In a ruling against Meta, the EU's top court affirms that consumer protection agencies can bring lawsuits against infringements of GDPR laws protecting data
Context & Ripple Effects
Meta has spent years fighting GDPR enforcement on multiple fronts: the Irish DPC hit it with a €390M fine over its ad and data handling, Germany's Federal Cartel Office forced an ad-business overhaul back in 2019, and privacy campaigner Max Schrems won a ruling that social networks cannot keep using people's data for ad targeting indefinitely.
This ruling changes who can attack. Until now, GDPR enforcement ran mainly through data protection authorities; by affirming that consumer protection agencies can also file lawsuits over GDPR infringements, the EU's top court opens a second litigation front aimed squarely at Meta.
First-order effects
- Meta now faces potential GDPR lawsuits not just from regulators but from consumer protection agencies across EU member states, multiplying the number of parties that can challenge its data practices.
Second-order effects
- Consumer-agency suits stack on top of existing pressure — the Irish DPC fine, the cartel office's ad overhaul order, and the CJEU's Schrems ruling on indefinite ad targeting — raising the cumulative legal cost of defending Meta's data-for-ads model.
Third-order effects
- If the pattern holds, GDPR enforcement becomes decentralized and court-driven rather than confined to national regulators, with successive rulings consistently narrowing how platforms may process user data for advertising.
The trend: GDPR enforcement in Europe is broadening from regulator fines to a court-backed web of litigants — consumer agencies, cartel authorities, and campaigners — steadily constraining Meta's ad-data business.