Facebook data breach - €265million fine - Data Compliant

Facebook data breach – €265million fine

The Irish DPC has issued a fine of €265 million to Meta Platforms Ireland Limited (MPIL) – the data controller of the Facebook network – after a 19-month enquiry. The DPC also issued a reprimand and has imposed a range of specified remedial actions to be completed within three months.

While the Irish DPC is the lead regulator, this decision included cooperation with the other EU data protection supervisory authorities.  This has been a surprisingly swift process, largely due to the EU countries being in agreement over the issue.

The enquiry began in April 2021.  Over 530 million Facebook users’ personal data — including email addresses and mobile phone numbers — were reported to have been exposed online. It appears that the data had been scraped maliciously from Facebook profiles, using a Contact Importer tool provided by Facebook. In September 2019, Facebook adjusted the tool to prevent further malicious activity. The DPC focussed its enquiry on tools running from 25 May 2018 (when GDPR came into force) and September 2019” (when Facebook made its security amendments).

The core issue that led to the fine was Meta’s failure to meet the obligations around Data Protection by Design and Default (Article 25 of the GDPR) by implementing appropriate technical and organisational measures.

Data Protection by Design and Default

Data Protection by Design and Default is not new.  But while in the past it’s been “advisable”, it is now, under GDPR, a legal requirement. Which means that you must, by law, have appropriate technical and organisational measures in place to ensure you comply effectively with data protection principles; and that you protect and safeguard individuals’ rights.

In practice, this means that you must think about data protection and privacy compliance – up-front. And build it into all the data processing you undertake. It has to be embedded throughout your business and all its practices.  And it’s important that it starts at the very beginning of the process, from concept and design stage, and runs right through the lifecycle of any personal data processing you do. 

This is the requirement that the DPC determined that Meta did not meet.

Meta Statement

In response to the DPC actions, Meta says it is “reviewing this decision carefully”, and stated: “We made changes to our systems during the time in question, including removing the ability to scrape our features in this way using phone numbers… Unauthorised data scraping is unacceptable and against our rules and we will continue working with our peers on this industry challenge … Protecting the privacy and security of people’s data is fundamental to how our business works. That’s why we have cooperated fully with the Irish Data Protection Commission on this important issue. “

Total Meta GDPR fines?

This latest fine brings the total amount of fines imposed since Autumn 2021 by the DPC on Meta to €912m.  Previous fines include €405m just a couple of months ago (teenagers’ Instagram accounts displayed their phone numbers and email addresses on a “public-by-default” setting); In March 2022, a GDPR fine of €17m was levied;  and in September 2021 a €225m fine was issued over “severe” and “serious” infringements by WhatsApp .

Avoid GDPR Fines

Privacy by Design and Default is at the heart of the GDPR. A Data Protection Impact Assessment (DPIA) is just one of the vital tools businesses need to help them meet their compliance and security obligations. It is an essential means of demonstrating that you put compliance and the security of your data subjects at the heart of everything you do.   

Consider the individuals whose data you are processing. What will be the impact on them? Will the processing be fair? Is it even legal? Would they expect you to process it in this way? Have you made them aware? Have you told them their rights? Will their data be safe? Have you done your due diligence on your suppliers? Do you have the right contracts? What are the risks? How can the risks be mitigated? Do you have appropriate organisational processes in place? What technical safeguards do I have / need? 

Asking yourselves questions like this will help you be sure you are taking appropriate steps towards meeting your obligations when processing personal data.

If you have questions or concerns about the practicalities around Data Protection by Design and Default, or how best to conduct a DPIA, or if you would like to chat about your own measures in this area, please call 01787 277742 or email dc@datacompliant.co.uk. You can find information about some of our services here.

Victoria Tuffill  29th November 2022

 

97 Responses

  1. tadalafil says:

    tadalafil

    tadalafil

  2. cialis pay with paypal

    cialis pay with paypal

  3. can you buy viagra in canada over the counter

    can you buy viagra in canada over the counter

  4. cialis tadalafil 5mg once a day

    cialis tadalafil 5mg once a day

  5. buy generic viagra in usa

    buy generic viagra in usa

  6. sildenafil online india

    sildenafil online india

  7. buying cialis online

    buying cialis online

  8. can you buy viagra over the counter nz

    can you buy viagra over the counter nz

  9. sildenafil 2 says:

