/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Irish DPC launches inquiry into Facebook after the company reported millions of Facebook Lite and Instagram user passwords were stored in plain text internally

The Data Protection Commission was notified by Facebook that it had discovered that hundreds of millions of user passwords …

Data Protection Commission

Context & Ripple Effects

The inquiry is the second time in six months Ireland's Data Protection Commission has moved on Facebook: it had already opened a probe into the company's 2018 data breach, using its role as lead regulator for multinationals headquartered in Ireland. The trigger this time was Facebook's own disclosure in late March that it would notify hundreds of millions of Facebook users and thousands of Instagram users after discovering passwords stored in readable internal logs rather than properly hashed.

What makes this filing consequential is scale and precedent: within weeks the DPC reported 19 cross-border investigations open since GDPR took effect, 11 of them targeting Facebook, WhatsApp, and Instagram — making this plain-text password case one more test of whether Ireland's regulator can police the platforms domiciled on its soil.

First-order effects

  • Facebook now faces a formal GDPR inquiry into its password-handling practices for Facebook Lite and Instagram, with the DPC empowered to demand records and ultimately levy fines proportionate to global turnover.
  • Hundreds of millions of Facebook Lite users and thousands of Instagram users are left to assess exposure from credentials that were readable inside Facebook's systems, having already been promised notifications by the company.

Second-order effects

  • The caseload concentration forces the DPC to build repeatable enforcement machinery: with 11 of 19 post-GDPR investigations aimed at Facebook's family of apps, each outcome calibrates how aggressively it treats the next self-reported incident.
  • Other multinationals regulated from Dublin — and their security teams — face a raised bar on credential storage, since Facebook's disclosure shows even internal-only logging lapses now draw formal regulatory proceedings rather than quiet fixes.

Third-order effects

  • The pattern held: five years later the same investigation closed with Meta fined €91M for storing passwords in plain text, establishing that self-disclosure does not shield a platform from penalty under GDPR.
  • If the DPC keeps converting self-reports into nine-figure outcomes, the Irish lead-regulator model hardens into the de facto enforcement channel for US platforms' data practices across the EU — and companies' incentive to disclose quickly gets weighed against the fines disclosure invites.

The trend: GDPR enforcement is maturing from breach-notification paperwork into sustained, penalty-backed supervision of Big Tech by Ireland's Data Protection Commission.