{"id":16505,"date":"2023-05-25T16:18:42","date_gmt":"2023-05-25T16:18:42","guid":{"rendered":"https:\/\/businessadapter.es\/1-2-billion-penalty-to-meta\/"},"modified":"2024-12-11T10:44:18","modified_gmt":"2024-12-11T10:44:18","slug":"1-2-billion-penalty-to-meta","status":"publish","type":"post","link":"https:\/\/businessadapter.es\/en\/1-2-billion-penalty-to-meta\/","title":{"rendered":"<strong>1.2 billion penalty to Meta<\/strong>"},"content":{"rendered":"\n<h1><span style=\"color: #800000;\"><strong>1.2 billion penalty to Meta<\/strong><\/span><\/h1>\n<p style=\"text-align: justify;\"><strong><a href=\"https:\/\/www.meta.com\/es\/\" target=\"_blank\" rel=\"noopener\">META Ireland<\/a><\/strong> has been fined 1.2 billion euros by the <a href=\"https:\/\/www.dataprotection.ie\/\" target=\"_blank\" rel=\"noopener\">Irish Data Protection Authority<\/a> for non-compliance with <a href=\"https:\/\/businessadapter.es\/servicios\/proteccion-de-datos\/proteccion-datos-valencia\">data protection regulations<\/a>.<\/p>\n<p>It is undeniable that the figure is shocking, especially if we know that it is the largest fine ever imposed by a European authority.<\/p>\n<h3><span style=\"color: #800000;\"><strong>Reason for sanction to META Ireland<\/strong><\/span><\/h3>\n<p>META Ireland has been sanctioned for transferring personal data of European users of the social network <a href=\"https:\/\/es-es.facebook.com\/\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> to data centers in the United States, which were then used by the intelligence services of that country.<a href=\"https:\/\/www.meta.com\/es\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\" wp-image-5330 alignright\" src=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/09\/social-network-76532_640-300x199.png\" alt=\"\" width=\"549\" height=\"364\" srcset=\"https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/09\/social-network-76532_640-300x199.png 300w, https:\/\/businessadapter.es\/wp-content\/uploads\/2020\/09\/social-network-76532_640.png 640w\" sizes=\"(max-width: 549px) 100vw, 549px\" \/><\/a><\/p>\n<p>Therefore, the sanction is directed only at <a href=\"https:\/\/es-es.facebook.com\/\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> and not at <a href=\"https:\/\/www.instagram.com\/\" target=\"_blank\" rel=\"noopener\">Instagram <\/a>or <a href=\"https:\/\/www.whatsapp.com\/?lang=es\" target=\"_blank\" rel=\"noopener\">WhatsApp<\/a>.<\/p>\n<p>Moreover, these data transfers were, in the words of <a href=\"https:\/\/edpb.europa.eu\/sites\/default\/files\/files\/file1\/cv_jelinek_engl_en.pdf\" target=\"_blank\" rel=\"noopener\">Andrea Jelinek<\/a>, Chairman of the <a href=\"https:\/\/edpb.europa.eu\/about-edpb\/about-edpb\/edpb-chairmanship_es\" target=\"_blank\" rel=\"noopener\">European Data Protection Committee<\/a>, &#8220;systematic, repetitive and continuous&#8221;, taking into account that they involved a massive volume of data processing.<\/p>\n<p>The investigation began in 2020 and it has been this Monday when the final decision has been made known, so it has been a difficult case to solve due to the complexity of the situation, as well as the legal absences.<\/p>\n<h3><span style=\"color: #800000;\"><strong>Conclusions of the Irish sanctioning authority<\/strong><\/span><\/h3>\n<h4>First:<\/h4>\n<p>The level of protection of the U.S. legal system is not equivalent to the European legal system.<\/p>\n<h4>Second:<\/h4>\n<p>The standard contractual clauses drawn up in 2020 and 2021 are not sufficient to guarantee data protection at the European level in the face of US legislation.<\/p>\n<h4>Third:<\/h4>\n<p>Meta Ireland has no complementary measures to compensate for the inadequate protection provided by U.S. law.<\/p>\n<h4>Fourth:<\/h4>\n<p>The exceptions provided for in <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">Article 49 of the GDPR<\/a> do not apply to the transfer of data by META.<\/p>\n<h4>Fifth:<\/h4>\n<p>Meta Ireland has violated <a href=\"https:\/\/www.boe.es\/doue\/2016\/119\/L00001-00088.pdf\" target=\"_blank\" rel=\"noopener\">Article 46.1 of the GDPR<\/a> by transferring personal data to a third country, which does not provide adequate safeguards, as well as data subjects do not have enforceable rights and effective legal remedies.<\/p>\n<h3><span style=\"color: #800000;\"><strong>What is the penalty imposed on META Ireland?<\/strong><\/span><\/h3>\n<p>The Irish authority has decided the following:<\/p>\n<p>5-month <strong> deadline<\/strong>to stop transferring data from the EU to the US.