Site navigation

Does Meta’s £1bn Fine Set ‘Dangerous Precedent’ for US-EU Data Sharing?

Michael Edgar

,

Meta's £1bn fine
Meta received a record-breaking €1.2 billion (£1bn) fine from Irish regulators for its breach of GDPR data sharing policies. 

The fine was announced by Ireland’s Data Protection Commission (DPC) after a decade-long case which concluded Meta was transferring European users’ data in a way that created risks to the fundamental rights and freedoms of the users.  

Meta now has to stop the transfer of users’ data to America within five months, and remove EU user data from US servers within six months. Previously transferred data must also be transferred back to the EU.

The case began after the whistleblower Edward Snowden, uncovered the involvement in US big tech assisting the US’s National Security Agency’s surveillance apparatus. Which allowed the US government to access European data stored on US servers. 

The findings sparked a case of litigation against Meta – among many others – by activist groups beginning not long after in 2013. Meta had been in the clear largely due to the DPC deeming the use of standard contractual clauses (SCCs) a lawful way to send data to the US. 

However, this decision was rejected by the European Court of Justice (CJEU), which ordered the DPC to take action, causing them to  eventually deem SCCs as no longer a valid mechanism for transferring data.

This decision raises implications for other US-based cloud providers – such as Microsoft, Google, and Amazon – to lawfully share and receive data from Europe. Meta’s case also comes just over a year after Google was under fire for a similar breach of the EUs General Data Protection Regulations. The investigation found that despite efforts to regulate data transfers for Google Analytics, it was not sufficient to exclude US intelligence services from accessing the data. 

“This is not about one company’s privacy practices – there is a fundamental conflict of law between the US government’s rules on access to data and European privacy rights, which policymakers are expected to resolve in the summer,” said Nick Clegg, Meta’s head of global affairs.

However, according to Edward Machin, senior lawyer at Ropes & Gray, a data, privacy & cybersecurity practice, even if a new data transfer framework is agreed it will almost certainly be challenged before the European Court of Justice and there is a reasonably good chance that it will also be invalidated. “In the meantime, businesses on both sides of the pond are stuck in a groundhog day that will continue to cost significant time and money while not giving the legal certainty that surely isn’t too much to ask for at this point.”

Following the invalidation of SCCs for EU-US data transfers, lawmakers will now be under pressure to finalise a new framework before the end of the six-month transition period for Meta to comply, says Machin. 

Meta has said it will file an appeal with the Irish and European courts. However, the chances to have this decision overturned are low, according to the Austrian lawyer involved in campaigns against Meta with Austrian privacy advocacy group noyb, Max Schrems. “Past violations cannot be overcome by a new EU-US deal. Meta can at best delay the payment of the fine for a bit,” said Schrems.

“The DPC initially acknowledged that Meta had continued its EU-US data transfers in good faith, and that a fine would be unnecessary and disproportionate. However, this was overruled by the European Data Protection Board (EDPB), which also chose to disregard the clear progress that policymakers are making to resolve this underlying  issue,” said Clegg. “This decision is flawed, unjustified and sets a dangerous precedent for the countless other companies transferring data between the EU and US.”


Recommended


The case against Meta involved three court proceedings which together incurred legal costs exceeding €10m (£8.6m). The fine, however, will go to the Irish state, which Schrems says is “absurd” considering the DPC did everything to avoid a decision.

The DPC had avoided a decision for a decade, calling the case “frivolous” and forcing activists to appeal to the EDPB to overturn decisions. “The Irish regulator has done everything to avoid this decision, but was consistently overturned by the European Courts and institutions. It is kind of absurd that the record fine will go to Ireland,” commented Schrems. 

The fine, surpassing the former largest fine of €746m (£647m) given to Amazon in 2021, has the possibility to grow larger. The CJEU judgement allows users to claim emotional damages for data protection rights violations, leaving avenues open for class-action lawsuits. 

Meta has confirmed that there will be no imminent disruption to Facebook in Europe.

Michael Edgar

Staff Writer, DIGIT

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far