Privacy

Meta dodged a €4BN privacy fine over unlawful ads, argues GDPR complainant

Comment

facebook meta surveillance
Image Credits: Bryce Durbin / TechCrunch

A €390 million privacy fine for Meta announced earlier this month in the European Union — for running behavioral ads on Facebook and Instagram in the region without a valid legal basis — was several billion dollars smaller than it should have been, and orders of magnitude too tiny to be a deterrent for others going big on breaking the bloc’s privacy laws, according to the not-for-profit which filed the original complaint over Facebook’s ‘forced consent’ back in May 2018.

This week the privacy rights group, noyb, has written to the European Data Protection Board (EDPB) to raise fresh hell — arguing that the Irish regulator which issued the final decision on its complaint against Meta’s ads failed to follow the Board’s instructions to investigate the financial benefits it accrued off of the unlawful data processing.

It argues the Irish Data Protection Commission (DPC) has failed to implement the EDPB’s binding decision from December — which instructed the regulator to both find the legal basis Meta had claimed for running behavioral ads unlawful and significantly increase the size of the fine the DPC had proposed in its earlier draft decision.

In the final decision which the DPC issued earlier this month, the DPC declined to act on the Board’s direction to ascertain an estimate of the financial benefit Meta gained from targeting EU users with behavioral ads in breach of EU data protection law.

And while the Irish regulator did top-up the level of fine on Meta to €390 million — versus the €28 million to €36 million it had originally proposed for transparency failures — the revised fine neither reflects the seriousness of the systematic breach of European users’ fundamental rights, per noyb — nor does it implement the Board’s requirement that the DPC determine the unlawful financial benefits accrued by Meta from running ads that break EU privacy law.

Meta’s New Year kicks off with $410M+ in fresh EU privacy fines

noyb notes that, per EDPB guidelines on calculation of fines (and the text of the final decision put out by the DPC incorporating the Board’s binding decisions), the Irish regulator needed to ensure any fines “counterbalanc[e] the gains from the infringement” and also “impose a fine that exceeds that [unlawfully obtained] amount”.

In the absence of directions, the [DPC] is unable to ascertain an estimation of the matters identified above. Accordingly, I am unable to take these matters into account for the purpose of this assessment,” is how the DPC’s Helen Dixon dryly dismissed the EDPB’s instruction — a few lines of text that essentially let Meta off the hook on what noyb calculates should have been a penalty set at the maximum possible under the EU’s General Data Protection Regulation (GDPR): 4% of annual revenue. (Or over €4 billion in Meta’s case.)

noyb’s letter lays out how it has estimated the total revenue Meta generated, over the 4.5+ year infringement period, on users in the European Economic Area (EEA) — a figure it puts at circa €72.5 billion. It says it’s arrived at this estimate by looking at the publicly listed company’s financial reports (and adjusting revenue figures to only reflect users in the EEA, not the European continent as a whole) — querying why the DPC’s far more numerous staff couldn’t have done the same.

“While ‘behavioural advertisement’ does not make up all the revenue of Meta’s overall advertising, it is clear that in any realistic scenario, the revenue from ‘behavioural advertisement’ in the EU overshot the maximum [possible, under GDPR] fine of €4.36BN,” noyb also argues.

In a statement, its honorary chairman, Max Schrems, adds: “By not even checking publicly available information, the DPC gifted €3.97BN to Meta.”

“It took us an hour and a spread sheet to make the calculation,” he went on. “I am sure the Irish taxpayers would not mind having that extra cash, if a DPC employee would have just opened a search engine and done some research.

noyb’s letter also questions why the DPC apparently failed to use its statutory powers under the regulation to ask the data controller for any information required for the performance of its tasks — which could have provided it with a precise route to estimate how wealthy Meta got by unlawfully processing Europeans’ data.

“Given that SAs [supervisory authorities] can only fine based on the revenue of the last year, and the Irish DPC has taken more than 4.5 years to issue a final decision, Meta has made substantial revenue from violating the law, even if the maximum fine of 4% of the annual turnover is applied,” noyb goes on. “The estimated revenue from advertisements in the EEA of €72,53BN, would only be reduced to €68,17BN if the full 4% would be applied. This clearly makes even a maximum fine of 4% not even remotely ‘effective, proportionate and dissuasive’ in comparison to the unlawful revenue made by Meta IE [Ireland].

