# Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations

- Type: News
- Source: Hunton Andrews Kurth
- Date: 2022-09-07
- Original: https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/#entry-216
- Canonical: https://overview.legal/posts/6284
- Topics: AI Enforcement Actions, Compensation Mechanisms and Remedies, AI Act Violations, GPAI Enforcement, AI Act Formal Non-Compliance, Social Media, Market Surveillance Corrective Actions and Enforcement, AI Conformity Declaration, AI Impact Assessment, Fines

## Summary

> The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, children’s phone numbers and email addresses were publicly accessible.

## Full text

[Skip to content](#lxb%5Faf-loop) 

### [ Menu](#)

[![Hunton Andrews Kurth LLP logo](https://www.huntonprivacyblog.com/wp-content/uploads/sites/28/2018/04/hak-logo-color-330x93.png)](https://www.huntonak.com/)

[Home](https://www.huntonprivacyblog.com/)[About](https://www.huntonprivacyblog.com/about/)[Contact](https://www.huntonprivacyblog.com/contact/)[Publications](https://www.huntonprivacyblog.com/publications/)

Search… Search 

# [Privacy & Information Security Law Blog](https://www.huntonprivacyblog.com) 

Global Privacy and Cybersecurity Law Updates and Analysis

[Home](https://www.huntonprivacyblog.com/) » Irish Data Protection Commissioner Fines Instagram for Children Privacy Violations

# Irish Data Protection Commissioner Fines Instagram for Children Privacy Violations

Posted on September 7, 2022

Posted in [Children’s Privacy](https://www.huntonprivacyblog.com/category/childrens-privacy/), [European Union](https://www.huntonprivacyblog.com/category/european-union/), [International](https://www.huntonprivacyblog.com/category/international/)

Listen to this post

<https://s3.us-west-1.amazonaws.com/lxb-text-to-speech/privacy-information-security-law-blog/.07b0b979-50a7-4ddf-a281-76a35668c20d.mp3>

On September 5, 2022, the Irish Data Protection Commissioner (the “DPC”) imposed a €405,000,000 fine on Instagram (a Meta-owned social media platform) for violations of the EU General Data Protection Regulation’s (“GDPR’s”) rules on the processing of children’s personal data.

The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, children’s phone numbers and email addresses were publicly accessible.

The fine is the second-largest fine imposed by an EU regulator for GDPR violations. According to online sources, Meta plans to appeal the fine.

The DPC has not yet published an official statement about the fine.

Tags: [Data Protection Authority](https://www.huntonprivacyblog.com/tag/data-protection-authority-2/), [EU Member States](https://www.huntonprivacyblog.com/tag/eu-member-states/), [GDPR](https://www.huntonprivacyblog.com/tag/gdpr/), [Ireland](https://www.huntonprivacyblog.com/tag/ireland/), [Penalty](https://www.huntonprivacyblog.com/tag/penalty/), [Personal Data](https://www.huntonprivacyblog.com/tag/personal-data/), [Social Media](https://www.huntonprivacyblog.com/tag/social-media/)

[Print:](#)

[Email this post](mailto:?subject=Irish%20Data%20Protection%20Commissioner%20Fines%20Instagram%20for%20Children%20Privacy%20Violations%20-%20Privacy%20%20and%20%20Information%20Security%20Law%20Blog&body=https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/)[Tweet this post](https://twitter.com/share/?text=Irish+Data+Protection+Commissioner+Fines+Instagram+for+Children+Privacy+Violations&url=https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/)[Like this post](https://www.facebook.com/sharer.php/?u=https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/)[Share this post on LinkedIn](https://www.linkedin.com/shareArticle/?mini=true&url=https%3A%2F%2Fwww.huntonprivacyblog.com%2F2022%2F09%2F07%2Firish-data-protection-commissioner-fines-instagram-for-children-privacy-violations%2F&title=Irish+Data+Protection+Commissioner+Fines+Instagram+for+Children+Privacy+Violations+-+Privacy++and++Information+Security+Law+Blog&summary=On%20September%205,%202022,%20the%20Irish%20Data%20Protection%20Commissioner%20imposed%20a%20€405,000,000%20fine%20on%20Instagram%20for%20violations%20of%20the%20EU%20General%20Data%20Protection%20Regulation's%20rules%20on%20the%20processing%20of%20children's%20personal%20data.%20)

