← All enforcement actions
GDPRB2C Tech

Meta Platforms€1.2B GDPR fine (2023)

Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework

Penalty
€1.2B
Regulator
Irish Data Protection Commission (DPC)
Jurisdiction
European Union

What happened

Ireland's DPC fined Meta €1.2B for transferring Facebook user data from the EEA to the US using Standard Contractual Clauses that, post-Schrems II, did not adequately protect against US surveillance access. Meta was ordered to suspend transfers and bring processing into compliance within 6 months.

Root cause

What every team should do

  1. Run a Transfer Impact Assessment (TIA) for every non-EEA processor/sub-processor
  2. Pair SCCs with supplementary measures (encryption, pseudonymisation, access controls)
  3. Maintain an EU data-residency option for enterprise customers as a sales accelerator
  4. Re-validate transfer mechanisms whenever ECJ or EDPB issues new guidance
Source: Irish DPC final decision (May 22, 2023).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Amazon Europe Core
€746M
Largest GDPR fine at the time — behavioural ad targeting without valid consent
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly
British Airways
£20M
Magecart-style skimmer on payment page — 429K records exposed