Skip to main content
Meta's €390 Million Fine: What Failed and What You Need to FixPrivacy Regulations
3 min readFor Legal and Compliance Teams

Meta's €390 Million Fine: What Failed and What You Need to Fix

What Happened

On January 4, 2023, the Irish Data Protection Commission imposed a €390 million fine on Meta for its Facebook and Instagram platforms. This significant enforcement action marks one of the largest penalties under the GDPR to date. The Irish DPC, acting as Meta's lead Supervisory Authority under the one-stop-shop mechanism, delivered this decision, indicating a strong enforcement stance among EU regulators.

Timeline

Date unknown (pre-enforcement): Meta's processing operations under scrutiny by Irish DPC
January 4, 2023: Irish Data Protection Commission announces €390 million penalty against Meta's Facebook and Instagram services

The timeline highlights a common challenge: enforcement actions often appear suddenly, but compliance failures usually develop over months or years.

Which Controls Failed or Were Missing

Without access to the full decision, we can't pinpoint the exact Article violations. However, fines of this size under GDPR often result from systemic failures across several control areas:

Lawful basis documentation. Processing personal data at Meta's scale without clear, documented legal grounds is risky. Many organizations mistakenly treat lawful basis selection as a one-time task rather than an ongoing requirement.

Technical and Organisational Measures. Article 32 of GDPR requires security measures appropriate to the risk. At an enterprise level, this means implementing encryption, access controls, monitoring, and incident response systems that match your data's volume and sensitivity. A €390 million fine suggests these measures were inadequate.

Accountability mechanisms. Article 5(2) requires you to demonstrate compliance. This involves maintaining records of processing activities (Article 30), conducting Data Protection Impact Assessments for high-risk processing (Article 35), and documenting your Technical and Organisational Measures. If you can't produce this documentation, regulators will assume the controls don't exist.

Data subject rights infrastructure. Chapter III rights require operational systems, not just policy documents. If your DSAR process involves manual email chains and spreadsheets, you're not meeting the "without undue delay" standard in Article 12(3).

What the Relevant Standard Requires

GDPR sets clear requirements that apply to all organizations:

Article 5 (Principles): Your processing must be lawful, fair, transparent, purpose-limited, data-minimized, accurate, storage-limited, secure, and accountable. These are enforceable obligations with specific implementation requirements.

Article 6 (Lawful Basis): Every processing operation needs one of six legal grounds: consent, contract, legal obligation, vital interests, public task, or legitimate interests. You must identify and document the applicable basis before processing begins.

Article 24 (Controller Responsibility): Implement appropriate Technical and Organisational Measures to ensure and demonstrate GDPR compliance. "Appropriate" scales with your processing risk, data volume, and organizational complexity.

Article 32 (Security): Security measures must account for the state of the art, implementation costs, and risks to data subjects. This requires ongoing risk assessment and control updates.

Article 35 (DPIA): High-risk processing requires a Data Protection Impact Assessment before you begin. High-risk includes systematic monitoring, large-scale special category data processing, and automated decision-making with significant effects.

Lessons and Action Items for Your Team

Document your lawful basis now. Create a processing inventory that maps every data collection point, processing activity, and data category to a specific Article 6 legal ground. Include your reasoning. If relying on legitimate interests, document your balancing test under Article 6(1)(f).

Audit your Technical and Organisational Measures. List every control for data security, access management, and breach detection. Test them. Can you detect unauthorized access? Do you encrypt data at rest and in transit? Can you restore data after an incident? Document the results and fix the gaps.

Build DSAR infrastructure that scales. If you're manually fulfilling data subject requests, you're creating evidence of non-compliance. Implement automated systems for discovery, retrieval, and delivery that can respond within the 30-day window in Article 12(3).

Conduct DPIAs for high-risk processing. Use ISO/IEC 29134 as your framework. Document the processing purpose, necessity, proportionality, and risk mitigation measures. Update your DPIAs when processing operations change.

Prepare for Prior Consultation. Article 36 requires consultation with your Supervisory Authority before proceeding with high-risk processing without adequate mitigation. Proactive consultation builds regulatory relationships and demonstrates accountability.

The Meta fine underscores that regulators will enforce compliance rigorously. Your task is to implement the controls GDPR requires and document your compliance. Start with the action items above to avoid facing similar penalties.

You Might Also Like