##### Related Posts

[FTC Releases Agenda for Commercial Surveillance and Data Security Forum](https://www.huntonprivacyblog.com/2022/08/31/ftc-releases-agenda-for-commercial-surveillance-and-data-security-forum/) 

August 31, 2022

[FTC Issues Report to Congress on COPPA Staffing, Enforcement and Remedies](https://www.huntonprivacyblog.com/2022/08/25/ftc-issues-report-to-congress-on-coppa-staffing-enforcement-and-remedies/) 

August 25, 2022

[FTC Extends Public Comment Period on Advertising to Kids in Digital Media](https://www.huntonprivacyblog.com/2022/08/24/ftc-extends-public-comment-period-on-advertising-to-kids-in-digital-media/) 

August 24, 2022

Search… Search 

### Stay Connected

[ RSS ](/feed/) [ LinkedIn ](https://www.linkedin.com/company/hunton-andrews-kurth/) [ YouTube ](https://www.youtube.com/channel/UCzmgts6DyJGgfEmlRSzpkXw) [ Follow Us on Twitter ](https://twitter.com/hunton%5Fprivacy) 

[ Subscribe](/subscribe/)

### Topics

Topics Select Category Behavioral Advertising Centre for Information Policy Leadership Children’s Privacy Cyber Insurance Cybersecurity Enforcement European Union Events FCRA Financial Privacy General Health Privacy Identity Theft Information Security International Marketing Multimedia Resources Online Privacy Security Breach U.S. Federal Law U.S. State Law Workplace Privacy 

