Privacy

How companies collect, use, secure and transfer personal data shapes people’s ability to participate in modern life without losing control of their information.

Documented records

23

Court confirms core Amazon GDPR findings but annuls €746 million fine

The court upheld findings that Amazon’s advertising processing lacked a valid legitimate-interest basis and that its transparency was insufficient. It annulled the 2021 decision’s fine and compliance order on procedural grounds.

Status
Confirmed
Company
Amazon
Authority
Luxembourg Administrative Court
Decision date
12 March 2026
View case

EU fines Meta €200 million over its consent-or-pay model

The Commission found that Meta’s binary model required Facebook and Instagram users either to consent to combining personal data for personalised advertising or pay for an ad-free service. It did not offer the less-personalised but otherwise equivalent service required by the Digital Markets Act.

Status
Confirmed
Company
Meta
Authority
European Commission
Decision date
23 April 2025
Penalty
€200,000,000
View case

Meta fined €251 million after Facebook token breach

A Facebook design flaw allowed attackers to obtain access tokens affecting about 29 million accounts. The regulator found failures in breach notification, documentation and data protection by design.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission
Decision date
12 December 2024
Penalty
€251,000,000
View case

Meta fined €91 million for storing passwords in plaintext

Meta notified the regulator that some social-media user passwords had been stored in plaintext on internal systems. The inquiry assessed notification, documentation and security obligations.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission
Decision date
26 September 2024
Penalty
€91,000,000
View case

Meta reaches $1.4 billion Texas biometric-data settlement

Texas alleged that Facebook’s former Tag Suggestions feature captured facial geometry from photographs without the disclosures and consent required by state biometric-privacy law. The state brought the first case under its Capture or Use of Biometric Identifier Act.

Status
Confirmed
Company
Meta
Authority
Texas Attorney General
Decision date
30 July 2024
View case

Amazon ordered to pay $25 million over children’s Alexa recordings

The government alleged that Amazon retained children’s voice recordings indefinitely, disregarded deletion requests and used retained data to improve Alexa’s algorithms.

Status
Confirmed
Company
Amazon
Authority
United States Department of Justice and Federal Trade Commission
Decision date
19 July 2023
Penalty
US$25,000,000
View case

Microsoft pays $20 million to settle Xbox children’s privacy charges

The FTC charged that Microsoft collected personal information from children under thirteen during Xbox account creation before notifying parents and obtaining verifiable consent. The complaint also addressed incomplete parental notices, disclosures to game publishers and retention of children’s data after an account-creation process was abandoned.

Status
Confirmed
Company
Microsoft
Authority
United States Federal Trade Commission and Department of Justice
Decision date
5 June 2023
Penalty
US$20,000,000
View case

Meta fined €1.2 billion over EU–US data transfers

The Irish regulator found that Meta Ireland continued transferring Facebook users’ personal data to the United States without safeguards that addressed the risks identified by the Court of Justice of the EU.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission and European Data Protection Board
Decision date
12 May 2023
Penalty
€1,200,000,000
View case

CNIL fines Microsoft €60 million over Bing cookies

CNIL found that Bing placed an advertising cookie on users’ devices without valid consent when they visited the search engine. It also found that the site offered a one-click route to accept cookies but no equally direct route to refuse them.

Status
Confirmed
Company
Microsoft
Authority
French Data Protection Authority (CNIL)
Decision date
19 December 2022
Penalty
€60,000,000
View case

Irish DPC fines Meta €265 million over Facebook data-protection design

The inquiry followed the publication of a dataset containing Facebook users’ personal data that had been scraped from the service. The DPC examined whether Facebook Search, Messenger Contact Importer and Instagram Contact Importer had been designed and configured in line with data-protection-by-design and default requirements.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission
Decision date
25 November 2022
Penalty
€265,000,000
View case

Instagram fined €405 million over children’s data

The inquiry examined Instagram settings and the public disclosure of email addresses and phone numbers belonging to child users, including users of business accounts.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission and European Data Protection Board
Decision date
2 September 2022
Penalty
€405,000,000
View case

Irish DPC fines Meta €17 million over breach-record accountability

The DPC examined twelve Facebook data-breach notifications received during a six-month period in 2018. It found that Meta Platforms Ireland failed to put appropriate technical and organisational measures in place that would allow it to readily demonstrate how it protected EU users’ data in the context of those breaches.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission
Decision date
15 March 2022
Penalty
€17,000,000
View case

CNIL fines Facebook Ireland €60 million over cookie refusal design

CNIL found that visitors to facebook.com in France could accept cookies immediately but could not refuse them with comparable ease. Refusal required several additional actions, which the authority found affected users’ freedom of consent.

Status
Confirmed
Company
Meta
Authority
French Data Protection Authority (CNIL)
Decision date
31 December 2021
Penalty
€60,000,000
View case

Irish DPC fines WhatsApp €225 million over transparency

The DPC investigated how WhatsApp Ireland explained its processing to users and non-users, including the information it provided about data shared between WhatsApp and other Facebook companies. The European Data Protection Board resolved objections among supervisory authorities and instructed the DPC to reassess the proposed fine.

Status
Confirmed
Company
Meta
Authority
Irish Data Protection Commission
Decision date
20 August 2021
Penalty
€225,000,000
View case

CNIL fines Amazon €35 million over advertising cookies

CNIL found that Amazon Europe Core placed advertising cookies on visitors’ devices before consent and provided inadequate information about their purpose. The authority also found that the mechanism offered to people arriving through an advertisement did not provide valid prior consent.

Status
Confirmed
Company
Amazon
Authority
French Data Protection Authority (CNIL)
Decision date
7 December 2020
Penalty
€35,000,000
View case

Facebook agrees to $5 billion FTC privacy settlement

The FTC alleged that Facebook violated a 2012 privacy order by misleading users about control over their personal information and the handling of facial-recognition settings and phone numbers.

Status
Confirmed
Company
Meta
Authority
United States Federal Trade Commission
Decision date
24 July 2019
Penalty
US$5,000,000,000
View case

FTC order resolves Microsoft Passport privacy and security claims

The FTC alleged that Microsoft made false or misleading statements about privacy and security in Passport, Passport Wallet and Kids Passport. The complaint addressed undisclosed collection, claims about purchase security and failures to implement reasonable procedures for preventing, detecting and auditing unauthorised access.

Status
Confirmed
Company
Microsoft
Authority
United States Federal Trade Commission
Decision date
24 December 2002
View case