The court upheld findings that Amazon’s advertising processing lacked a valid legitimate-interest basis and that its transparency was insufficient. It annulled the 2021 decision’s fine and compliance order on procedural grounds.
- Status
- Confirmed
- Company
- Amazon
- Authority
- Luxembourg Administrative Court
- Decision date
- 12 March 2026
View caseReporting on a complaint involving a school account says the authority found that tracking cookies were placed without valid consent and that access rights were not handled correctly.
- Status
- Reported
- Company
- Microsoft
- Authority
- Austrian Data Protection Authority
- Event date
- 24 July 2025
View caseThe Commission found that Meta’s binary model required Facebook and Instagram users either to consent to combining personal data for personalised advertising or pay for an ad-free service. It did not offer the less-personalised but otherwise equivalent service required by the Digital Markets Act.
- Status
- Confirmed
- Company
- Meta
- Authority
- European Commission
- Decision date
- 23 April 2025
- Penalty
- €200,000,000
View caseA Facebook design flaw allowed attackers to obtain access tokens affecting about 29 million accounts. The regulator found failures in breach notification, documentation and data protection by design.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission
- Decision date
- 12 December 2024
- Penalty
- €251,000,000
View caseThe regulator examined LinkedIn’s legal bases for processing members’ data for behavioural analysis and targeted advertising. It found failures involving lawfulness, fairness and transparency.
- Status
- Confirmed
- Company
- Microsoft
- Authority
- Irish Data Protection Commission
- Decision date
- 22 October 2024
- Penalty
- €310,000,000
View caseMeta notified the regulator that some social-media user passwords had been stored in plaintext on internal systems. The inquiry assessed notification, documentation and security obligations.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission
- Decision date
- 26 September 2024
- Penalty
- €91,000,000
View caseTexas alleged that Facebook’s former Tag Suggestions feature captured facial geometry from photographs without the disclosures and consent required by state biometric-privacy law. The state brought the first case under its Capture or Use of Biometric Identifier Act.
- Status
- Confirmed
- Company
- Meta
- Authority
- Texas Attorney General
- Decision date
- 30 July 2024
View caseThe EDPB found an ongoing infringement involving processing for behavioural advertising on the basis of contract and legitimate interests across the European Economic Area.
- Status
- Confirmed
- Company
- Meta
- Authority
- European Data Protection Board
- Decision date
- 27 October 2023
View caseThe government alleged that Amazon retained children’s voice recordings indefinitely, disregarded deletion requests and used retained data to improve Alexa’s algorithms.
- Status
- Confirmed
- Company
- Amazon
- Authority
- United States Department of Justice and Federal Trade Commission
- Decision date
- 19 July 2023
- Penalty
- US$25,000,000
View caseThe FTC alleged that Ring gave employees and contractors broad access to customers’ videos and failed to implement basic security measures, enabling account takeovers and harassment.
- Status
- Confirmed
- Company
- Amazon
- Authority
- United States Federal Trade Commission
- Decision date
- 16 June 2023
View caseThe FTC charged that Microsoft collected personal information from children under thirteen during Xbox account creation before notifying parents and obtaining verifiable consent. The complaint also addressed incomplete parental notices, disclosures to game publishers and retention of children’s data after an account-creation process was abandoned.
- Status
- Confirmed
- Company
- Microsoft
- Authority
- United States Federal Trade Commission and Department of Justice
- Decision date
- 5 June 2023
- Penalty
- US$20,000,000
View caseThe Irish regulator found that Meta Ireland continued transferring Facebook users’ personal data to the United States without safeguards that addressed the risks identified by the Court of Justice of the EU.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission and European Data Protection Board
- Decision date
- 12 May 2023
- Penalty
- €1,200,000,000
View caseCNIL found that Bing placed an advertising cookie on users’ devices without valid consent when they visited the search engine. It also found that the site offered a one-click route to accept cookies but no equally direct route to refuse them.
- Status
- Confirmed
- Company
- Microsoft
- Authority
- French Data Protection Authority (CNIL)
- Decision date
- 19 December 2022
- Penalty
- €60,000,000
View caseThe inquiry followed the publication of a dataset containing Facebook users’ personal data that had been scraped from the service. The DPC examined whether Facebook Search, Messenger Contact Importer and Instagram Contact Importer had been designed and configured in line with data-protection-by-design and default requirements.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission
- Decision date
- 25 November 2022
- Penalty
- €265,000,000
View caseThe inquiry examined Instagram settings and the public disclosure of email addresses and phone numbers belonging to child users, including users of business accounts.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission and European Data Protection Board
- Decision date
- 2 September 2022
- Penalty
- €405,000,000
View caseThe DPC examined twelve Facebook data-breach notifications received during a six-month period in 2018. It found that Meta Platforms Ireland failed to put appropriate technical and organisational measures in place that would allow it to readily demonstrate how it protected EU users’ data in the context of those breaches.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission
- Decision date
- 15 March 2022
- Penalty
- €17,000,000
View caseCNIL found that visitors to facebook.com in France could accept cookies immediately but could not refuse them with comparable ease. Refusal required several additional actions, which the authority found affected users’ freedom of consent.
- Status
- Confirmed
- Company
- Meta
- Authority
- French Data Protection Authority (CNIL)
- Decision date
- 31 December 2021
- Penalty
- €60,000,000
View caseConsumer Reports compared workplace communication policies and identified broad collection and use terms that employees may be unable to negotiate.
- Status
- Context
- Company
- Microsoft
- Authority
- Consumer Reports Digital Lab
- Event date
- 1 September 2021
View caseThe DPC investigated how WhatsApp Ireland explained its processing to users and non-users, including the information it provided about data shared between WhatsApp and other Facebook companies. The European Data Protection Board resolved objections among supervisory authorities and instructed the DPC to reassess the proposed fine.
- Status
- Confirmed
- Company
- Meta
- Authority
- Irish Data Protection Commission
- Decision date
- 20 August 2021
- Penalty
- €225,000,000
View caseCNIL found that Amazon Europe Core placed advertising cookies on visitors’ devices before consent and provided inadequate information about their purpose. The authority also found that the mechanism offered to people arriving through an advertisement did not provide valid prior consent.
- Status
- Confirmed
- Company
- Amazon
- Authority
- French Data Protection Authority (CNIL)
- Decision date
- 7 December 2020
- Penalty
- €35,000,000
View caseThe FTC alleged that Facebook violated a 2012 privacy order by misleading users about control over their personal information and the handling of facial-recognition settings and phone numbers.
- Status
- Confirmed
- Company
- Meta
- Authority
- United States Federal Trade Commission
- Decision date
- 24 July 2019
- Penalty
- US$5,000,000,000
View caseA government-commissioned data protection impact assessment documented risks in diagnostic data sent by enterprise versions of Office and proposed measures for public-sector use.
- Status
- Context
- Company
- Microsoft
- Authority
- Dutch Ministry of Justice and Security
- Event date
- 7 November 2018
View caseThe FTC alleged that Microsoft made false or misleading statements about privacy and security in Passport, Passport Wallet and Kids Passport. The complaint addressed undisclosed collection, claims about purchase security and failures to implement reasonable procedures for preventing, detecting and auditing unauthorised access.
- Status
- Confirmed
- Company
- Microsoft
- Authority
- United States Federal Trade Commission
- Decision date
- 24 December 2002
View case