Privacy

Meta’s New Year kicks off with $410M+ in fresh EU privacy fines

Comment

Facebook CEO and founder Mark Zuckerberg
Image Credits: Saul Loeb / AFP / Getty Images

Meta is kicking off the New Year with more privacy fines and corrective orders hitting its business in Europe. The latest swathe of enforcement relates to a number of EU General Data Protection Regulation (GDPR) complaints over the legal basis it claims to run behavioral ads.

The Facebook owner’s lead data protection watchdog in the region, the Irish Data Protection Commission (DPC), announced today that it’s adopted final decisions on two of these long-running enquiries — against Meta-owned social networking site, Facebook, and social photo-sharing service, Instagram.

The DPC’s press release reveals financial penalties of €210 million (~$223 million) for Facebook and €180 million (~$191 milliion) for Instagram — and confirms the European Data Protection Board (EDPB)’s binding decision last month on these complaints that contractual necessity is not an appropriate basis for processing personal data for behavioral ads.

These new sanctions add to a pile of privacy fines for Meta in Europe last year — including a €265 million penalty for a Facebook data-scraping breach; €405 million for an Instagram violation of children’s privacy; €17 million for several historical Facebook data breaches; and a €60 million penalty over Facebook cookie consent violations — making for a total of €747 million in (publicly disclosed) EU data protection and privacy fines handed down to the adtech giant in 2022.

But now, in the first few days of 2023, Meta has landed financial penalties worth more than half last year’s regional total — and more sanctions could be coming shortly.

Corrective measures are also being applied, per the DPC’s PR — with Meta being ordered to bring its processing into compliance with the GDPR within three months.

This means it can no longer rely on a claim of contractual necessity to run behavioral ads — and will instead have to ask users for their consent. (And cannot profile and target users who do refuse its surveillance ads.)

Commenting in a statement, Max Schrems, the founder of the European privacy rights group (noyb) that filed the original GDPR complaints, said: “This is a huge blow to Meta’s profits in the EU. People now need to be asked if they want their data to be used for ads or not. They must have a ‘yes or no’ option and can change their mind at any time. The decision also ensures a level playing field with other advertisers that also need to get opt-in consent.”

Given how central Meta’s tracking and targeting ad model remains to its business, the tech giant is extremely likely to appeal the decisions — and if it does that it could open up fresh delays while legal arguments against the now-ordered enforcement play out in the courts. So there could still be years of wrangling ahead before Meta submits to correction via EU privacy law.

The DPC’s final decisions on these inquiries also still have not been published, so full details on differences of views between data protection authorities — and other interesting tidbits, such as on how the size of the fines have been determined — remain tbc.

But in a press release announcing the two final decisions, the DPC offers its own spin on the regulatory disagreements — writing:

On the question as to whether Meta Ireland had acted in contravention of its transparency obligations, the CSAs [concerned supervisory authorities] agreed with the DPC’s decisions, albeit that they considered the fines proposed by the DPC should be increased.

Ten of the 47 CSAs raised objections in relation to other elements of the draft decisions (one of which was subsequently withdrawn in the case of the draft decision relating to the Instagram service). In particular, this subset of CSAs took the view that Meta Ireland should not be permitted to rely on the contract legal basis on the grounds that the delivery of personalised advertising (as part of the broader suite of personalised services offered as part of the Facebook and Instagram services) could not be said to be necessary to perform the core elements of what was said to be a much more limited form of contract.

The DPC disagreed, reflecting its view that the Facebook and Instagram services include, and indeed appear to be premised on, the provision of a personalised service that includes personalised or behavioural advertising. In effect, these are personalised services that also feature personalised advertising. In the view of the DPC, this reality is central to the bargain struck between users and their chosen service provider, and forms part of the contract concluded at the point at which users accept the Terms of Service.

The DPC’s PR also confirms the EDPB found an additional breach by Meta of the GDPR fairness principle (i.e., in addition to the transparency breach the DPC found which the Board upheld) — hence it being directed to (further) increase the level of fines imposed.

A third decision against Meta-owned messaging platform WhatsApp (also over this legal basis issue) remains on the DPCs desk — but is slated to arrive in a week or so. (We’re told by the regulator this is owing to a short delay in the DPC receiving the binding decision on that complaint from the EDPB.)

noyb says it’s expecting a fine for WhatsApp in that parallel procedure to be announced in mid January.