### Tags

Select Tag Select Tag Aaron SimpsonAccountabilityAdequacyAdvertisementAdvertisingAnna PaterakiAnonymizationAnti-terrorismAPECApple Inc.Article 29 Working PartyArtificial IntelligenceAustraliaAustriaBaltimoreBankruptcyBelgiumBiden AdministrationBig DataBinding Corporate RulesBiometric DataBlockchainBojana BellamyBrazilBrexitBritish ColumbiaBrittany BaconBrusselsBusiness Associate AgreementBYODCaliforniaCAN-SPAMCanadaCayman IslandsCCPACCTVChildren’s PrivacyChileChinaChinese TaipeiChristopher GrahamClass ActionClinical TrialCloudCloud ComputingCNILColombiaColoradoCommodity Futures Trading CommissionComplianceComputer Fraud and Abuse ActCongressConnecticutConsentConsent OrderConsumer ProtectionConsumer RightsCookiesCOPPACoronavirus/COVID-19Council of EuropeCouncil of the European UnionCourt of Justice of the European UnionCPPACPRACredit MonitoringCredit ReportCriminal LawCritical InfrastructureCroatiaCross-Border Data FlowCyber AttackCybersecurity and Infrastructure Security AgencyData ControllerData LocalizationData PortabilityData ProcessorData Protection ActData Protection AuthorityData Protection Impact AssessmentData TransferDavid DumontDavid VladeckDelawareDepartment of CommerceDepartment of Health and Human ServicesDepartment of Homeland SecurityDepartment of JusticeDepartment of the TreasuryDepartment of TreasuryDisclosureDistrict of ColumbiaDo Not CallDo Not TrackDobbsDodd-Frank ActDPIAE-PrivacyE-Privacy DirectiveEcuadorEdith RamirezElectronic Communications Privacy ActElectronic Privacy Information CenterElizabeth DenhamEmailEmployee MonitoringEncryptionENISAEU Data Protection DirectiveEU Member StatesEuropean CommissionEuropean Data Protection BoardEuropean Data Protection SupervisorEuropean ParliamentFacebookFacial Recognition SoftwareFacial Recognition TechnologyFACTAFair Information Practice PrinciplesFederal Aviation AdministrationFederal Bureau of InvestigationFederal Communications CommissionFederal Data Protection ActFederal Trade CommissionFERCFinancial IncentiveFinTechFloridaFood and Drug AdministrationForeign Intelligence Surveillance ActFranceFred CateFreedom of Information ActFreedom of SpeechFundamental RightsGDPRGeolocationGeorgiaGermanyGlobal Privacy AssemblyGlobal Privacy Enforcement NetworkGoogleGramm Leach Bliley ActHackerHawaiiHealth InformationHIPAAHITECH ActHong KongHungaryIllinoisIndiaIndianaInformation Commissioners OfficeInformation SecurityInformation SharingInsurance ProviderInternal Revenue ServiceInternational Association of Privacy ProfessionalsInternetInternet of ThingsIP AddressIrelandIsraelItalyJacob KohnstammJapanJason BeachJay RockefellerJenna RodeJennifer StoddartJessica RichJohn DelionadoJohn EdwardsKentuckyKoreaLatin AmericaLaw EnforcementLawrence StricklingLegislationLegislatureLiabilityLinkedInLisa SottoLitigationLocation-Based ServicesLondonMadrid ResolutionMaineMalaysiaMarketingMarkus HeyderMarylandMassachusettsMexicoMicrosoftMinnesotaMobile AppMobile DeviceMySpaceNational Institute of Standards and TechnologyNational Labor Relations BoardNational Science and Technology CouncilNational Security AgencyNational Telecommunications and Information AdministrationNebraskaNetherlandsNevadaNew HampshireNew JerseyNew MexicoNew YorkNew ZealandNigeriaNinth CircuitNorth CarolinaObama AdministrationOECDOffice for Civil RightsOffice of Foreign Assets ControlOhioOnline Behavioral AdvertisingOpt-In ConsentOregonOutsourcingPakistanPaul TiaoPayment CardPCI DSSPenaltyPenalty Consumer ProtectionPennsylvaniaPersonal DataPersonal Health InformationPersonal InformationPersonally Identifiable InformationPeruPhilippinesPhyllis MarcusPolandPRISMPrivacy By DesignPrivacy PolicyPrivacy RulePrivacy ShieldProtected Health InformationRansomwareRecord RetentionRed Flags RuleRichard ThomasRight to Be ForgottenRight to PrivacyRisk-Based ApproachRosemary JayRussiaSafe HarborSanctionsSchremsSecurities and Exchange CommissionSecurity RuleSenateSerbiaService ProviderSingaporeSmart GridSmart MeteringSocial MediaSocial Security NumberSouth AfricaSouth CarolinaSouth KoreaSpainSpywareStandard Contractual ClausesState Attorneys GeneralStick With Security SeriesStored Communications ActSupreme CourtSurveillanceSwedenSwitzerlandTaiwanTargeted AdvertisingTelecommunicationTelecommunicationsTelemarketingTelephone Consumer Protection ActTennesseeTerry McAuliffeTexasText MessageThailandTransparencyTransportation Security AdministrationTrump AdministrationTwitterUnited Arab EmiratesUnited KingdomUnited StatesUnmanned Aircraft SystemsUruguayUtahVermontVideo Privacy Protection ActVideo SurveillanceVirginiaViviane RedingWashingtonWashington D.C.WhistleblowingWireless NetworkWiretapZIP Code 

