---
title: "Meta Faces €1.2 Billion Fine Over GDPR Violations"
canonical: "https://www.virtcloudrocks.com/space/INFOSEC/blog/852370/Meta%20Faces%20%E2%82%AC1.2%20Billion%20Fine%20Over%20GDPR%20Violations"
format: markdown
---
> ℹ️ Excerpt from **SANS NewsBites Vol. 25 Num. 041** : Utah Local Entities Flunk Security Audit; Expect More Meta-scale EU Fines for Data Privacy Violations; Public Package Repositories Are Being DoS-ed with Malware

Ireland’s Data Protection Authority has fined Meta €1.2 billion (US$1.3 billion) following an investigation that found Facebook has been sending European users’ personal data to the US in violation of the General Data Protection Regulation (GDPR). The ruling also gives Facebook six months to cease sending the data to the US. In 2020, the Court of Justice of the European Union ruled that Facebook data sent to the US did not have sufficient protection from government surveillance.  
   
**Editor's Note**  
  
[[Honan](https://www.sans.org/newsletters/editorial-board-newsbites/)]  
This story is making headlines due to the €1.2 Billion fine which is the highest GDPR fine issued to date. However, the other penalties, such as the transfer of EU personal data back from the US to the EU, the deletion of EU personal data within the US, and the stop to the flow of EU personal data to the US, will have a much bigger impact on Meta as it will have to make significant changes to how it runs its business. The Irish Data Protection Commission has given Meta 5 months to comply. Meta will no doubt appeal the rulings and many companies that currently transfer EU personal data to the US, or to US companies with operations in the EU, will watch this case very closely as they too could face similar penalties. At the heart of the issue is the lack of human rights protection for non-US citizens to US mass surveillance laws and until fundamental changes are made to such laws this will be an ongoing issue. Currently the US and EU are negotiating a new framework to enable the transfer of EU personal data to replace the EU-US Privacy Shield but there is no guarantee this will address the core issue.  
  
[[Pescatore](https://www.sans.org/profiles/john-pescatore/)]  
Meta, a US-based company, being sanctioned because of US government access to user data is not very different from the US sanctioning Huawei, a China-based company, for suspected government access. Just because technology leaps across borders does not mean, and never has meant all countries have to allow it to do so. Companies should be building business plans and IT architectures that build privacy and data security in to support opt-in exposure models and higher levels of privacy than required in the US.  
  
[[Neely](https://www.sans.org/profiles/lee-neely/)]  
In a previous ruling by the Ireland court, Meta was asked to suspend the data transfers. Meta disagreed. There is deal pending between the US & EU to allow for these types of data transfers; until that is squared away, use caution if you're transferring EU user data to the US.  
  
[[Dukes](https://www.sans.org/profiles/curtis-dukes/)]  
To date, €1.2B is the largest fine ever assessed for GDPR violations. It serves as a wake-up call for companies that retain the personal data of European citizens. The explosive growth of social media platforms led to certain enterprise architecture decisions that make it difficult for companies like Meta to comply with GDPR. Some amount of re-architecting will be necessary in order to meet the six-month deadline imposed by the EU Data Protection Authority.  
  
**Read more in:**  
**- **[**www.wired.com**](https://www.wired.com/story/meta-gdpr-fine-ireland/): Meta’s $1.3 Billion Fine Is a Strike Against Surveillance Capitalism  
**- **[**www.nytimes.com**](https://www.nytimes.com/2023/05/22/business/meta-facebook-eu-privacy-fine.html): Meta Fined $1.3 Billion for Violating E.U. Data Privacy Rules  
**- **[**www.washingtonpost.com**](https://www.washingtonpost.com/technology/2023/05/22/meta-fined-eu-facebook-data-privacy/): E.U. slaps Meta with record $1.3 billion fine for data privacy violations  
**- **[**www.govinfosecurity.com**](https://www.govinfosecurity.com/facebook-ordered-to-suspend-data-transfers-to-us-from-europe-a-22129): Facebook Ordered to Suspend Data Transfers to US From Europe  
**- **[**www.scmagazine.com**](https://www.scmagazine.com/news/privacy/irelands-slaps-meta-with-1-3b-fine-over-gdpr-data-privacy-violations): Ireland slaps Meta with $1.3B fine over GDPR data privacy violations  
**- **[**arstechnica.com**](https://arstechnica.com/tech-policy/2023/05/facebook-ordered-to-pay-e1-2-billion-fine-and-stop-storing-eu-user-data-in-us/): Facebook hit with record €1.2 billion GDPR fine for transferring EU data to US