<\/p>\n<p>-6 months <strong> to<\/strong>delete all shared European user data.<\/p>\n<p><strong>Impose<\/strong>a fine of 1.2 billion euros for non-compliance.<\/p>\n<h4><span style=\"color: #000000;\"><strong>Positioning of META Ireland<\/strong><\/span><\/h4>\n<p>Meta Ireland considers this decision to be an &#8220;unjustified and unnecessary fine&#8221; and will therefore appeal, as expected.<\/p>\n<p>META&#8217;s card up its sleeve at the moment is that, during the time it takes to appeal the Irish authority&#8217;s decision, the Trans-Atlantic Data Privacy Framework Agreement may see the light of day.<\/p>\n<h3><span style=\"color: #800000;\"><strong>What is the Trans-Atlantic Data Privacy Framework?<\/strong><\/span><\/h3>\n<p>Trans-Atlantic Data Privacy Framework is the framework agreement on data privacy that should govern the transfer of data between the EU and the US, under the standards of protection required by European regulations, through an adequacy process.<\/p>\n<p>After the cancellation of the <a href=\"https:\/\/businessadapter.es\/sentencia-contra-el-escudo-de-privacidad-ue-y-eeuu\/\">EU-US Privacy Shield<\/a> in July 2020, actions have been taken to regulate this situation because such transatlantic transfers continue to take place, and the problem of ensuring data protection is still present.<\/p>\n<p>Following the adoption of the framework agreement between the EU and the US in March 2022 on this subject, as well as the <a href=\"https:\/\/www.europarl.europa.eu\/thinktank\/es\/document\/EPRS_BRI(2022)739261\" target=\"_blank\" rel=\"noopener\">Executive Order (EO 14086)<\/a> issued by President Joe Biden on October 7, 2022, the following improvements were included in the guarantees for data protection by the US:<\/p>\n<p>&#8211;<strong>Limiting<\/strong>access to data by U.S. intelligence authorities to what is strictly necessary and proportionate for the purpose of protecting national security.<\/p>\n<p>-Strict <strong> supervision<\/strong>of the activities carried out by the U.S. intelligence services.<\/p>\n<p>&#8211;<strong>Creation<\/strong>of a specific, independent and impartial data protection court where data subjects can exercise their rights with respect to the processing of their data by the U.S. national security authorities.<\/p>\n<p>In February of this year, the European Data Protection Board<a href=\"https:\/\/edpb.europa.eu\/edpb_en\" target=\"_blank\" rel=\"noopener\">(EDPB<\/a>) applauded these improvements on the US side; however, it expressed some concerns related to commercial issues and government access to data transferred to the US from the EU.<\/p>\n<p>This Agreement has not yet been approved, and therefore is not yet in force, so we will have to wait for its publication, which is expected for the summer.<\/p>\n<h3><span style=\"color: #800000;\"><strong>Business Adapter\u00ae at your service  <\/strong><\/span><\/h3>\n<p>If you need advice, contact us by email: <a href=\"mailto:info@businessadapter.es,%20\">info@businessadapter.es, <\/a> you can also call <a href=\"http:\/\/tel.961318804\">96 131 88 04<\/a>, or leave your message in this form:<\/p>\n<p> <\/p>\n<p><strong>[su_button url=&#8221;https:\/\/businessadapter.es\/contacto&#8221; target=&#8221;blank&#8221; background=&#8221;#f6f903&#8243; color=&#8221;#181818&#8243; size=&#8221;7&#8243; center=&#8221;yes&#8221; icon_color=&#8221;#000000&#8243;]Contact us, we will be pleased to help you.[\/su_button]<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1.2 billion penalty to Meta META Ireland has been fined 1.2 billion euros by the Irish Data Protection Authority for [&hellip;]<\/p>\n","protected":false},"author":1373,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[75],"tags":[82,86],"class_list":["post-16505","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-compliance-with-lopd-and-rgpd","tag-data-protection-penalties"],"_links":{"self":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/users\/1373"}],"replies":[{"embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/comments?post=16505"}],"version-history":[{"count":1,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16505\/revisions"}],"predecessor-version":[{"id":16507,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/posts\/16505\/revisions\/16507"}],"wp:attachment":[{"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/media?parent=16505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/categories?post=16505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businessadapter.es\/en\/wp-json\/wp\/v2\/tags?post=16505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}