Update: Meta has published a blog post with a response to the decisions in which it claims its choice of legal basis for processing people’s data for ads “respects GDPR.” It also says it plans to appeal the decisions — both on substance and the level of fines imposed.

“Facebook and Instagram are inherently personalised, and we believe that providing each user with their own unique experience – including the ads they see – is a necessary and essential part of that service,” Meta writes, echoing the DPC’s view that it’s ‘all or nothing’ when it comes to ad-supported ‘personalized’ services.

“To date, we have relied on a legal basis called ‘Contractual Necessity’ to show people behavioural advertisements based on their activities on our platforms, subject to their safety and privacy settings. It would be highly unusual for a social media service not to be tailored to the individual user,” it also argues — without mentioning that prior to switching to a claim of contractual necessity in 2018, ahead of the GDPR coming into application, it had relied upon a claim of user consent for ads processing.

Meta’s blog post also claims the DPC’s decisions do not prevent personalised advertising on its platform; and do not mandate the use of consent for ads-based processing.

“The suggestion that personalised ads can no longer be offered by Meta across Europe unless each user’s agreement has first been sought is incorrect,” it argues. “Similar businesses use a selection of legal bases to process data and we are assessing a variety of options that will allow us to continue offering a fully personalised service to our users.”

TikTok ‘pauses’ privacy policy switch in Europe after regulatory scrutiny

Enforcement on forced consent

This clutch of Meta-focused complaints dates back to May 2018, when the GDPR came into application across the European Union — after the European privacy rights campaign group, noyb, targeted the tech giant’s use of so-called “forced consent” (aka, pushing sign-up terms on users that mean they either ‘agree’ to their data being processed for behavioral ads or they can’t use the service).

The Irish regulator’s draft decision on the complaints leaked back in October 2021 — and, in contrast to the EDPB’s binding decision, the DPC did not object to Meta’s reliance on contractual necessity for running behavioral ads. Although it did find violations of the GDPR’s transparency requirements, saying users were unlikely to have understood they were signing up to a Facebook ad contract when they clicked agree on its terms of service.

Hence the DPC originally proposed a smaller penalty (of just $36 million) vs. the more than 10x larger financial sting in final decisions emerging now (still with the WhatsApp final decision pending).

This far tougher enforcement has been arrived at (albeit, slowly) through the GDPR’s cooperation mechanism — which loops in other EU data protection authorities (who can, and in this case several did, object to a lead supervisor’s draft decision); and casts the EDPB as final arbiter when regulators can’t agree among themselves. So, in this case (and not for the first time), the DPC has been instructed to reach a different outcome than if it had been left to decide alone.

And — as has happened several times before — the standard of enforcement flowing from a collective regulatory process baked into GDPR is higher (and tougher) than it would have been with Ireland acting on its own. 

The DPC’s press release frames the outcome rather differently — as a difference of legal interpretations — with the regulator writing that the EDPB “took a different view on the ‘legal basis’ question”; and adding: “The final decisions adopted by the DPC on 31 December 2022 reflect the EDPB’s binding determinations as set out above. Accordingly, the DPC’s decisions include findings that Meta Ireland is not entitled to rely on the ‘contract’ legal basis in connection with the delivery of behavioural advertising as part of its Facebook and Instagram services, and that its processing of users’ data to date, in purported reliance on the ‘contract’ legal basis, amounts to a contravention of Article 6 of the GDPR.”

It will be interesting to see whether Meta’s lawyers seek to make hay with the DPC’s (now publicly) stated view that Facebook and Instagram are “premised on, the provision of a personalised service that includes personalised or behavioural advertising” — and its (convenient-for-Meta) conflation of personalised services and personalised advertising via an expressed stance that such a conjoined pairing is “central to the bargain struck between users and their chosen service provider, and forms part of the contract concluded at the point at which users accept the Terms of Service”, as it puts it — as the tech giant seeks to overturn this GDPR decision against the legal basis it’s relied upon to run behavioral ads in the EU since 2018.

Curiously, the DPC’s view on this (and Meta’s!) ignores the existence of other forms of (non-privacy) violating ads which Meta could use to monetize its service — such as contextual ads.

Its PR is also silent on the question of whether Meta will be ordered to delete all the data it’s been illegally processing since 2018. But litigation funders are unlikely to ignore the opportunity to scale privacy class actions.

