The Irish Data Protection Commission wraps up an investigation into a 2019 breach, fining Meta €91M for violating GDPR rules by storing passwords in plain text
The Irish Data Protection Commission found that the company violated several GDPR rules.
Context & Ripple Effects
The €91M penalty adds to a record of Irish DPC enforcement against Meta: the regulator previously imposed a €17M penalty tied to a series of disclosed breaches and a €265M fine over scraped user data.
Because Ireland’s regulator is a key GDPR enforcer for large technology platforms, the case makes password-handling practices—not only data collection or disclosure—a continuing compliance exposure.
First-order effects
- Meta must absorb a €91M GDPR penalty after the DPC concluded its investigation into the 2019 plaintext-password storage breach.
- The finding puts Meta’s credential-storage controls and associated GDPR compliance processes under renewed regulatory scrutiny.
Second-order effects
- Other platforms with EU-facing services have a stronger incentive to audit credential storage, access controls, and breach-governance procedures, especially as the DPC’s Meta cases span distinct security failures.
- The cumulative enforcement record makes privacy and security controls a more material operating cost for platforms, while increasing demand for tools and services that document compliance.
Third-order effects
- If enforcement continues across different categories of security lapse, GDPR compliance will increasingly be judged as an operational-control discipline rather than a narrow privacy-policy exercise.
- The pattern could further concentrate compliance advantages among larger platforms able to sustain specialized legal, security, and audit functions, though the corpus does not establish how broadly that effect will extend.
The trend: European privacy enforcement is broadening from isolated breach penalties into sustained oversight of the technical controls that govern platform data security.