Facebook owner Meta has been fined €1.2bn (£1bn) for abusively handling personal data when transferring it between Europe and the United States.
It is imposed by the Data Protection Commission (DPC) of Ireland and is the highest fine imposed under the EU’s General Data Protection Regulation.
The GDPR sets out rules companies must follow to transfer user data outside of the EU.
Meta says it will appeal the “unfair and unnecessary” verdict.
At the heart of this decision is the use of Standard Contractual Clauses (SCCs) to transfer data from the European Union to the United States.
These legal contracts, drawn up by the European Commission, contain security measures to ensure that personal data continues to be protected even when transferred outside of Europe.
However, there are concerns that these data streams still expose Europeans to the US’s weaker data protection laws – and that US intelligence agencies could access the data.
This decision has no impact on Facebook in the UK. The Information Commissioner’s Office told the BBC the decision “does not apply in the UK” but said it “has taken note of the decision and will review the details in due course”.
Most large companies have complex networks for transferring data — including email addresses, phone numbers, and financial information — to recipients abroad, many of which rely on SCCs.
And Meta says its widespread use makes the fine unfair.
Facebook President Nick Clegg said: “We are therefore disappointed that we have been singled out and using the same legal mechanisms as thousands of other companies looking to offer services in Europe.”
“This decision is flawed, unjustified and sets a dangerous precedent for the myriad other companies that transfer data between the EU and the US.”
But privacy groups have welcomed this precedent.
Caitlin Fennessy of the International Association of Privacy Professionals said: “The size of this record-breaking fine is commensurate with the importance of the signal it sends.”
“Today’s decision signals that there are a lot of risks at stake for companies.”
This could lead to EU companies requiring US partners to store data within Europe – or switching to domestic alternatives, she added.
In 2013, former US National Security Agency official Edward Snowden revealed that American authorities had repeatedly accessed people’s information through technology companies like Facebook and Google.
And Austrian privacy activist Max Schrems filed a lawsuit against Facebook for failing to protect its privacy rights, sparking a decades-long dispute over the legality of transferring EU data to the US.
Europe’s highest court, the European Court of Justice (ECJ), has repeatedly said Washington has inadequate controls to protect Europeans’ information.
And in 2020, the ECJ ruled that an EU-US data transfer agreement was invalid.
However, the ECJ left the door open for companies to use standard contractual clauses and stated that the transfer of data to any other third country is permissible as long as an “adequate level of data protection” is guaranteed.
The test meta has been detected as failed.
Asked about the €1.2 billion fine, Mr Schrems said he was “glad with this decision after ten years of litigation” but the fine could have been much higher.
“Until US surveillance laws are changed, Meta will need to fundamentally overhaul its systems,” he added.
Despite the record-breaking fine, experts believe Meta’s privacy practices will not change.
“A €1 billion parking ticket has no repercussions on a company that makes many billions more from illegal parking,” said Johnny Ryan, senior fellow at the Irish Council for Civil Liberties.
The US recently updated its internal legal protections to give the EU more assurance that American intelligence agencies would follow new data access rules.
In 2021, Amazon was fined for a similar disregard for EU data protection standards.
Ireland’s DPC has also fined WhatsApp, another Meta-owned company, for breaching strict regulations regarding the transparency of data shared with its other subsidiaries.
Add Comment