There’s further drama unfolding around the DPC’s announcement today, too: Schrems has tweeted to complain that the DPC told noyb it will not be sent the final decision until after Meta has had a chance to redact the document … “Never seen something like that in 10 years of litigation,” he added. “F*cking crazy.”

(Reminder: noyb filed a complaint of criminal corruption against the DPC back in 2021 — accusing the regulator of corruption and “procedural blackmail” in relation to attempts to shut down the public release of documents related to GDPR complaints so this issue was already more than fraught.)

In a press release of its own, noyb’s Schrems further hits out at what he described as the DPC’s “very diabolic public relations game” — writing: “Getting overturned by the EDPB is a major blow for the DPC, no[w] they seem to at least try to gain the public perception of this case. In 10 years of litigation I have never seen a decision only being served to one party but not the other. The DPC plays a very diabolic public relations game. By not allowing noyb or the public to read the decision, it tries to shape the narrative of the decision jointly with Meta. It seems the cooperation between Meta and the Irish regulator is well and alive — despite being overruled by the EDPB.”

In a further unusual move by the Irish regulator — which only looks set to crank up criticism of its friction-generating approach to GDPR enforcement — the DPC has announced it’s launching an annulment action against certain “jurisdictional” elements of the EDPB decision.

It told TechCrunch it’s not seeking to annul the Board’s decision on the consent vs. contractual necessity issue. Rather it claims it’s unhappy about other elements of the direction the Board issued, via the GDPR Article 65 dispute resolution process, and is accusing the steering body of overreaching its jurisdiction.

This action appears to have been instigated because the Board’s binding decision also directs the DPC to conduct what the Irish regulator couches as “a fresh investigation that would span all of Facebook and Instagram’s data processing operations and would examine special categories of personal data that may or may not be processed in the context of those operations.”

Such an investigation — were it to actually take place — could really drive a stake through the heart of Meta’s privacy-sucking business model in the EU, where legal experts have been warning for years the tech giant’s consent-less tracking and profiling of citizens is in breach of the bloc’s legal framework on data protection.

So it’s certainly interesting that the DPC is keen to avoid having to open a wide-ranging investigation of Meta’s data handling on the EDPB’s instruction.

Its PR states that the decisions it’s announced today “naturally do not include reference to fresh investigations of all Facebook and Instagram data processing operations that were directed by the EDPB in its binding decisions” — with the regulator explaining its objection thusly:

The EDPB does not have a general supervision role akin to national courts in respect of national independent authorities and it is not open to the EDPB to instruct and direct an authority to engage in open-ended and speculative investigation. The direction is then problematic in jurisdictional terms, and does not appear consistent with the structure of the cooperation and consistency arrangements laid down by the GDPR. To the extent that the direction may involve an overreach on the part of the EDPB, the DPC considers it appropriate that it would bring an action for annulment before the Court of Justice of the EU in order to seek the setting aside of the EDPB’s directions.

It remains to be seen what the EU’s General Court will make of the DPC’s complaint.

However a legal challenge by WhatsApp to an earlier EDPB binding decision on a separate GDPR inquiry — which also substantially dialled up the level of enforcement it would have faced from an earlier DPC draft decision — was ruled inadmissible by the court last month.

Meta’s behavioral ads will finally face GDPR privacy reckoning in January

WhatsApp challenge to decision that led to $267M GDPR fine tossed by EU court

More TechCrunch

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities

For Mark Zuckerberg’s 40th birthday, his wife got him a photoshoot. Zuckerberg gives the camera a sly smile as he sits amid a carefully crafted re-creation of his childhood bedroom.…

Mark Zuckerberg’s makeover: Midlife crisis or carefully crafted rebrand?

Strava announced a slew of features, including AI to weed out leaderboard cheats, a new ‘family’ subscription plan, dark mode and more.

Strava taps AI to weed out leaderboard cheats, unveils ‘family’ plan, dark mode and more

We all fall down sometimes. Astronauts are no exception. You need to be in peak physical condition for space travel, but bulky space suits and lower gravity levels can be…

Astronauts fall over. Robotic limbs can help them back up.

Microsoft will launch its custom Cobalt 100 chips to customers as a public preview at its Build conference next week, TechCrunch has learned. In an analyst briefing ahead of Build,…

Microsoft’s custom Cobalt chips will come to Azure next week

What a wild week for transportation news! It was a smorgasbord of news that seemed to touch every sector and theme in transportation.