### Archives

Archives Select Month  September 2022  August 2022  July 2022  June 2022  May 2022  April 2022  March 2022  February 2022  January 2022  December 2021  November 2021  October 2021  September 2021  August 2021  July 2021  June 2021  May 2021  April 2021  March 2021  February 2021  January 2021  December 2020  November 2020  October 2020  September 2020  August 2020  July 2020  June 2020  May 2020  April 2020  March 2020  February 2020  January 2020  December 2019  November 2019  October 2019  September 2019  August 2019  July 2019  June 2019  May 2019  April 2019  March 2019  February 2019  January 2019  December 2018  November 2018  October 2018  September 2018  August 2018  July 2018  June 2018  May 2018  April 2018  March 2018  February 2018  January 2018  December 2017  November 2017  October 2017  September 2017  August 2017  July 2017  June 2017  May 2017  April 2017  March 2017  February 2017  January 2017  December 2016  November 2016  October 2016  September 2016  August 2016  July 2016  June 2016  May 2016  April 2016  March 2016  February 2016  January 2016  December 2015  November 2015  October 2015  September 2015  August 2015  July 2015  June 2015  May 2015  April 2015  March 2015  February 2015  January 2015  December 2014  November 2014  October 2014  September 2014  August 2014  July 2014  June 2014  May 2014  April 2014  March 2014  February 2014  January 2014  December 2013  November 2013  October 2013  September 2013  August 2013  July 2013  June 2013  May 2013  April 2013  March 2013  February 2013  January 2013  December 2012  November 2012  October 2012  September 2012  August 2012  July 2012  June 2012  May 2012  April 2012  March 2012  February 2012  January 2012  December 2011  November 2011  October 2011  September 2011  August 2011  July 2011  June 2011  May 2011  April 2011  March 2011  February 2011  January 2011  December 2010  November 2010  October 2010  September 2010  August 2010  July 2010  June 2010  May 2010  April 2010  March 2010  February 2010  January 2010  December 2009  November 2009  October 2009  September 2009  August 2009  July 2009  June 2009  May 2009  April 2009  March 2009  February 2009  January 2009  December 2008  November 2008 

### Recent Updates

* [Irish Data Protection Commissioner Fines Instagram for Children Privacy Violations](https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/)
* [Wawa Inc. Settles Multi-State AG Breach Investigation for $8 Million](https://www.huntonprivacyblog.com/2022/09/06/wawa-inc-settles-multi-state-ag-breach-investigation-for-8-million/)
* [FTC Releases Agenda for Commercial Surveillance and Data Security Forum](https://www.huntonprivacyblog.com/2022/08/31/ftc-releases-agenda-for-commercial-surveillance-and-data-security-forum/)
* [California AG Provides Summary of Recent CCPA Enforcement Actions, with Focus on Global Privacy Control](https://www.huntonprivacyblog.com/2022/08/31/california-ag-provides-summary-of-recent-ccpa-enforcement-actions-with-focus-on-global-privacy-control/)
* [Update: California Legislation Proposes Extending CCPA Exemptions for HR and B2B Data](https://www.huntonprivacyblog.com/2022/08/30/california-legislation-proposes-extending-ccpa-exemptions-for-hr-and-b2b-data/)

### Links & Resources

* [California Consumer Privacy Act Resource Center](https://www.huntonak.com/en/practices/privacy-and-cybersecurity/ccpa.html)
* [The Centre for Information Policy Leadership](https://www.informationpolicycentre.com/)
* [Privacy and Cybersecurity Practice](https://www.huntonak.com/en/practices/privacy-and-cybersecurity/)
* [Privacy and Data Security Law Deskbook](https://lrus.wolterskluwer.com/store/product/privacy-and-cybersecurity-law-deskbook-2022-edition/?applyPromo=PCLD20)
* [GTDT Data Protection & Privacy](https://www.lexology.com/gtdt/workareas/data-protection-and-privacy)
* [Blockchain Legal Resource](https://www.blockchainlegalresource.com/)
* [Hunton Employment & Labor Perspectives Blog](https://www.huntonlaborblog.com/)
* [Hunton Insurance Recovery Blog](https://www.huntoninsurancerecoveryblog.com/)
* [Hunton Retail Law Resource](https://www.huntonretailindustryblog.com/)

### [![RSS](https://www.huntonprivacyblog.com/wp-includes/images/rss.png)](https://huntonwilliams.infongen.com/rss2?searchId=58e73dea-73cb-41b3-b975-476046a3284c&userId=1c3b947c51c7289ec9233bf7b1035ba0&s=og9%2FdoUYuqIX1lTdiMq7%2BNn7Wok%3D) Privacy News

