Meta fined R4.7 billion for data breach

Meta Platforms has been fined for failing to prevent half a billion users’ data to be leaked, to the tune of €265 million (nearly R4.7 billion). The fine was issues by the Irish Data Protection Commission after finding that Meta had failed to apply strict safeguards required under the bloc’s sweeping General Data Protection Regulation (GDPR).

Read: iPhone supply to fall 6 million units short amid protests

This is now the third biggest fine under GDPR, and includes a directive to Meta’s Irish unit to ensure its processing complies with the law. The Irish authority is the lead watchdog for some of Silicon Valley’s biggest tech firms that have set up an EU base in the country, including Meta.

The investigation started after a large dataset of Facebook personal data had been published to the internet by the hackers. It included the data of 533 million Facebook users around the world, which included their email addresses and phone numbers. The investigation looked into “Facebook Search, Facebook Messenger Contact Importer and Instagram Contact Importer tools in relation to processing carried out by Meta” between May 2018 and September 2019, the data protection commission said.

According to Meta, “protecting the privacy and security of people’s data is fundamental to how our business works”, and it will cooperate fully with the Commission. “We made changes to our systems during the time in question, including removing the ability to scrape our features in this way using phone numbers,” the company said. “Unauthorised data scraping is unacceptable and against our rules and we will continue working with our peers on this industry challenge. We are reviewing this decision carefully.”

GDPR came into effect in May 2018, which immediate upturned how data is managed and protected in the EU. It also gave the body the ability to fine businesses as much as 4 percent of a company’s annual sales if they have been found to be in breach of the regulation.