Tesla keeps cutting jobs and the feds probe Waymo

Sony Music Group has sent letters to more than 700 tech companies and music streaming services to warn them not to use its music to train AI without explicit permission.…

Sony Music warns tech companies over ‘unauthorized’ use of its content to train AI

Winston Chi, Butter’s founder and CEO, told TechCrunch that “most parties, including our investors and us, are making money” from the exit.

GrubMarket buys Butter to give its food distribution tech an AI boost

The investor lawsuit is related to Bolt securing a $30 million personal loan to Ryan Breslow, which was later defaulted on.

Bolt founder Ryan Breslow wants to settle an investor lawsuit by returning $37 million worth of shares

Meta, the parent company of Facebook, launched an enterprise version of the prominent social network in 2015. It always seemed like a stretch for a company built on a consumer…

With the end of Workplace, it’s fair to wonder if Meta was ever serious about the enterprise

X, formerly Twitter, turned TweetDeck into X Pro and pushed it behind a paywall. But there is a new column-based social media tool in town, and it’s from Instagram Threads.…

Meta Threads is testing pinned columns on the web, similar to the old TweetDeck

As part of 2024’s Accessibility Awareness Day, Google is showing off some updates to Android that should be useful to folks with mobility or vision impairments. Project Gameface allows gamers…

Google expands hands-free and eyes-free interfaces on Android

A hacker listed the data allegedly breached from Samco on a known cybercrime forum.

Hacker claims theft of India’s Samco account data

A top European privacy watchdog is investigating following the recent breaches of Dell customers’ personal information, TechCrunch has learned.  Ireland’s Data Protection Commission (DPC) deputy commissioner Graham Doyle confirmed to…

Ireland privacy watchdog confirms Dell data breach investigation

Ampere and Qualcomm aren’t the most obvious of partners. Both, after all, offer Arm-based chips for running data center servers (though Qualcomm’s largest market remains mobile). But as the two…

Ampere teams up with Qualcomm to launch an Arm-based AI server

At Google’s I/O developer conference, the company made its case to developers — and to some extent, consumers — why its bets on AI are ahead of rivals. At the…

Google I/O was an AI evolution, not a revolution

TechCrunch Disrupt has always been the ultimate convergence point for all things startup and tech. In the bustling world of innovation, it serves as the “big top” tent, where entrepreneurs,…

Meet the Magnificent Six: A tour of the stages at Disrupt 2024

There’s apparently a lot of demand for an on-demand handyperson. Khosla Ventures and Pear VC have just tripled down on their investment in Honey Homes, which offers up a dedicated…

Khosla Ventures, Pear VC triple down on Honey Homes, a smart way to hire a handyman

TikTok is testing the ability for users to upload 60-minute videos, the company confirmed to TechCrunch on Thursday. The feature is available to a limited group of users in select…

TikTok tests 60-minute video uploads as it continues to take on YouTube

Flock Safety is a multibillion-dollar startup that’s got eyes everywhere. As of Wednesday, with the company’s new Solar Condor cameras, those eyes are solar-powered and use wireless 5G networks to…

Flock Safety’s solar-powered cameras could make surveillance more widespread

Since he was very young, Bar Mor knew that he would inevitably do something with real estate. His family was involved in all types of real estate projects, from ground-up…

Agora raises $34M Series B to keep building the Carta for real estate

Poshmark, the social commerce site that lets people buy and sell new and used items to each other, launched a paid marketing tool on Thursday, giving sellers the ability to…

Poshmark’s ‘Promoted Closet’ tool lets sellers boost all their listings at once

Google is launching a Gemini add-on for educational institutes through Google Workspace.

Google adds Gemini to its Education suite

More money for the generative AI boom: Y Combinator-backed developer infrastructure startup Recall.ai announced Thursday it has raised a $10 million Series A funding round, bringing its total raised to over…

YC-backed Recall.ai gets $10M Series A to help companies use virtual meeting data

Engineers Adam Keating and Jeremy Andrews were tired of using spreadsheets and screenshots to collab with teammates — so they launched a startup, CoLab, to build a better way. The…

CoLab’s collaborative tools for engineers line up $21M in new funding

Reddit announced on Wednesday that it is reintroducing its awards system after shutting down the program last year. The company said that most of the mechanisms related to awards will…

Reddit reintroduces its awards system

Sigma Computing, a startup building a range of data analytics and business intelligence tools, has raised $200 million in a fresh VC round.

Sigma is building a suite of collaborative data analytics tools