Reason.com - Free Minds and Free Markets
Reason logo Reason logo
  • Latest
  • Magazine
    • Current Issue
    • Archives
    • Subscribe
    • Crossword
  • Video
  • Podcasts
    • All Shows
    • The Reason Roundtable
    • The Reason Interview With Nick Gillespie
    • The Soho Forum Debates
    • Just Asking Questions
    • The Best of Reason Magazine
    • Why We Can't Have Nice Things
  • Volokh
  • Newsletters
  • Donate
    • Donate Online
    • Donate Crypto
    • Ways To Give To Reason Foundation
    • Torchbearer Society
    • Planned Giving
  • Subscribe
    • Reason Plus Subscription
    • Print Subscription
    • Gift Subscriptions
    • Subscriber Support

Login Form

Create new account
Forgot password

Privacy

European Union Fines Meta $1.3 Billion Because of NSA Spying Programs

The record penalty seems to be based less on the Facebook parent company's lax data practices than the U.S. intelligence community's data-collection programs.

Joe Lancaster | 5.26.2023 3:00 PM

Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests
The National Security Agency's Maryland headquarters; Meta CEO Mark Zuckerberg speaks in front of the Facebook logo | Illustration: Lex Villena; Anthony Quintano
(Illustration: Lex Villena; Anthony Quintano)

Ireland's Data Protection Commission announced this week that Meta Ireland, the Irish subsidiary of Facebook parent company Meta, had violated privacy provisions of the General Data Protection Regulation (GDPR), a rule that went into effect in 2018. The GDPR mandated much stricter data privacy rules in the European Union (E.U.), which caused some growing pains upon implementation.

The Irish agency determined that Meta "transfer[red] personal data" from the E.U. to the U.S. in a manner that "did not address the risks to the fundamental rights and freedoms of data subjects," i.e. Europeans who use Facebook. It fined the social media firm 1.2 billion euros ($1.3 billion USD), the E.U.'s largest penalty on record.

But the fine seems to be based less on Meta's carelessness with customer data than the U.S. intelligence community's snooping practices.

Controversy over transatlantic data transfers goes back a decade, to Edward Snowden's disclosures about U.S. National Security Agency (NSA) spying programs. Among Snowden's revelations was PRISM, a program that according to The Verge "allows [intelligence agencies] to expedite court-approved data collection requests" of tech companies. Rather than a traditional warrant from a judge which would be susceptible to open records laws, the intelligence community largely relied on classified orders from the Foreign Intelligence Surveillance Court.

Data transfers between the U.S. and Europe had generally been allowed under a "safe harbor" legal framework since 2000. But key to that agreement was an understanding that all parties involved would generally safeguard users' privacy, and in the aftermath of the Snowden disclosures, the E.U. Court of Justice threw out the agreement in 2015. The parties formed a new agreement, known as the E.U.-U.S. Privacy Shield, the following year, but in 2020, the Court invalidated that agreement as well, again citing NSA spying programs. Meta's actions at issue would have been acceptable under the Privacy Shield but were no longer allowed after it was struck down.

The new judgment contains no allegations of specific data breaches, which one would expect with a penalty of over $1 billion. The Federal Trade Commission (FTC), for example, assessed a fine of between $575 million and $700 million against credit bureau Equifax after a 2017 data breach that exposed 147 million people's personal information. The FTC also hit Facebook with a $5 billion fine in 2019 for misuse of user data for the Cambridge Analytica scandal (a saga which, in retrospect, produced much more smoke than fire).

Rather, Meta's fine came as a result of the potential breach of information that could result from U.S. intelligence agency snooping. As Mike Masnick wrote at Techdirt, Meta was penalized because "it transferred some EU user data to US servers. And, because, in theory, the NSA could then access the data. That's basically it. The real culprit here is the US being unwilling to curb the NSA's ability to demand data from US companies."

As always, Meta can handle the fine: The company reported $116.6 billion in revenues last year. But smaller companies may not have that luxury. When countries pass onerous privacy regulations just to protect their citizens' data from the intelligence community's prying eyes, that cost is borne not by the spy agencies themselves but by the small companies forced to comply.

Start your day with Reason. Get a daily brief of the most important stories and trends every weekday morning when you subscribe to Reason Roundup.

This field is for validation purposes and should be left unchanged.

NEXT: These Murders Don't Fit Into the Culture War

Joe Lancaster is an assistant editor at Reason.

PrivacyFacebookEuropean UnionData CollectionNSAPenaltiesIrelandFinesEuropeSocial MediaRegulationSurveillance
Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests

Show Comments (34)

Latest

Brickbat: Cooking the Books

Charles Oliver | 5.9.2025 4:00 AM

The App Store Freedom Act Compromises User Privacy To Punish Big Tech

Jack Nicastro | 5.8.2025 4:57 PM

Is Shiloh Hendrix Really the End of Cancel Culture?

Robby Soave | 5.8.2025 4:10 PM

Good Riddance to Ed Martin, Trump's Failed Pick for U.S. Attorney for D.C.

C.J. Ciaramella | 5.8.2025 3:55 PM

Trump's Tariffs Are Already Raising Car Prices and Hurting Automakers

Joe Lancaster | 5.8.2025 2:35 PM

Recommended

  • About
  • Browse Topics
  • Events
  • Staff
  • Jobs
  • Donate
  • Advertise
  • Subscribe
  • Contact
  • Media
  • Shop
  • Amazon
Reason Facebook@reason on XReason InstagramReason TikTokReason YoutubeApple PodcastsReason on FlipboardReason RSS

© 2024 Reason Foundation | Accessibility | Privacy Policy | Terms Of Use

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

r

Do you care about free minds and free markets? Sign up to get the biggest stories from Reason in your inbox every afternoon.

This field is for validation purposes and should be left unchanged.

This modal will close in 10

Reason Plus

Special Offer!

  • Full digital edition access
  • No ads
  • Commenting privileges

Just $25 per year

Join Today!