* [After two decades, SA's privacy and transparency laws are ready for action](https://www.capetalk.co.za/articles/454082/after-two-decades-sa-s-privacy-and-transparency-laws-are-ready-for-action-bizun)
* [Data access challenges thwarting European CEOs’ aims to become data-driven intelligent organisations](https://www.digitaljournal.com/pr/data-access-challenges-thwarting-european-ceos-aims-to-become-data-driven-intelligent-organisations)
* [Marketing Consulting Services Market See Huge Growth for New Normal | The Boston Consulting, McKinsey, PwC](https://www.digitaljournal.com/pr/marketing-consulting-services-market-see-huge-growth-for-new-normal-the-boston-consulting-mckinsey-pwc)
* [Veeam Promotes Mohamad Rizk to Regional Head for Middle East and CIS](https://www.albawaba.com/business/pr/veeam-promotes-mohamad-rizk-regional-head-middle-east-and-cis-1490260)
* [IPXHOP becomes first 'ISMS' certified IP company in S.Korea](http://www.econotimes.com/IPXHOP-becomes-first-ISMS-certified-IP-company-in-SKorea-1640926)
* [Antimicrobial Hospital Curtains Market Size Latest Trends Key Players Revenue and Forecast 2028](https://www.digitaljournal.com/pr/antimicrobial-hospital-curtains-market-size-latest-trends-key-players-revenue-and-forecast-2028)
* [India will have new data laws in next 3-4 months: Rajeev Chandrasekhar](https://www.business-standard.com/article/current-affairs/india-will-have-new-data-laws-in-next-3-4-months-rajeev-chandrasekhar-122090700923%5F1.html)
* [‘Back to school’ is also ‘back to cyberattacks’ for some districts](https://www.washingtonpost.com/politics/2022/09/07/back-school-is-also-back-cyberattacks-some-districts/)
* [Mexico’s scam loan apps ensnare young workers as enforcers](https://nationalpost.com/pmn/news-pmn/crime-pmn/mexicos-scam-loan-apps-ensnare-young-workers-as-enforcers)
* [CCPA Business-to-Business and Employment Information Exceptions Ending – Foley & Lardner LLP](https://www.rocketnews.com/2022/09/ccpa-business-to-business-and-employment-information-exceptions-ending-foley-lardner-llp/)

# [Privacy & Information Security Law Blog](https://www.huntonprivacyblog.com) 

### Attorney Advertising

Case results depend upon a variety of factors unique to each case. Case results do not guarantee or predict a similar result in any future case. Unless otherwise noted, attorneys not certified by the Texas Board of Legal Specialization.

[ RSS ](/feed/) [ LinkedIn ](https://www.linkedin.com/company/hunton-andrews-kurth/) [ YouTube ](https://www.youtube.com/channel/UCzmgts6DyJGgfEmlRSzpkXw) [ Follow Us on Twitter ](https://twitter.com/hunton%5Fprivacy) 

[Privacy Notice](https://www.huntonprivacyblog.com/updated-privacy-policy/)[Disclaimer](https://www.huntonprivacyblog.com/disclaimer/)[Cookies](https://www.huntonprivacyblog.com/cookies/)

### About Our Practice Group

Hunton Andrews Kurth’s Privacy and Cybersecurity practice helps companies manage data at every step of the information life cycle. The firm is a leader in its field and for the fourth consecutive year has been ranked by _Computerworld_ magazine in a survey of more than 4,000 corporate privacy leaders as the top law firm globally for privacy and data security. Chambers and Partners also rated Hunton Andrews Kurth the top privacy and data security practice in its _Chambers Global_, _Chambers USA_ and _Chambers UK_ guides.

Hunton Andrews Kurth’s award-winning Privacy & Information Security Law Blog is among the top-ranked legal blogs.

Copyright © 2022, Hunton Andrews Kurth LLP. All Rights Reserved.

[Law blog design & platform by LexBlog LexBlog Logo ](https://www.lexblog.com/products/blog-premier/)

## Cited law provisions (1)

### GDPR — gdpr-art-29-en

The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.

---
Generated by overview.legal · https://overview.legal/posts/6284 · 2026-08-22
