We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Meta's company logo outside the company's headquarters in Dublin city. Leah Farrell/Rolling News

Irish Data Protection Commission fines Meta €251m over Facebook data hacks

Ireland’s Data Protection Commission found multiple infringements of the rules known as the General Data Protection Regulation.

THE DATA PROTECTION Commission has announced that it has fined Facebook owner Meta €251m over a data protection failure that saw 29 million Facebook accounts hacked.

The Data Protection Commission (DPC) criticised Meta for a security flaw in its video upload function which hackers were able to exploit to gain full access to other users’ Facebook profiles.

Over a two week period in 2018, unauthorised users were able to hack into almost 30 million Facebook accounts globally, and had access to personal data including email addresses, phone numbers, locations and places of work.

Under the 27-nation EU’s strict privacy regime, Ireland’s DPC is Meta’s lead privacy regulator due to the company’s regional headquarters Dublin location.

“The failure to build in data protection requirements throughout the design and development cycle can expose individuals to very serious risks and harms, including a risk to the fundamental rights and freedoms of individuals,” said Graham Doyle, the regulator’s head of communications.

“By allowing unauthorised exposure of profile information, the vulnerabilities behind this breach caused a grave risk of misuse of these types of data,” he added.

Meta Ireland and its US parent company remedied the breach shortly after its discovery, the DPC said, and reported the issue to the regulator in September 2018.

It is the latest fine in a series issued to the US social media giant and its rivals, as global regulators crack down on tech companies.

Meta has said that it would appeal against the decision.

In September, the DPC fined Meta 91 million euros for failing to put measures in place to protect users’ password data and for taking too long to alert the regulator of the issue. 

Author
View 28 comments
Close
28 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.

    Leave a commentcancel

     
    JournalTv
    News in 60 seconds