Ireland's DPC fines Meta €405M, saying Instagram violated children's privacy under GDPR, the second-highest fine under the law and DPC's third for the company
Politico Vincent Manancourt
Context & Ripple Effects
The €405M sanction follows the DPC's documented finding that Instagram failed on children's privacy, while related reporting describes Instagram's broader effort to regain teen users through influencer and recommendation changes. That makes youth-facing product decisions a regulatory exposure for Meta, not only a growth tactic.
Later DPC actions against Meta widened the enforcement record from children's privacy to scraper-exposed user data and behavioral-ad data practices, placing this fine at the start of a more sustained regulatory confrontation.
First-order effects
- Meta and Instagram face a €405M GDPR penalty over children's privacy, increasing the immediate compliance burden around services and features used by younger people.
- The DPC reinforces its role as Meta's key EU privacy enforcer, adding a third company-specific fine to its record at the time.
Second-order effects
- Meta's teen-retention efforts, including changes intended to draw teens back to Instagram, face greater pressure to demonstrate that engagement design aligns with children's privacy requirements.
- The subsequent DPC penalties over scraping and behavioral advertising show scrutiny extending across Meta's data practices, rather than remaining confined to Instagram's treatment of children.
Third-order effects
- If the DPC continues pursuing separate GDPR cases across youth privacy, data security, and advertising, Meta's EU operations will face enforcement as a portfolio-wide product and data-governance issue.
- The European Data Protection Board's role in a later Meta fine points to a system in which EU-level intervention can strengthen outcomes from Ireland-led enforcement.
The trend: EU privacy enforcement is moving toward repeated, category-by-category scrutiny of Big Tech data practices rather than isolated penalties.
Related: GDPR · Instagram · DPC fines Meta over scraped user data · DPC fines Meta over behavioral ad data · European Data Protection Board and Meta fine
Related Coverage
- Ireland fines Instagram a record $400 mln over children's data Reuters
- Instagram fined €405m over children's data privacy BBC
- EU Hits Instagram With $400M Fine for Violating Kids' Privacy PCMag
- The Morning After: Meta gets fined $402 million Engadget
- Meta got fined $400 million for failing to protect kids' privacy on Instagram Insider
- Instagram fined €405M in EU over children's privacy TechCrunch
- Instagram owner Meta fined €405m over handling of teens' data The Guardian
- Irish regulator fines Instagram €405mn for failing to protect children's data Financial Times
- Instagram Fined for Violating Children's Privacy; China Orders Tech Firms to ‘Improve Traceability’ of Users ExchangeWire.com
- Instagram Fined $402 Million Over Handling of Teens' Data PetaPixel
- Instagram to Pay Over $400M in Fine in Ireland for Children's Data Mishandling Coinspeaker
- Ireland Fines Instagram $400 Mn Over Children's Data Fossbytes
- Instagram whacked with massive fine over child privacy Digital Trends
- Ireland Fines Instagram a Record $400 Million Over Children's Data Slashdot
- Irish regulator fines Meta $400M for breaking data protection laws The Hill
- Instagram was fined $402 million for mishandling teens' data in the EU The Verge
- Irish Data Watchdog Fines Instagram 405 Mn Euros Over Children Agence France-Presse
- Instagram fined 405m euros by privacy regulator over handling of children's data The Independent
- Ireland's data watchdog hits Instagram with €405 million fine Irish Mirror
- Irish watchdog fines Instagram 405M euros in teen data case Associated Press
- Irish Data Protection Commissioner fines Instagram €405m The Irish Times
- Instagram Hit With Record $402 Million Fine Over Children's Data WebProNews
- Instagram fined €405 million for sharing children's data Neowin
- Instagram hit with record $591m fine for its treatment of children's data The Age
- Meta fined $402M in Ireland over GDPR violations SiliconANGLE
- Instagram slapped with a $402 million fine over its abuse of kids' privacy iMore
- Meta faces $402 million EU fine over Instagram's privacy settings for children Engadget
- Instagram hit with $400 million fine for violation of EU children privacy rules 9to5Mac
- Irish data watchdog fines Instagram €405m for GDPR violations Silicon Republic
Discussion
-
@samir_madani
Sam
on x
The Irish came up with a brilliant way to stay warm this winter. You're a good sport about it, Zuck! https://twitter.com/...
-
@privacat
@privacat
on x
It begins. I'm looking forward to reading the decision by the @DPCIreland to understand what went wrong and how to prevent this for clients in the future. https://twitter.com/...
-
@cbridge_chief
Daragh O Brien
on x
@meta appealing the fine is unsurprising. The introduction of changes that address the issue are significantly more important.