    sildenafil 2

    sildenafil 2

  10. cialis no prescrip

    cialis no prescrip

  11. does medicare pay for cialis

    does medicare pay for cialis

  12. buy tramadol us pharmacy

    buy tramadol us pharmacy

  13. publix pharmacy cipro

    publix pharmacy cipro

  14. viagra online lowest price

    viagra online lowest price

  15. cialis overnight deleivery

    cialis overnight deleivery

  16. where to purchase viagra online

    where to purchase viagra online

  17. poppers and cialis

    poppers and cialis

  18. Primaquine says:

    Primaquine

    Primaquine

  19. buy cialis australia

    buy cialis australia

  20. best viagra online

    best viagra online

  21. viagra tablets online india

    viagra tablets online india

  22. viagra canadian pharmacy prices

    viagra canadian pharmacy prices

  23. buy viagra online india 100mg

    buy viagra online india 100mg

  24. over the counter viagra pills

    over the counter viagra pills

  25. compare sildenafil prices

    compare sildenafil prices

  26. tadalafil 40 mg india

    tadalafil 40 mg india

  27. buy cialis brand

    buy cialis brand

  28. buy cialis 20mg

    buy cialis 20mg

  29. tadalafil citrate research chemical

    tadalafil citrate research chemical

  30. metronidazole sciatica

    metronidazole sciatica

  31. bactrim epilepsie

    bactrim epilepsie

  32. mylan-gabapentin 300mg

    mylan-gabapentin 300mg

  33. valacyclovir instructions

    valacyclovir instructions

  34. nolvadex injection

    nolvadex injection

  35. side effects of pregabalin

    side effects of pregabalin

  36. metformin licence

    metformin licence

  37. furosemide pseudotumor

    furosemide pseudotumor

  38. lisinopril dzialanie

    lisinopril dzialanie

  39. 40 mg semaglutide

    40 mg semaglutide

  40. 9 weeks on semaglutide

    9 weeks on semaglutide

  41. minute md semaglutide reviews

    minute md semaglutide reviews

  42. zoloft first week

    zoloft first week

  43. flagyl faydaları

    flagyl faydaları

  44. cephalexin ingredients

    cephalexin ingredients

  45. how long has cymbalta been around

    how long has cymbalta been around

  46. can escitalopram kill you

    can escitalopram kill you

  47. gabapentin antihistamines

    gabapentin antihistamines

  48. is keflex the same as amoxicillin

    is keflex the same as amoxicillin

  49. fluoxetine and phentermine

    fluoxetine and phentermine

  50. viagra online 100mg

    viagra online 100mg

  51. can i take tylenol with duloxetine

    can i take tylenol with duloxetine

  52. spiraldynamics

    spiraldynamics

  53. Spiral Dynamics

    Spiral Dynamics

  54. can you drink alcohol with ciprofloxacin 500 mg

    can you drink alcohol with ciprofloxacin 500 mg

  55. cephalexin drug interactions

    cephalexin drug interactions

  56. does bactrim cause yeast infections

    does bactrim cause yeast infections

  57. can i take bactrim sooner than 12 hours

    can i take bactrim sooner than 12 hours

  58. vxi.su says:

    vxi.su

    vxi.su

  59. amoxicillin while pregnant

    amoxicillin while pregnant

  60. augmentin dosage

    augmentin dosage

  61. side effects of effexor xr

    side effects of effexor xr

  62. diclofenac interactions

    diclofenac interactions

  63. ddavp in dogs

    ddavp in dogs

  64. flexeril dose for back pain

    flexeril dose for back pain

  65. what are the side effect of citalopram

    what are the side effect of citalopram

  66. depakote er dosage for bipolar

    depakote er dosage for bipolar

  67. diltiazem hcl side effects

    diltiazem hcl side effects

  68. cozaar vs lisinopril

    cozaar vs lisinopril

  69. extended release niacin or ezetimibe and carotid intima–media thickness

    extended release niacin or ezetimibe and carotid intima–media thickness

  70. is it better to take flomax in the morning or evening

    is it better to take flomax in the morning or evening

  71. contrave rx says:

    contrave rx

    contrave rx

  72. allopurinol 100 mg tablet

    allopurinol 100 mg tablet

  73. aripiprazole 2 mg tablet

    aripiprazole 2 mg tablet

  74. why does amitriptyline cause breast enlargement

    why does amitriptyline cause breast enlargement

  75. aspirin and blood pressure

    aspirin and blood pressure

  76. side effects of stopping celexa

    side effects of stopping celexa

  77. how long can you take celebrex 200mg?

    how long can you take celebrex 200mg?

  78. baclofen uso says:

    baclofen uso

    baclofen uso

  79. buspar and weight gain

    buspar and weight gain

  80. celecoxib davis pdf

    celecoxib davis pdf

  81. actos ejecutoriados

    actos ejecutoriados

  82. remeron dosing

    remeron dosing

  83. repaglinide manufacturer

    repaglinide manufacturer

  84. valley medical weight loss semaglutide

    valley medical weight loss semaglutide

  85. acarbose similar

    acarbose similar

  86. protonix side effects mayo clinic

    protonix side effects mayo clinic

  87. robaxin and pregnancy

    robaxin and pregnancy

  88. how long does abilify take to work

    how long does abilify take to work

  89. spironolactone 852

    spironolactone 852

  90. what are the side effects of tizanidine

    what are the side effects of tizanidine

  91. synthroid kelp

    synthroid kelp

  92. double dose of tamsulosin

    double dose of tamsulosin

  93. stromectol pill price

    stromectol pill price

  94. what are the pros and cons of venlafaxine?

    what are the pros and cons of venlafaxine?

  95. voltaren (diclofenac potassium) potassium

    voltaren (diclofenac potassium) potassium

  96. linagliptina y sitagliptina

    linagliptina y sitagliptina

Comments are closed.