Friday, January 24, 2025
HomeCyber Security NewsFacebook Hit With record-breaking $1.3 Billion Fine Over Data Rules

Facebook Hit With record-breaking $1.3 Billion Fine Over Data Rules

Published on

SIEM as a Service

Follow Us on Google News

Facebook (now Meta) has faced many allegations and litigations in the past 10 years. Most are related to privacy, data protection, and surveillance in other countries. However, a case that was filed against Facebook in 2013 was given a verdict. 

The case involves US mass surveillance against European Personal data and transferring of EU data to US data centers. According to the US Surveillance Law (FISA 702), Meta has been subject to the transfer of a large number of data over the past 10 years.

As per the European Court of Justice (CJEU), Meta will now have to pay a record fine of €1.2 billion and also return all the personal data to its EU data centers.

The whistle Blew in 2013

Edward Snowden blew the whistle about US surveillance in 2013, which created huge havoc against the NSA’s mass surveillance apparatus. Meta has been aware of the case that was filed against them in 2013 but did not take any precautions in the past 10 years.

The verdict also stated the reauthorization of the US Surveillance Law (FISA 702). Many Cloud providers like Microsoft, Google, and Amazon might face a similar fine if they do not comply with the European Data Protection Board  (EDPB). 

Other countries like Austria, France, and Italy have also felt the US services were unlawful but did not proceed with a major fine.

Irish DPC’s Protection Against Meta

It took nearly 10 years, 3 court proceedings, and 10 million euros to end up with the verdict while the Irish DPC was trying to protect Meta by all means. Initially, they rejected this case as “frivolous,” which had Mr. Schrems (the Austrian Activist) to get back to the CJEU. 

The DPC also tried to frame that Meta had used the “Standard Contractual Clause” henceforth, they cannot take any action against them. However, the claim was rejected by the CJEU, which made DPC provide the final shield to Meta by arguing to stop a fine and go with the deletion of data that was already transferred. The EDPB overturned it.

These court proceedings and the verdict have a shaky situation between the previous EU-US data deals (“Privacy Shield” and “Safe Harbor”), which had faced a lot of criticism.

Mr. Schrems stated, “Meta will appeal this decision, but there is no real chance to have this decision materially overturned. Past violations cannot be overcome by a new EU-US deal. Meta can, at best delay the payment of the fine for a bit. Meta plans to rely on the new deal for transfers going forward, but this is likely not a permanent fix. In my view, the new deal has maybe a ten percent chance of not being killed by the CJEU. Unless US surveillance laws gets fixed, Meta will likely have to keep EU data in the EU.”

Privacy must always be an option when it comes to sharing of a user’s data. The current generation depends entirely on “data,” which must be protected at all costs.

Shut Down Phishing Attacks with Device Posture Security – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

North Korean IT Workers Steal Companies Source Codes to Demand Ransomware

The Federal Bureau of Investigation (FBI) has issued fresh warnings about malicious activities by...

Zero-Click Outlook RCE Vulnerability (CVE-2025-21298), PoC Released

Microsoft issued a critical patch to address CVE-2025-21298, a zero-click Remote Code Execution (RCE)...

Critical Vulnerability in Next.js Framework Exposes Websites to Cache Poisoning and XSS Attacks

A new report has put the spotlight on potential security vulnerabilities within the popular...

New Cookie Sandwich Technique Allows Stealing of HttpOnly Cookies

The "Cookie Sandwich Attack" showcases a sophisticated way of exploiting inconsistencies in cookie parsing...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

North Korean IT Workers Steal Companies Source Codes to Demand Ransomware

The Federal Bureau of Investigation (FBI) has issued fresh warnings about malicious activities by...

Zero-Click Outlook RCE Vulnerability (CVE-2025-21298), PoC Released

Microsoft issued a critical patch to address CVE-2025-21298, a zero-click Remote Code Execution (RCE)...

GhostGPT – Jailbreaked ChatGPT that Creates Malware & Exploits

Artificial intelligence (AI) tools have revolutionized how we approach everyday tasks, but they also...