“Nevertheless the EDPB and the DPC are bound by Articles 83(1), (2)(k) and (5) GDPR at the same time, meaning that the maximum fine of 4% may not be overstepped but must also be used fully to comply with the conflicting requirements of the GDPR.”

So — tl;dr — even the maximum possible financial penalty under GDPR would not have been remotely dissuasive to Meta in financial terms — given how much more money it was minting by trampling all over European users’ privacy. Yet, the kicker is, Meta didn’t even get fined that (inadequate) maximum amount! Lol! 

noyb’s letter presents a neatly calculated and — frankly — damning assessment of high profile enforcement flaws in the GDPR. Flaws that enable Big Tech to play the system by forum shopping for ‘friendly’ regulators who can find endless ways to chew the cud around complaints and spin claims of protocol and procedure into a full blown dance of dalliance and delay, and whose convenient decisions can, at the last, be relied upon to help minimize any damage — in a cynical mockery of due process that’s turned the EU’s flagship data protection framework into a paper tiger where Big Tech’s users’ rights are concerned.

noyb is calling on the EDPB to take “immediate action” against the DPC — to ensure its binding decision “is fully implemented in [or, well, by] Ireland”.

“Given the clear evidence that Meta IE [Ireland] has profited from the violation of Article 6(1) GDPR in vast excess of the maximum fine of 4% under Article 83(5) GDPR and the Irish DPC’s clear breach of the binding decision in this respect, we urge the EDPB and its members to take immediate action against the Irish DPC to ensure that the EDPB decision is fully implemented in Ireland,” it urges.

However this (meta – ha!) complaint by noyb — about the outcome of its 2018 complaint about Meta’s ads — most likely lands at the end of the road as far as regulators are concerned. Next stop: Class-action style litigation?

noyb’s call joins a pile of complaints (and legal actions) targeting the Irish regulator’s failure to rigorously enforce the GDPR against abusive Big Tech business models — including litigation over inaction (also vis-à-vis the behavioral ads industry) and an accusation of criminal corruption (also from noyb), to name two of the barrage of slings and arrows fired at the DPC since the GDPR came into application (on paper) and complainants started the clock on their interminable wait for enforcement. 

The DPC was contacted for comment on noyb’s complaint to the EDPB — but it declined to offer a response.

We also reached out to the EDPB. A spokeswoman for the Board told us it “takes note” of noyb’s letter — but declined further comment at this time.

It remains to be seen what action — if any — the steering body will take. Its powers are limited in this context since its competence to intervene in the GDPR enforcement process relates to any objections raised to a lead supervisor’s draft decision (as happened in the Meta ads case).

After a final decision is issued the Board does not carry out a full re-evaluation of a case. So the chance of it being able to do much more here looks slim.

EU law enshrines the independence of Member States’ data protection regulators so the Board essentially has to work with whatever it’s given in a draft decision (and/or any objections raised by other DPAs). Which is why the DPC also sees mileage in challenging the portion of the Board’s binding decision that instructed it to further investigate Meta’s data processing — as it argues that’s jurisdictional overreach.

This structure effectively means a lead DPA can do considerable work to shape GDPR outcomes that impact users all over the bloc — by, for starters, minimizing what they investigate and then, even if they do open a probe, by narrowly scoping these enquiries and limiting what they factor into their preliminary decisions.

In the case of Meta, the DPC did not provide any data on the estimated financial benefit it amassed from its unlawful behavioral ads. Which — once again — looks terribly convenient for the tech giant.

While there’s not much Internet users can do about such a gaping enforcement gap — aside from hoping litigation funders step in and spin up more class-action style lawsuits to sue for damages on these major breaches — EU lawmakers themselves should be very concerned.

Concerned that a flagship piece of the EU’s digital rulebook — one that’s now also a key component at the heart of an expanding tapestry of regulations the bloc has been building up in recent years around data governance, to try to foster trust and get more data flowing in the hopes of fuelling a revolution in homegrown AI innovation — is proving to be such a jelly in the face of systematic law breaking.

Rules that can’t protect or correct aren’t going to impress anyone over the long run. And that means the paper tiger may yet have some teeth: If the GDPR enforcement failures keep stacking up, the sour taste that leaves for EU citizens tired of watching their rights trampled might risk toppling people’s trust in the whole carefully constructed ‘European project’.

