/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The Irish DPC fines Meta €17M for GDPR violations related to 12 personal data breaches that Meta disclosed to the regulator between June 2018 and December 2018

Natasha Lomas / TechCrunch :

TechCrunch Natasha Lomas

Context & Ripple Effects

The €17M penalty was an early Irish DPC enforcement action over a cluster of Meta breach disclosures from 2018. Later cases show the regulator continuing to close separate Meta investigations, including a €265M penalty over scraped-user-data safeguards and a €91M fine over plain-text password storage.

The arc broadened beyond breach handling: the DPC subsequently imposed a €390M behavioral-ad-data penalty with a three-month remediation deadline. That makes the 2018-breach decision relevant as part of a widening compliance burden on Meta's European operations.

First-order effects

  • Meta must absorb the €17M fine and account to the Irish DPC for GDPR shortcomings across the 12 disclosed personal-data breaches.
  • The Irish DPC establishes a concrete enforcement outcome for Meta's 2018 breach disclosures, rather than treating disclosure itself as sufficient compliance.

Second-order effects

  • Meta faces a growing set of distinct DPC cases spanning breach safeguards, password handling, scraping exposure, and ad-data practices, increasing the need to remediate systems across product and data-governance teams.
  • The DPC's later, larger Meta penalties raise the stakes for how Meta prioritizes controls around personal-data storage and incident response.

Third-order effects

  • EU privacy enforcement is moving toward cumulative, issue-by-issue scrutiny of Big Tech data practices: one company's breach response, security controls, and data-use policies can each produce separate regulatory exposure.
  • As cases extend from incidents to core advertising practices, European data protection compliance becomes a business-model constraint for platforms, not only a security function.

The trend: The Irish DPC's Meta cases illustrate increasingly sustained GDPR enforcement across both platform security failures and commercial data practices.

Discussion

  • @sophieintveld @sophieintveld on x
    Assuming the company is making as much money as last year, it takes Facebook about 83 minutes to recuperate a €17m fine. https://twitter.com/...
  • @maxschrems @maxschrems on x
    Wow... @DPCIreland now tries to trash other DPAs within the @EU_EDPB with such graphics, when their report actually admits that: - 99% of cases do not see a formal decision (86% are “amicable” resolutions and 13% are “not perused by the complainant anymore). (1) https://twitter.c…
  • @shalf @shalf on x
    Lulz. Even with 1-2 more zeros, it would still be non-relevant. https://twitter.com/...