-
@privacylawyerd
@privacylawyerd
on x
@PrivaCat Could this be more exciting than the WhatsApp decision? I'm looking forward to finding out.
-
@estelmp
Estelle M.
on x
With this penalty, the sum of all #GDPR fines to date is now over 2 billion € (pending appeals, of course) 👇 https://twitter.com/...
-
@arlenedickinson
Arlene Dickinson
on x
A fine, no matter the size, is not going to stop this blatant abuse of privacy and the resulting abuse of children. Social media giants are not above the law. https://twitter.com/...
-
@jlwgreg
James Gregson
on x
@MattNavarra Feels like this really only scratching the surface of what all these platforms are guilty of.
-
@cbridge_chief
Daragh O Brien
on x
@PrivacyLawyerD @PrivaCat My money is on DP by Design being a big issue. Devil will be in the detail.
-
@jason_kint
Jason Kint
on x
Hey hey 👋🏽 Ireland. You're alive. Nice to see Facebook get hit with its first real fine for violating GDPR. $400 million even sounds like a lot. Wake me up when we get to a billion. https://www.nytimes.com/...
-
@cbridge_chief
Daragh O Brien
on x
Instagram fined €405m by Irish regulator for breaching children's privacy rights - https://independent.ie/ > Timeline is important here. Investigation started in 2020. Changes made in 2021. Which came first? chicken or egg? https://www.independent.ie/...
-
@cbridge_chief
Daragh O Brien
on x
So, the investigation took a little over 2 years, triggered @Meta to make changes, and still resulted in a €405 million fine. Good day at the office.
-
@jamie_saris
A. Jamie Saris
on x
#Ireland and #EU show they're not f*ckin' around with #GDPR. €405m will get even the vile #Zuckerberg's attention. If u want to regulate big business, u need an economy big enough to intimidate bad actors. #EU is such an economy. https://www.irishtimes.com/...
-
@profcarroll
David Carroll
on x
Glad to see Zuck smacked with a $400M bill from the GDPR by way of Ireland for letting kids set their public-by-default Instagram accounts as Businesses and other growth hacking garbage that's plainly illegal for good reasons. https://www.nytimes.com/...
-
@cbridge_chief
Daragh O Brien
on x
Here's @meta back in 2020 telling the @BBC that they “rejected the claims” but where “cooperating with @DPCIreland”. https://www.bbc.com/... Then they made changes later to the thing that they disputed to stop doing the thing that was being investigated during the investigation.
-
@privacat
@privacat
on x
@PrivacyLawyerD As Daragh mentioned lots of potential failure points here: DP by design and default (Art.25), data accuracy (Art. 5), consent of kids (Art. 8), possibly even a failure to assess risk (Art. 35). Obviously, we'll know more once the decision is released, but this is …
-
@robertjbateman
Robert Bateman
on x
Agreed. I believe thi has to do with kids' data being exposed because they were allowed to have business accounts which made some data public by default. Once investigation began Insta changed this for adults (as well as closing the kids loophole) Classic DP by design stuff. http…
-
@jduballreports
Joe Duball
on x
Seems summer break is over in Europe... a message that if you're not safeguarding kids then there will be a price. Follows a global trend for securing better children's privacy commitments. https://twitter.com/...
-
@privacat
@privacat
on x
@PrivacyLawyerD I think it will be. For one, it involves kids, and second, it was an interesting issue: kids signing up for business accounts without adequate controls in place to verify, and then data getting shared freely. https://www.siliconrepublic.com/ ...
-
@willguyatt
Will Guyatt
on x
Good news to see the Irish DPC showing Meta it has teeth when it comes to GDPR breaches https://www.bbc.com/...
-
@privacat
@privacat
on x
@PrivacyLawyerD By not checking ages at signup and defaulting to post business info publicly, that's pretty damning.
-
@adam_k_levin
Adam Levin
on x
A $400 million fine is unlikely to change anything at Meta, unfortunately. https://www.reuters.com/...
-
@gabrielazanfir
Dr. Gabriela Zanfir-Fortuna
on x
The Irish Data Protection Commission has fined Instagram €405 million for violations of the General Data Protection Regulation re: children/teens data. The text of the decision is not yet available. Meta disclosed it is about old defaults, which were changed in the past year. htt…
-
@paulfehlinger
Paul Fehlinger
on x
Second highest GDRP fine to date: https://twitter.com/...
-
@aoifewhite101
Aoife White
on x
Instagram fined €405M for violating kids' privacy, great scoop from @vmanancourt https://www.politico.eu/...
-
@vmanancourt
Vincent Manancourt
on x
New: Instagram has been fined €405M for violating kids' privacy. That's the second highest GDPR fine ever, and the Irish regulator's third for a Meta-owned company. https://pro.politico.eu/...