The Irish Data Protection Commission wraps up an investigation into a 2019 breach, fining Meta €91M for violating GDPR rules by storing passwords in plain text
#privacy #Facebook #HaveIBeenPwned #DataBreach #Instagram — https://9to5mac.com/... X: Brian O'Donovan / @brianod_news : Breaking: Meta, the parent company of Facebook, Instagram and WhatsApp, has been fined €91m by the Irish Data Protection Commission (DPC). It follows an investigation into the storage of passwords. @rtenews https://www.rte.ie/... @dpcireland : 📢Latest News: Irish Data Protection Commission fines Meta Ireland €91 million https://www.dataprotection.ie/ ... [image] Johnny Ryan / @johnnyryan : It is good to see the DPC enforce the security principle (GDPR Article 5(1)(f)) today. But it is shocking that an issue voluntarily disclosed by Meta to the DPC in 2019 has taken more than 5 years to result in enforcement. https://dataprotection.ie/... Adrian Weckler / @adrianweckler : Almost none of these accumulated fines have been paid yet; most tied up in appeals Patrick Costello TD / @costellop : Glad to finally see some strong enforcement of large tech companies for breaching GDPR, however it's hard to understand how this took 5 years. Hopefully the @DPCIreland deal with similar data protection cases much faster in the future. https://www.irishtimes.com/... Adrian Weckler / @adrianweckler : Meta fined €91m by Irish data privacy regulator for storing passwords in plain text. Meta's fine tally with Dublin's regulator now over €2bn, https://www.independent.ie/... Adrian Weckler / @adrianweckler : Breakdown of €2.6bn in fines on Meta from Irish DPC over last 3 years. All money goes to Irish exchequer (+ €14bn Apple tax). [image] Forums: Hacker News : Meta fined $102M for storing passwords in plain text r/NewsOfTheStupid : Engadget: Meta fined $102 million for storing passwords in plain text r/leetcode : This is the FAANG company that I grind for? r/technology : Meta fined $102 million for storing passwords in plain text | The Irish Data Protection Commission found that the company violated several GDPR rules. r/technews : Meta fined $102 million for storing passwords in plain text | The Irish Data Protection Commission found that the company violated several GDPR rules. BeauHD / Slashdot : Meta Fined $102 Million For Storing 600 Million Passwords In Plain Text
Context & Ripple Effects
This enforcement sits within a continuing Irish DPC record against Meta: the regulator had already imposed a €17M penalty tied to a series of disclosed breaches and later challenged Meta’s ad and data-handling practices with a €390M GDPR fine.
The case matters because it applies GDPR’s security principle to a foundational credential-handling practice, rather than to a narrowly defined product or policy dispute. It adds another security-control finding to Meta’s wider European privacy enforcement history, which also includes the EU’s action over transatlantic data transfers.
First-order effects
- Meta Ireland must absorb the €91M penalty and address the password-storage control failure identified by the Irish DPC.
- The decision formally establishes that the disclosed credential-storage practice fell short of GDPR’s security requirements.
Second-order effects
- Meta’s security and privacy teams face added pressure to demonstrate auditable safeguards for credentials and other sensitive account data, not merely disclose incidents after discovery.
- The ruling gives European regulators a concrete enforcement reference for security-principle cases, raising the compliance stakes for platforms that retain large volumes of account data.
Third-order effects
- If such enforcement remains consistent, GDPR compliance will increasingly hinge on demonstrable engineering controls and governance, making security operations a more material operating cost for large platforms.
- Repeated decisions against the same platform may reinforce a regulatory model in which privacy enforcement shapes product and infrastructure choices over time, though the ultimate effect will depend on remediation and appeals.
The trend: European privacy enforcement is moving from broad data-use disputes toward sustained scrutiny of the operational security controls behind major platforms’ data systems.