FineMeFine Intelligence
GDPR Art. 46DPC · IrelandMay 22, 2023

Meta Platforms, Inc.

Technology · Enterprise · Public company

€1.2B
Monetary fine

Summary

The Irish Data Protection Commission (DPC) issued a €1.2 billion fine against Meta Platforms Inc. for transferring the personal data of EU users to the United States without adequate safeguards, in violation of GDPR Chapter V. The transfers relied on Standard Contractual Clauses (SCCs) in a post-Schrems II environment where US surveillance law was found to provide insufficient protection. Meta was also ordered to suspend all future transfers and bring its processing into compliance within 5 months.

Article 83 factors applied

Nature, gravity and duration:Severe — systemic, ongoing transfers to US over years
Intentional or negligent character:Negligent — continued transfers despite Schrems II ruling
Categories of personal data:General personal data of c. 300M EU users
Degree of cooperation:Partial cooperation with supervisory authority
Turnover of the undertaking:Global turnover ~$116B — statutory max applied

Could have been avoided / reduced

Timely adoption of supplementary measures after Schrems II (2020)
Transition to EU-US Data Privacy Framework (certified July 2023)
Proactive engagement with DPC on transfer impact assessments
Data localisation for EU user data prior to ruling