Meta Platforms Inc., the parent company of Facebook, has been handed a substantial fine of €91 million (approximately $101.5 million) by Ireland’s Data Protection Commission (DPC). This penalty stems from a significant security breach in 2019, where Meta failed to protect the passwords of hundreds of millions of Facebook users by storing them in plaintext on its servers.
The DPC initiated a statutory inquiry into the incident in April 2019 under the European Union’s General Data Protection Regulation (GDPR) after Meta disclosed the breach. The investigation revealed that Meta did not meet the stringent security standards mandated by the GDPR, primarily because the company neglected to encrypt user passwords. This oversight created a considerable risk, as unsecured passwords could potentially be accessed by unauthorized third parties, compromising users’ sensitive information.
In addition to failing to encrypt passwords, Meta was found to have violated GDPR protocols by not notifying the DPC of the breach within the required 72-hour timeframe after becoming aware of it. Furthermore, the company did not adequately document the breach, further exacerbating the severity of the violation. Deputy Commissioner Graham Doyle emphasized the gravity of the situation, stating, “It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data. It must be borne in mind, that the passwords the subject of consideration in this case, are particularly sensitive, as they would enable access to users’ social media accounts.”
This fine significantly surpasses a previous penalty of €17 million imposed by the DPC in March 2022 for a 2018 security breach that affected up to 30 million Facebook users. The substantial increase in the fine reflects the larger scale of the 2019 breach, which exposed the passwords of hundreds of millions of users compared to the earlier incident. The GDPR allows data protection authorities to issue fines based on factors such as the nature, gravity, and duration of the infringement, the scope or purpose of the data processing, and the number of data subjects affected, among other considerations.

Despite the hefty fine, it represents only a fraction of what Meta could potentially face under GDPR, which permits penalties of up to 4% of a company’s global annual turnover. Given Meta’s impressive revenue of $134.90 billion in 2023, the company could theoretically be liable for fines in the billions, underscoring the significant financial risks associated with non-compliance.
The DPC’s latest sanction highlights ongoing concerns regarding Meta’s commitment to privacy compliance. The company has accumulated a majority of the largest GDPR penalties among tech giants, signaling persistent challenges in adhering to data protection regulations. This pattern of fines emphasizes the critical importance of robust data security measures and timely breach notifications to protect user information and maintain regulatory compliance.
Meta has faced numerous scrutiny over its data handling practices, and this latest fine serves as a stark reminder of the consequences of inadequate data protection. As regulatory bodies like the DPC continue to enforce GDPR rules rigorously, companies must prioritize data security and transparency to avoid similar penalties in the future.
In conclusion, Meta’s €91 million ($101.5 million) fine for the 2019 breach that exposed hundreds of millions of Facebook passwords underscores the critical importance of data protection and regulatory compliance in today’s digital landscape. As the company grapples with the financial and reputational repercussions of this incident, it remains to be seen how Meta will address its ongoing privacy challenges and improve its data security protocols to prevent future breaches.

Your First 10 AI Skills
10 practical AI skills, copy-paste prompts and a 7-day plan to start using AI with confidence.
Download the guide →
