
Meta, the parent company of Facebook, has been slapped with a substantial $100 million fine by the European Union (EU) due to serious privacy violations involving user passwords. The fine was imposed by the Irish Data Protection Commission (DPC), the EU’s leading privacy regulator, following a detailed investigation that uncovered that Meta had been storing users’ passwords in plaintext format, which poses a significant security risk.
The investigation was prompted by Meta’s own admission back in 2019 that some user passwords were stored in a readable format, a blatant breach of user privacy laws. While the DPC confirmed that there was no evidence of unauthorized access to these passwords, the very act of storing them improperly raises critical questions about Meta’s handling of sensitive user information.
In a response to the fine, Meta issued a statement emphasizing its proactive measures to address the issue and its cooperation with the DPC throughout the inquiry. “We took immediate action to fix this error, and there is no evidence that these passwords were abused or accessed improperly. We proactively flagged this issue to our lead regulator,” the statement read. However, the DPC reiterated that industry standards dictate that passwords must never be stored in plaintext due to the inherent risks involved.
The Irish DPC has increasingly become the main regulator for major US tech companies operating in Europe, and this fine adds to a growing list of penalties that Meta has faced in recent years. Notably, the company was previously fined $451 million for mishandling teen data on Instagram and $6.1 million for issues related to WhatsApp. Additionally, Meta faced a staggering $1.3 billion fine over concerns about data transfers to the United States.
This latest penalty underscores the EU’s commitment to enforcing strict data privacy regulations and serves as a stark reminder to all tech companies about the critical importance of safeguarding user data. The ongoing scrutiny of Meta and similar corporations highlights the need for adherence to privacy laws to protect user information and maintain public trust, especially in an age where data breaches are increasingly common. As companies navigate this landscape, ensuring robust data protection measures will be essential to avoid hefty fines and reputational damage.


















