Cybersecurity Policy Report, Irish High Court Upholds Fine Against Meta Over GDPR Violations, (May 26, 2026)
Organizations Mentioned:Facebook
By Tony Foley
An appeal of a fine issued last year by Ireland’s Data Protection Commission (DPC) against Meta Platforms Ireland Ltd. over violations of the European Union’s General Data Protection Regulation (GDPR) has been rejected by the High Court of Ireland.
Background. The DPC sanctions stemmed from a data access and portability request from an individual directed at Meta on May 25, 2018, the day the GDPR became effective, seeking access to his personal data stored on Facebook’s “Hive” data warehouse, not just the data made available via Facebook’s standard user tools. The individual requested the data in raw or original format, not merely summaries or curated extracts, and asked for sufficient contextual information to understand how the data was processed. The request sought to have the data delivered in a structured, machine-readable format to enable independent analysis and reuse. Facebook rejected the request, citing proportionality issues and other GDPR limitations.
The DPC preliminarily ruled in October 2025 that Meta violated articles 12, 15, and 20 of the GDPR by refusing to comply with the complainant’s request, providing inadequate information, refusing to provide the data in a manner consistent with GDPR data-portability requirements, and failing to meet GDPR’s time limits. The agency proposed a fine of 360 million to 430 million euros ($420 million-$500 million). In November 2025, Meta objected to the DPC’s preliminary ruling, maintaining that the process of the investigation was originally limited to the complainant but that the DPC incorrectly treated the complaint as raising issues of general application and arguing that the agency was not authorized under the GDPR to expand a complaint-based inquiry into systemic matters without formally opening an own-volition inquiry. The DPC rejected Meta’s objections in December 2025, after which Meta appealed to the High Court.
High Court ruling. In its Thursday decision in Meta Platforms Ireland Ltd. v. Data Protection Commission, the High Court dismissed Meta’s challenge, finding that in articles 57-58, the GDPR provides wide investigative and corrective powers to data protection authorities, including the obligation to investigate complaints to the extent appropriate. The court said a complaint-based inquiry could lawfully address systemic issues. Such a result does not convert a complaint-based inquiry into an own-volition process but rather reflects the DPC’s overarching obligation to ensure effective enforcement of the GDPR, the court said.
The High Court similarly held that GDPR article 83 requires administrative fines to be calculated with regard to the nature, gravity, and duration of the infringement and the number of data subjects affected, regardless of whether the proceedings originated from an individual complaint. Accordingly, the DPC’s significant fines were in line with the GDPR’s requirements that a fine should be proportionate and dissuasive, the court said. Finally, the court rejected Meta’s contention that the DPC’s ruling was procedurally unfair, noting that the company was fully on notice of the issues in the case and was not entitled to expect that it would be exempt from corrective measures of general application.
News: InternationalLegislation LitigationEnforcement DataPrivacy GDPR