TECHNOLOGY

Meta Fined €251 Million for Breaking EU Data Privacy Law

Meta, the company that owns Facebook, also owns Instagram and WhatsApp

Share
Meta Fined €251 Million for Breaking EU Data Privacy Law
It is an American multinational technology conglomerate based in Menlo Park, California. (Photo: TKWS)
Share

In the latest penalty against Meta for violating European privacy rules, the social networking giant was fined €251 million (about $264 million) on Tuesday for a data leak discovered in September 2018, which led to the personal information of approximately 29 million Facebook users being published online, with many accounts subsequently hacked.

The penalty was imposed by the Irish Data Protection Commission (DPC) after two inquiries into Meta Platforms Ireland Limited (MPIL) were completed. The DPC stated that the categories of personal data affected included users’ full names, email addresses, phone numbers, locations, places of work, dates of birth, religions, genders, posts on timelines, groups of which users were members, and children’s personal data, and nearly 3 million of the total affected Facebook users were based in countries within the European Union and the European Economic Area (EEA).

“The breach arose from the exploitation by unauthorised third parties of user tokens on the Facebook platform,” the DPC said in a statement. “The breach was remedied by MPIL and its US parent company shortly after its discovery.”

> LinkedIn Fined €310 Million for Violating European Data Privacy Rules

The DPC determined that Meta had violated several EU General Data Protection Regulation (GDPR) rules by failing to document facts about the breaches and the steps taken to address them. It also found that Meta had not ensured that, by default, personal data necessary for specific purposes were processed securely to prevent unauthorised access by third parties. These failures resulted in a €110 million fine.

The DPC further reprimanded MPIL for not including all required information in its breach notification, which could and should have been included. For this, an additional administrative fine of €8 million was imposed.

Meta was also fined €133 million for failing to protect data protection principles in the design of its processing systems. This failure hindered the Supervisory Authority’s ability to verify compliance. Together, these penalties brought the total fine to €251 million.

In September 2024, the DPC submitted a draft decision to the GDPR cooperation mechanism, as required under Article 60 of the GDPR. No objections to the draft decision were raised before the publication of the full decision and related information, which will be shared in due course.

> How to Earn on Facebook From Kenya

Written by
JUSTUS KIPRONO -

Justus Kiprono is a freelance journalist based in Nairobi, Kenya. He tracks Capital Markets and economic trends, infrastructure reform, government spending, and the financial impacts of state decision-making nationwide. You can reach him: [email protected]

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

PAST ARTICLES AND INSIGHTS

Related Articles
KUCCPS chief executive Dr Agnes Mercy Wahome
FEATURED STORYNEWS

KUCCPS: Students Urged to Finalise University Applications as Midnight Deadline Looms

The Kenya Universities and Colleges Central Placement Service (KUCCPS) has issued a...

A Follower of Prophet Owuor Sues Kemri Over Conflicting Findings of Her HIV Status
NEWS

A Follower of Prophet Owuor Sues KEMRI Over Conflicting Findings of Her HIV Status

Millicent Awino, a follower of the controversial preacher Prophet Dr David Owuor,...

psg vs bayern
SPORTS

PSG vs Bayern Munich: All of us in red?

The Allianz Arena will transform into a sea of red on Wednesday...

673006309 17976852210007772 6962139009261287012 n
NEWSSPORTS

Sports Disputes Tribunal Extends FKF Boss Hussein Mohammed’s Suspension

The Sports Disputes Tribunal (SDT) has prolonged the suspension of Football Kenya...