Meta, Facebook’s parent company, on Monday (22 May) was fined a record €1.2bn under GDPR for unlawful data transfers to the US by Ireland’s data protection watchdog.
However, doubts remain over the consequentiality of the decision for user privacy, as a new EU-US data transfer agreement is set to be signed before Meta would actually have to delete user data from US servers.
Moreover, as with previous record-setting fines for US big tech companies under GDPR, Facebook still has numerous opportunities to appeal the fine, both under Irish law and at the European Court of Justice.
Under the conditions of the fine, Meta has until 12 November of this year to move back or delete user data from US servers, but is unlikely to actually have to comply. Since March 2022, EU and US officials have agreed on the political terms of the EU-US Data Privacy Framework (DPF), a data-transfer agreement set up to harmonise GDPR legislation with US data collection.
Originally slated to be signed in July of this year, Estelle Massé, campaigner at digital privacy NGO Access Now, told EUobserver that it is likely to be postponed to October — still in time for Facebook to not have to delete EU user data.
“This [decision] might not mean much for people’s rights,” Massé said. “In practice, it would mean that actually Facebook would have to do nothing, because they would have a new legal basis under which the data can move to the US and stay there.”
The €1.2bn fine is obviously a huge amount of money, but Massé expects that Meta’s stock won’t suffer from the setback. “They’ve been setting aside money for quite some time now in preparation for this fine,” she said. “Based on what they told their investors just a month ago, and what they were expecting [from this fine], I’m expecting Facebook stock to go up today.”




