Meta privacy ruling and colossal fine
31st May 2023
Meta privacy ruling and colossal fine
“The sky is falling in. Well, probably not right now. But, the recent decision by Ireland’s data protection regulator to fine Meta 1.2bn Euros is potentially enormously significant for how UK-based organisations transfer personal data to the United States.”
Quite the start to the response from the DMA (Data & Marketing Association UK) regarding the recent ruling by the Data Protection Commission (DPC) of Ireland that figuratively dealt a colossal blow to data transfers between the European Union (EU) and the United States (US).
The ruling came in the form of a record-breaking fine and cease and desist order against Meta, the owner of Facebook.
The crux of the issue is around the fact that the data protection laws in the US are not as stringent as in the EU, specifically the fact that US Government Agencies are allowed to access the personal data of foreign nationals, which to some is seen as ‘spying’.
The case dates back ten years when privacy campaigner Max Schrems first took Facebook (now Meta) to court over its data protection practices. On his website, www.noyb.eu, Max Schrems made these comments:-
“Today (May 22, 2023), a decade-long (2013 – 2023) case on Meta’s involvement in US mass surveillance has led to a first direct decision. Meta must stop any further transfers of European personal data to the United States, given that Meta is subject to US surveillance laws.
Schrems added:
“We are happy to see this decision after ten years of litigation. The fine could have been much higher, given that the maximum fine is more than €4bn and Meta has knowingly broken the law to make a profit for ten years. Unless US surveillance laws get fixed, Meta will have to fundamentally restructure its systems.”
While this ruling does not directly impact data transfers between the UK and the US or the UK and EU due to Brexit, it raises crucial questions about varying privacy standards between countries outside the EU with commercial interests inside it.
Thousands of companies rely on EU standard contractual clauses (SCCs) as a legal mechanism to transfer data from the EU to the US. This is what Meta has been relying on. This is the legal way we have been told we can transfer data between the two continents.
Yet Meta has been told they have broken data protection laws because they fail to safeguard personal information. Does this, by extension, mean that no company can rely on SCCs any more – the very legal means legislators have given us for this purpose?
Perhaps it is fair to say that Meta is not ‘typical’ of most companies?
Their scale and their relationship with the authorities in the EU and the Government in the US are not ‘typical’.
One does wonder how far this ruling should be extended, though. Does it, by implication, affect other major firms such as Amazon, Google, LinkedIn, and Microsoft? Where do you draw the line?
We have already seen other Data Protection Authorities ban the flow of EU data to the US, for example, certain regions in Germany have ruled that Mailchimp in the US must not be used, and only this week the Belgian DPA ordered a ban on the transfer of tax data of US citizens residing in Belgium to the US. According to the Belgium DPA, the FATCA agreement, which provides for such transfers, is not in line with the GDPR, and the Belgian tax authority should have conducted an impact assessment.
The direction of travel is clear, but how far the UK will follow the EU is still unknown.
As far as Meta is concerned, it says it will appeal against the “unjustified and unnecessary” ruling.
Facebook Vice President, Global Affairs & Communications Nick Clegg (yes, that Nick Clegg, our former Deputy Prime Minister) said:
“We are . . . disappointed to have been singled out when using the same legal mechanism as thousands of other companies looking to provide services in Europe. . . . This decision is flawed, unjustified and sets a dangerous precedent for the countless other companies transferring data between the EU and the US.”
Nick Clegg on BBC.co.uk
The DPC has given Meta five months to halt the transfer of data from Europe to the US and an additional six months to stop the processing and storing of previously collected data in the US. This could require Meta to delete or move photos, videos, Facebook posts, and other data back to Europe.
The ruling has triggered concerns among businesses in the UK, especially those with customers in the EU and utilising cloud tech services hosted in the US. The Direct Marketing Association (DMA) is reviewing the case to understand its impact on UK companies and plans to provide guidance accordingly. We will keep you posted.
There is a bright spot on the horizon
Since the EU Court invalidated the previous EU-US data framework (Privacy Shield) in 2020, there has been a lack of clear guidelines for transatlantic data transfers.
There is currently a new ‘protocol / pact’ in front of the EU member states awaiting approval – which we hope will arrive this Summer (2023). This will be a replacement for Privacy Shield and will provide a new Trans-Atlantic Data Privacy Framework once it has been approved.
Legal experts and privacy groups have welcomed the ruling, recognising its significance in terms of data privacy, but unless the legal framework in the US is changed, we have our doubts that any resolution can be reached.
What actions should you take due to this Meta privacy ruling and colossal fine?
- Ensure you follow existing legislation regarding data transfer to the US using either EU SCCs or UK IDTAs to the LETTER.
- Avoid transferring data to the US if you can. (use Cloud services based in the UK or EU where possible, check email service providers, CRM systems etc.).
- Keep up to date with the changing legislation – ignorance is not a defence.
- Let’s all hope the new EU / US pact comes into effect swiftly this year.
Finally, and to quote Christopher Combemale, the Group CEO of the DMA once again:
“Don’t panic. We need not worry about the sky falling in. Yet.”
Please contact the data protection specialists here at Griffin House Consultancy if you require any help or advice. Everyone is entitled to a thirty-minute complimentary consultation. Book yours here.