Skip to content
Enforcement · Data Protection Authority of Ireland EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Meta Platforms Ireland Limited: Non-compliance with general data processing principles

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million.

Full text 3 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook service and EUR 180 million for violations related to the provision of its Instagram service. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of two individuals. Meta had updated its terms of service shortly before the GDPR came into force. In its new terms of service, Meta informed its users to click 'Agree and Continue' to indicate their agreement with the new terms of service. This was required for further access to the services. Meta assumed that the acceptance of the updated terms of use constituted a contract between Meta and the user, since the processing of the data would be necessary for the provision as well as the improvement of the services. According to Meta, the data processing was therefore lawful pursuant to Art. 6 (1) b) GDPR.

§

However, the complainant argued that Meta was actually trying to rely on consent as a legal basis for processing users' data. By making the access to its services conditional on users' consent to the updated terms of service, Meta was actually forcing users to consent to the processing of their personal data. Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR to other European supervisory authorities concerned. The DPC found that Meta did not rely on user consent as a legal basis, and did not consider 'coerced consent' in this case. It also did not rule out the possibility that Meta relied on a contractual legal basis. In response, the DPC received objections from different supervisory authorities. However, the DPC found that Meta had breached its transparency obligations under the GDPR, by not clearly explaining to users for what purpose and on what legal basis their personal data would be processed.

§

As no agreement could be reached on the disputed points, the DPC initiated a dispute resolution procedure pursuant to Art. 65 GDPR. In its decision, the EDPB confirmed the violation of transparency obligations by Meta. However, the EDPB took a different position than the DPC on the issue of the legal basis and found that Meta was not entitled to rely on a contractual legal basis. The EDPB therefore found that Meta had violated Art. 6 (1) GDPR. The DPC agreed in its final decision and imposed the fine and also required Meta to bring its data processing into compliance within three months. GDPR Articles: Art. 5 (1) a) GDPR, Art. 6 (1) GDPR, Art. 12 GDPR, Art. 13 (1) c) GDPR Industry: Media, Telecoms and Broadcasting

How it connects

3 of 3 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). Jan 9, 2025 IP Address Retention Period Identification
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… Mar 27, 2025 Telecommunications Personal Data Marketing
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian… First Chamber Nov 13, 2025 Telecommunications Personal Data Legitimate Interest