European Commission hit by EU court fine after breaking own data privacy rules

European Union
(Image credit: Shutterstock.com)

  • European Commission fined for breaking GDPR
  • EU General Court levies fine for failing to protect EU data
  • A German citizen was paid 400 euros

The European Commission has been forced to pay a 400 euro ($412) fine to a German citizen for breaking its own data protection regulations.

The German citizen used a “Sign in with Facebook” option on an EU conference registration page which subsequently sent information on the citizens’ IP address, web browser, and device to Meta Platforms and Amazon in the US.

The EU General Court concluded the European Commission had transferred personal data to the United States without proper safeguards, violating the EU’s stringent General Data Protection Regulation (GDPR).

EC violates GDPR

"The Commission takes note of the judgment and will carefully study the Court's judgment and its implications," a Commission spokesperson said (via Reuters).

The European Union has some of the strongest privacy protections in the world, with GDPR imposing rules on any organization that collects or manages personal data of EU citizens, with the ability to fine the organization up to 4% of their annual turnover in the event that they breach the regulations.

In 2024, Meta was hit by a $263 million fine for breaching GDPR in the 2018 Facebook data breach when the data on three million EU citizens was stolen by attackers who abused a bug in the “View as” profile function to steal access tokens and take over accounts.

Meta, continuing its string of annual GDPR violations, was also hit by a record $1.3 billion fine in 2023 for transferring EU data to the US, and a $259 million fine in 2022 for failing to protect the data of more than half a billion Facebook users.

The US does not have any principal data privacy regulations, with privacy regulations varying from state to state. The EU has been debating a key piece of legislation, known as the EU Cybersecurity Certification Scheme (EUCS), since 2020.

This legislation would provide a label to cloud computing companies that follow robust cybersecurity and privacy regulations, enabling them to process EU data outside of the bloc provided they safeguard the data to the same level required inside the EU.

You might also like

TOPICS
Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
GDPR
Meta hit with $263m fine over 2018 Facebook data breach
European Union technical background
Trump blasts EU regulators for targeting Meta, Apple and other US tech giants
European Union
Targeting citizens based on their political views is illegal, said EU data watchdog
Zuckerberg Meta AI
Zuckerberg asks Trump to stop US companies from having to pay EU fines
 In this photo illustration, the big tech companies Google, Apple, Meta, Amazon, Microsoft logos seen displayed on a mobile phone screen.
Big tech needs less than three weeks to pay off over $8 billion in 2024 fines
China flag and EU flag on cloudy sky. Waving in the sky
TikTok among six tech firms under fire for sending Europeans' personal data to China
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in News
Project Moohan prototype at Samsung Galaxy Unpacked, an XR goggles headset on display in a show area
Samsung's Android XR headset could avoid the Apple Vision Pro's biggest mistake, according to this leak
Rivian R1T
Big Rivian update delivers hands-off driving to rival Tesla Autopilot – and a new 'Rally' mode
Google Pixel 9 in Wintergreen showing back camera bar
The Google Pixel 10 could get a big camera boost if this new leak is legit
The Samsung Galaxy S25 Edge, close up on the dual camera system, against a marbled background
The Samsung Galaxy S25 Edge is being tipped to come with a sweet Google Gemini deal
Diego Luna looks questioningly at the back of someone's head as Cassian Andor in the show Andor
Disney+ is making Andor free to stream on YouTube, and now you have no excuse not to watch the best Star Wars show
Matt Murdock and Kirsten McDuffie standing in a court room in Daredevil: Born Again
Daredevil: Born Again episode 3 contains another Marvel reference to Spider-Man, but it's got nothing to do with Tom Holland's Peter Parker