Meta, formerly known as Facebook, has been slapped with a record-breaking fine of €1.2 billion ($1.3 billion) by Ireland’s Data Protection Commissioner (DPC), the leading privacy regulator in the European Union. The fine comes as a result of Meta’s mishandling of user information and its continued transfer of data to the United States, despite a 2020 EU court ruling that invalidated an EU-U.S. data transfer agreement.
This fine surpasses the previous record EU privacy fine of €746 million imposed on Amazon.com Inc by Luxembourg in 2021.
The dispute over where Meta stores its data began a decade ago when Austrian privacy campaigner Max Schrems raised concerns about U.S. surveillance following revelations by former U.S. National Security Agency contractor Edward Snowden. In response to the ruling, Meta has stated that it will appeal the decision, including the “unjustified and unnecessary fine,” which it believes sets a dangerous precedent for other companies. The company also plans to seek a stay of the suspension orders through the courts.
Meta has expressed confidence that a new data transfer agreement between the EU and the United States will be implemented before the suspension of data transfers becomes necessary. If the new pact is in place, Meta’s previous warning that it may have to suspend Facebook services in Europe will not materialize. The company emphasizes that without the ability to transfer data across borders, the internet risks becoming fragmented into national and regional silos.
The DPC stated in March that EU and U.S. officials are working towards a new data protection framework, expected to be ready by July, that addresses the concerns raised by the European Court of Justice about U.S. surveillance. However, privacy campaigner Max Schrems believes that Meta’s reliance on the new agreement for future data transfers is unlikely to be a permanent solution unless U.S. surveillance laws are rectified.
As the lead EU regulator for many major technology companies with European headquarters in Ireland, the DPC’s decision and suspension order against Meta could set a precedent for other firms. The DPC has now fined Meta a total of €2.5 billion for GDPR breaches, making it the most fined tech firm by the Irish regulator. Additionally, the DPC has initiated ten other inquiries into Meta’s platforms.

