Administrative fine in the amount of EUR 17 million applied by Irish Data Protection Authority to Meta Platforms for the infringement of articles 5(2) and 24(1) GDPR
The National Center for Personal Data Protection (NCPDP), for information and application purposes, communicates about the administrative fine in the amount of EUR 17 million applied by Irish Data Protection Authority (SA) to Meta Platforms (formerly Facebook) for the infringement of articles 5(2) and 24(1) GDPR.
The Irish SA launched an inquiry of its own-volition, arising from receipt of a series of twelve data breach notifications in the period between 7 June – 4 December 2018. The purpose of the inquiry was to examine the extent to which Meta Platforms achieved compliance with the requirements of articles 5(2) and 24(1) GDPR.
Following investigations, the Irish SA found that Meta Platforms failed to have in place appropriate technical and organisational measures such as would enable it to readily demonstrate the security measures that it implemented in practice to protect EU users’ data, thus imposing an administrative fine of EUR 17 million.
The NCPDP, as national supervisory authority for personal data processing, emphasizes the responsibility of personal data controllers to comply with the provisions of legal framework on personal data protection and to ensure that personal data processing operations are in accordance with the legislation in force.