Ireland’s data regulator has imposed a record €1.2 billion fine on Facebook owner Meta for violating European privacy rules, in a move that takes total penalties against the company above €2 billion.
The sanction handed down on Monday by Data Protection Commissioner Helen Dixon followed a long investigation into transfers by Facebook of Europeans’ personal data to the US.
She had not proposed a financial penalty against Meta in her original draft decision in the case but was “instructed” to impose a fine after a dispute resolution process at the European Data Protection Board, the body of almost 50 national and regional data regulators that must approve any cross-border penalties for data violations.
The social media giant has been directed to suspend any future data transfers within five months and told to cease within six months the “unlawful processing, including storage, in the US” of European data transferred in violation of EU law.
It is the biggest penalty since Ms Dixon assumed new powers in 2018 to supervise the pan-European operations of large tech companies such as Meta, which has its EU headquarters in Dublin and is one of the State’s biggest taxpayers.
She is responsible for inquiries into alleged breaches by big tech groups of the EU’s general data protection regulation (GDPR), which was billed as a game-changer in the drive to control how business use consumers’ personal information.
The latest fine is the sixth large GDPR penalty against Meta and its subsidiaries in Ireland, the first five of which cost the group just over €1 billion. Because it appealed previous fines in the High Court, Meta is considered likely to appeal the new sanction.
This fine brings the running total for Big Tech fines imposed by the DPC against Meta to more than €2.5 billion.
Meta Ireland was found to have violated the GDPR by continuing to transfer personal data from the EU to the US after a judgment against such transfers in Europe’s highest court.