Meta fined US$275 million following enquiry into April 2021 data leak

The data leak saw the personal information for 553 million accounts posted to the dark web

Add bookmark
Meta fined US$275 million following enquiry into April 2021 data leak

Ireland’s Data Protection Commission (DPC) has announced it will be imposing a €265mn (US$275mn) fine and “a range of corrective measures” on Meta Platforms Ireland Limited (MPIL), owner and operator of social media site Facebook, after an investigation into suspected data scraping on the site.

Data-scraping refers to a technique that locates and extracts information from a source, like a social media site, and deposits it in a database.

The inquiry was commenced on April 14 2021, after a data leak saw the personal data of 553 million Facebook users published to the internet. The Facebook IDs, names, dates of birth, locations, bios and in some cases email addresses of the affected accounts were made publicly available via a post on the dark web.

The DPC said the inquiry was concerned with “questions of compliance with the GDPR obligation for data protection by design and default”. These cybersecurity techniques put considerations of user or customer privacy and data protection at the forefront of software development.

Data protection by design embeds data privacy and protection features at the design phase, while data protection by default ensures that only solutions that are automatically data protection friendly are used to create user service settings. Under Irish GDPR laws, companies are obligated to use both these techniques when planning projects.

It was on this basis that MPIL was investigated by the DPC alongside all other EU data supervisory authorities. 

The DPC announced on November 25 that it had found that Meta had committed “infringement of Articles 25(1) and 25(2) GDPR”, meaning that the site had not followed its obligations to include data protection by design and default in Facebook’s design.

As a result of this, the commission said that it had “imposed a reprimand and an order requiring MPIL to bring its processing into compliance by taking a range of specified remedial actions within a particular timeframe”, a decision that “imposed administrative fines” of €265mn (US$275mn) on the company itself. This decision was backed by the data supervisory authorities across the EU.

The news of the fine comes days after it was reported that Meta had allegedly fired employees for breaking its terms of service and hijacking user accounts on the behalf of hackers.


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"637cc39bec0d076c7f3bea86","name":"Meta fires employees for allegedly hacking into users' accounts","description":"Internal documents allege that employees were paid thousands of dollars to hijack accounts","file":null,"url":"\/attacks\/news\/meta-fires-employees-for-allegedly-hacking-into-users-accounts"},{"id":"62f131794ed39e399d7bd243","name":"Twitter confirms data from 5.4 million accounts has been stolen","description":"Twitter has confirmed that a suspected data breach in July led to account data being stolen","file":null,"url":"\/attacks\/news\/twitter-confirms-data-from-54-million-accounts-has-been-stolen"},{"id":"6078615bd1d92e70163d1404","name":"IOTW: Facebook Data Leak Impacts 533 Million Users","description":null,"file":null,"url":"\/attacks\/articles\/iotw-facebook-data-leak-impacts-533-million-users"},{"id":"6380afee04196e675723ca28","name":"IOTW: Twitter accused of covering up data breach that affects millions","description":"The alleged breach has apparently never been reported despite affecting millions of users","file":null,"url":"\/attacks\/news\/iotw-twitter-accused-of-covering-up-data-breach-that-affects-millions"},{"id":"62fb8a8c16bbef6fc15b4af2","name":"IOTW: Signal users directly targeted in Twilio phishing attack","description":"Phishing attack on Twilio targets almost 2,000 Signal users","file":null,"url":"\/attacks\/news\/iotw-signal-users-directly-targeted-in-twilio-phishing-attack"}],"featured_content_portal_embedded":null}" >