
Meta Penalised 413 Million USD for Violating the GDPR
They claimed that the delivery of personalised advertising wasn't required, by virtue of the law, to the fulfilment of the contract made between Meta and its users.
By
CIO Applications Europe | Sunday, January 15, 2023

Regulatory wrangling resulted in a massive new fine over Facebook and Instagram data handling, even as Meta vows to appeal and EU data protection groups prepare for a court battle.
FREMONT, CA:In response to Meta Ireland's management of user data on Facebook and Instagram, the Irish Data Protection Commission stated that it will punish the firm with a total of USD 413 million for violating the EU's General Data Protection Regulation.
Companies seeking to process users' personal information under the GDPR must do so with one of six defined legal bases, which include the user's consent, the need to carry out a contract, and the need to adhere to a legal requirement. In its response to the first user complaints brought under the GDPR in 2018, Meta declared that it would now rely on the contract justification rather than the consent prong as it had done in the past. The complaints claimed that by requiring users to consent to Meta's use of their personal data for ad targeting, the company wasn't actually giving them a choice.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
According to that regulator, the Irish DPC's initial examination found no issues with the company's choice, but Meta was penalised for failing to clearly explain the necessary legal basis to its users. However, as part of the process mandated by the GDPR, the peer organisations of the DPC reviewed the draft decisions against Meta argued that the contract basis for data processing was problematic from a legal standpoint. They claimed that the delivery of personalised advertising wasn't required, by virtue of the law, to the fulfilment of the contract made between Meta and its users.
The DPC stated that it disagreed with this but that the structure of the GDPR, specifically the requirement that the European Data Protection Board review, required it to revise its earlier decisions in order to reflect the idea that Meta cannot rely on the contract justification for its processing of personal information. It also revised its proposed fines in this manner.
However, the DPC resisted the Data Protection Board's request that the Irish data regulator launch further investigations into the handling of Facebook and Instagram data, arguing that the EDPB lacks the jurisdiction to do so. The group announced it will submit a case with the European Court of Justice to stop further inquiries, contending that the EDPB had overstepped its authority with these directives.
Meta stated publicly that it was disappointed with the verdicts and that it would be appealing both the substance of the rulings and the fines. The DPC's findings set a three-month deadline for the corporation to abide by the new rules, but the ongoing legal fight may make that period much longer.
More in News
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info
Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe
THANK YOU FOR SUBSCRIBING


