Meta: €1.2B European Union (Ireland) privacy settlement

The largest GDPR fine on record: Meta was fined €1.2 billion by the Irish DPC for transferring EU user data to the US without an adequate legal basis after Schrems II — a structural reminder that international data transfers are still GDPR's hardest problem.

  • GDPR
  • European Union (Ireland)
  • Last updated

Enforcement snapshot

Amount
€1.2B
Regulator
Irish Data Protection Commission
Sector
Social media and advertising
Published
May 2023

Technical failure modes

What failed

01. Transfers without an adequate basis

Continued reliance on Standard Contractual Clauses (SCCs) post-Schrems II without sufficient supplementary measures.

02. No documented transfer impact assessment

The TIA — the document the EDPB expects every transfer to have — was either missing or insufficient for the volume of data involved.

03. No effective safeguards against US surveillance

The technical and organizational measures in place did not meaningfully limit US authorities' access to the transferred data.

04. Scale amplified the harm

Hundreds of millions of EU users meant the violation reached the upper bound of GDPR penalty exposure.

Next step

Do not wait for a demand letter to find the gap

The Meta decision is the marker case for international data transfers. SCCs alone are not enough; the Schrems II analysis requires real, documented assessments of US surveillance law and additional safeguards. The Data Privacy Framework changes the picture for some transfers, but not all of them — and not retroactively.

Get Started Free

Get started in less than 5 min