Privacy

Meta Fined Record $1.3 Billion and Ordered to Stop Sending European User Data to US

The European Union slapped Meta with a record $1.3 billion privacy fine and ordered it to stop transferring user data across the Atlantic.

Facebook account takeovers

The European Union slapped Meta with a record $1.3 billion privacy fine Monday and ordered it to stop transferring user data across the Atlantic, the latest salvo in a decadelong case sparked by U.S. cybersnooping fears.

The penalty fine of 1.2 billion euros from Ireland’s Data Protection Commission is the biggest since the EU’s strict data privacy regime took effect five years ago, surpassing Amazon’s 746 million euro penalty in 2021 for data protection violations.

The Irish watchdog is Meta’s lead privacy regulator in the 27-nation bloc because the Silicon Valley tech giant’s European headquarters is based in Dublin.

Meta, which had previously warned that services for its users in Europe could be cut off, vowed to appeal and ask courts to immediately put the decision on hold.

“There is no immediate disruption to Facebook in Europe,” the company said.

“This decision is flawed, unjustified and sets a dangerous precedent for the countless other companies transferring data between the EU and U.S.,” Nick Clegg, Meta’s president of global and affairs, and Chief Legal Officer Jennifer Newstead said in a statement.

It’s yet another twist in a legal battle that began in 2013 when Austrian lawyer and privacy activist Max Schrems filed a complaint about Facebook’s handling of his data following former National Security Agency contractor Edward Snowden’s revelations about U.S. cybersnooping.

The saga has highlighted the clash between Washington and Brussels over the differences between Europe’s strict view on data privacy and the comparatively lax regime in the U.S., which lacks a federal privacy law.

Advertisement. Scroll to continue reading.

An agreement covering EU-U.S. data transfers known as the Privacy Shield was struck down in 2020 by the EU’s top court, which said it didn’t do enough to protect residents from the U.S. government’s electronic prying.

That left another tool to govern data transfers — stock legal contracts. Irish regulators initially ruled that Meta didn’t need to be fined because it was acting in good faith in using them to move data across the Atlantic. But it was overruled in Monday’s ruling by the EU’s top panel of data privacy authorities.

Meanwhile, Brussels and Washington signed an agreement last year on a reworked Privacy Shield that Meta could use, but the pact is awaiting a decision from European officials on whether it adequately protects data privacy.

EU institutions have been reviewing the agreement, and the bloc’s lawmakers this month called for improvements, saying the safeguards aren’t strong enough.

Meta warned in its latest earnings report that without a legal basis for data transfers, it will be forced to stop offering its products and services in Europe, “which would materially and adversely affect our business, financial condition, and results of operations.”

The social media company might have to carry out a costly and complex revamp of its operations if it’s forced to stop shipping user data across the Atlantic. Meta has a fleet of 21 data centers, according to its website, but 17 of them are in the United States. Three others are in the European nations of Denmark, Ireland and Sweden. Another is in Singapore.

Other social media giants are facing pressure over their data practices. TikTok has tried to soothe Western fears about the Chinese-owned short video sharing app’s potential cybersecurity risks with a $1.5 billion project to store U.S. user data on Oracle servers.

Related: Facebook, GDPR and Max Schrems – Under the Hood of GDPR Legal Processes

Related: Open Banking: A Perfect Storm for Security and Privacy?

Related: Facebook Agrees to Pay $725 Million to Settle Privacy Suit

Related Content

CISO Conversations

SecurityWeek interviews Geoff Belknap, CISO at LinkedIn, and Guy Rosen, CISO at Facebook parent company Meta.

Vulnerabilities

Meta has patched a critical vulnerability that could have been exploited to take over any Facebook account via a brute-force attack.

Artificial Intelligence

Facebook and Instagram users will start seeing labels on AI-generated images that appear on their social media feeds, as the tech industry aims to...

Cybercrime

The Colombia office of the U.S. government agency that oversees foreign aid and development funding said its Facebook page was hacked and asked the...

Privacy & Compliance

End-to-End encryption in Facebook Messenger means that no one other than the sender and the recipient — not even Meta — can decipher people’s...

Threat Intelligence

Meta removed three foreign influence operations from the Facebook platform during Q3, 2023. Two were Chinese in origin, and one was Russian, the company...

Privacy

European privacy officials have widened a ban on Meta’s “behavioral advertising” practices to most of Europe.

Uncategorized

Britain's interior minister warned Meta that out end-to-end encryption on its platforms must "not to come at a cost to our children's safety".

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version