meta Platforms”). The decision followed an inquiry by the DPC into a series of 12 data breach notifications it received in the six-month period between 7 June 2018 and 4 December 2018. The inquiry examined the extent to which Meta Platforms complied with the requirements of GDPR Articles 5(1)(f), 5(2), 24(1) and 32(1) in relation to the processing of personal data relevant to the twelve breach notifications. As a result of its inquiry, the DPC found that Meta Platforms infringed Articles 5(2) and 24(1) GDPR. The DPC found that Meta Platforms failed to have in place appropriate technical and organisational measures, which would enable it to readily demonstrate the security measures that it implemented in practice to protect EU users’ data, in the context of the twelve personal data breaches. Given that the processing under examination constituted “cross-border” processing, the DPC’s decision was subject to the co-decision-making process outlined in Article 60 GDPR and all of the other European supervisory authorities were engaged as co-decisionmakers. While objections to the DPC’s draft decision were raised by two of the European supervisory authorities, consensus was achieved through further engagement between the DPC and the supervisory authorities concerned. Accordingly, the DPC’s decision represents the collective views of both the DPC and its counterpart supervisory authorities throughout the EU.

Extract from the regulator's publication.
Read the decision on the DPC website

No decision about Meta Platforms Ireland Limited from the Central Bank (last read 9 October 2026).

Monitor Meta Platforms Ireland Limited (email on any new decision) or order a dated report (€19).

Nearby in the register

See also: DPC