Skip to content
Enforcement · Data Protection Authority of Ireland EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security

The Irish DPA has fined Meta Platforms Ireland Limited EUR 265 million.

€265,000,000 Fine
Art. 25 GDPR

Full text

Key Excerpts from Decision

Data Protection Commission announces decision in Facebook “Data Scraping” Inquiry 28th November 2022 The Data Protection Commission (DPC) has today announced the conclusion to an inquiry into Meta Platforms Ireland Limited (MPIL), data controller of the “Facebook” social media network, imposing a fine of €265 million and a range of corrective measures. The DPC commenced this inquiry on 14 April 2021, on foot of media reports into the discovery of a collated dataset of Facebook personal data that had been made available on the internet. The scope of the inquiry concerned an examination and assessment of Facebook Search, Facebook Messenger Contact Importer and Instagram Contact Importer tools in relation to processing carried out by Meta Platforms Ireland Limited (‘MPIL’) during the period between 25 May 2018 and September 2019. The material issues in this inquiry concerned questions of compliance with the GDPR obligation for Data Protection by Design and Default. The DPC examined the implementation of technical and organisational measures pursuant to Article 25 GDPR (which deals with this concept). There was a comprehensive inquiry process, including cooperation with all of the other data protection supervisory authorities within the EU. Those supervisory authorities agreed with the decision of the DPC. The decision, which was adopted on Friday, 25 November 2022, records findings of infringement of Articles 25(1) and 25(2) GDPR. The decision imposed a reprimand and an order requiring MPIL to bring its processing into compliance by taking a range of specified remedial actions within a particular timeframe. In addition, the decision has imposed administrative fines totalling €265 million on MPIL.

View Full Original Decision (English)

How it connects

Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
2020 EDPB Annual Report 2019 EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report,… May 18, 2020 Privacy by Design & Default Privacy by Default Supervision
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer