The European Commission has been fined €400 ($412) by the EU General Court for violating the bloc’s stringent General Data Protection Regulation (GDPR). This marks the first time the Commission, the European Union’s executive authority, has been penalised under its own data protection laws.
The case arose after a German citizen used the “Sign in with Facebook” option to register for an EU conference. The citizen’s personal data, including their IP address, browser details, and device information, was transferred to U.S.-based companies Meta Platforms and Amazon without proper safeguards.
The court ruled that this constituted a “sufficiently serious breach” of GDPR, which sets strict standards for protecting EU citizens’ data.
In a statement, the Commission acknowledged the ruling and stated it would carefully study the judgment and its implications.
Further, in a quote given to Reuters, a Commission spokesperson said “the Commission takes note of the judgment and will carefully study the Court’s judgment and its implications.”
Recommended reading
- Demystifying GDPR & AI: Safeguarding Personal Data in the Age of LLMs
- Meta Delays AI Training in Europe Following Regulatory Concern
- X’s Default Data Harvesting for AI Model Under Regulatory Scrutiny
GDPR is recognised as one of the most comprehensive data privacy regulations globally, imposing strict obligations on organisations managing EU citizens’ data. Non-compliance can result in fines of up to 4% of an organization’s annual revenue.
While companies like Meta have faced record-breaking fines for GDPR violations, including a €1.2 billion penalty in 2023, this ruling highlights that even EU institutions are not exempt from the law.





