Site navigation

Over £730 Million GDPR Fines in 2022

Elizabeth Greenberg

,

GDPR fines 2022
Over 80% of GDPR violation fines levied in Europe in 2022 were paid by Meta.

As of December 2022, companies paid a total of £2.49 billion in fines for cases violating various data protection laws, according to Atlas VPN. 

Out of that, GDPR fines 2022 totaled to over £730 million, which is 36% lower than the £1.14bn paid in 2021. 

While many businesses failed to meet data compliance standards in the EU, Meta stands out as the most fined company of 2022. 

The majority of GDPR fines 2022 were paid by the social media conglomerate which struggled to uphold data protection laws across its many platforms. 

In Ireland, the Data Protection Commission (DPC), a GDPR enforcement authority, imposed a £356m fine against Instagram, which is owned by Meta. 

The violation concerned child users of Instagram, whose personal data, including email addresses and phone numbers were publicly exposed, and whose profiles were public-by-default. 

Facebook surmounted a £233m penalisation in Ireland, when the DPC found that users’ personal data were scraped from public profiles in 2018 and 2019, breaking two articles of the EU’s data protection laws. 

Moreover, the DPC issued a “reprimand and an order” forcing Meta to “bring its processing into compliance by executing a range of specified remedial activities within a specific deadline”.

The EU’s data protection regulations revolve not around company regulations but around user protection, allowing it to fine companies based outside of Europe.


Recommended


Any EU citizen is designated as a ‘data subject’ and therefore is protected by GDPR. 

Since the start of GDPR, Meta has paid about £1bn in fines. 

The EU is currently deliberating on if Meta’s terms of services are in violation of GDPR, which requires companies to allow users to opt in or out of unnecessary data services such as personalisation of ads. 

Meta includes the use of data for the personalisation of ads in its terms of service and does not allow users to opt out as part of its business model – this method of ‘forced consent’ may be forced to change depending on the decision.

The particular issues surrounding child users may influence how the UK proceeds with its own data protection legislation, as well as the Online Safety Bill, which specifically aims to safeguard children on the internet.


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data