EU lawmakers agree data reuse rules to foster AI and R&D

Europe proposes rules for fair access to connected device data

More TechCrunch

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

2 hours ago
A comprehensive list of 2024 tech layoffs

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

3 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

We just announced the breakout session winners last week. Now meet the roundtable sessions that really “rounded” out the competition for this year’s Disrupt 2024 audience choice program. With five…

The votes are in: Meet the Disrupt 2024 audience choice roundtable winners

The malicious attack appears to have involved malware transmitted through TikTok’s DMs.

TikTok acknowledges exploit targeting high-profile accounts

It’s unusual for three major AI providers to all be down at the same time, which could signal a broader infrastructure issues or internet-scale problem.

AI apocalypse? ChatGPT, Claude and Perplexity all went down at the same time

Welcome to TechCrunch Fintech! This week, we’re looking at LoanSnap’s woes, Nubank’s and Monzo’s positive milestones, a plethora of fintech fundraises and more! To get a roundup of TechCrunch’s biggest…

A look at LoanSnap’s troubles and which neobanks are having a moment

Databricks, the analytics and AI giant, has acquired data management company Tabular for an undisclosed sum. (CNBC reports that Databricks paid over $1 billion.) According to Tabular co-founder Ryan Blue,…

Databricks acquires Tabular to build a common data lakehouse standard

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following…

Worldcoin faces pivotal EU privacy decision within weeks

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

OpenAI fixes the issue that caused ChatGPT outage for several hours

True Fit, the AI-powered size-and-fit personalization tool, has offered its size recommendation solution to thousands of retailers for nearly 20 years. Now, the company is venturing into the generative AI…

True Fit leverages generative AI to help online shoppers find clothes that fit

Audio streaming service TuneIn is teaming up with Discord to bring free live radio to the platform. This is TuneIn’s first collaboration with a social platform and one that is…

Discord and TuneIn partner to bring live radio to the social platform

The early victors in the AI gold rush are selling the picks and shovels needed to develop and apply artificial intelligence. Just take a look at data-labeling startup Scale AI…

Scale AI founder Alexandr Wang is coming to Disrupt 2024

Try to imagine the number of parts that go into making a rocket engine. Now imagine requesting and comparing quotes for each of those parts, getting approvals to purchase the…

Engineer brothers found Forge to modernize hardware procurement

Raspberry Pi has released a $70 AI extension kit with a neural network inference accelerator that can be used for local inferencing, for the Raspberry Pi 5.

Raspberry Pi partners with Hailo for its AI extension kit

When Stacklet’s founders, Travis Stanfield and Kapil Thangavelu, came out of Capital One in 2020 to launch their startup, most companies weren’t all that concerned with constraining cloud costs. But…

Stacklet sees demand grow as companies take cloud cost control more seriously

Fivetran’s Managed Data Lake Service aims to remove the repetitive work of managing data lakes.

Fivetran launches a managed data lake service

Lance Riedel and Nigel Daley both spent decades in search discovery, but it was while working at Pinterest that they began trying to understand how to use search engines to…

How a couple of former Pinterest search experts caught Biz Stone’s attention

GetWhy helps businesses carry out market studies and extract insights from video-based interviews using AI.

GetWhy, a market research AI platform that extracts insights from video interviews, raises $34.5M

AI-powered virtual physical therapy platform Sword Health has seen its valuation soar 50% to $3 billion.

Sword Health raises $130M and its valuation soars to $3B

Jeffrey Katzenberg and Sujay Jaswa, along with three general partners, manage $1.5 billion in assets today through their Build, Venture and Seed strategies.

WndrCo officially gets into venture capital with fresh $460M across two funds

The startup targets the middle ground between platforms that offer rigid templates, and those that facilitate a full-control approach.

Storyblok raises $80M to add more AI to its ‘headless’ CMS aimed at non-technical people

The startup has been pursuing a ground-up redesign of a well-understood technology.

‘Star Wars’ lasers and waterfalls of molten salt: How Xcimer plans to make fusion power happen

Sēkr, a startup that offers a mobile app for outdoor enthusiasts and campers, is launching a new AI tool for planning road trips. The new tool, called Copilot, is available…

Travel app Sēkr can plan your next road trip with its new AI tool

Microsoft’s education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy rights nonprofit noyb has just lodged two complaints with Austria’s data…

Microsoft hit with EU privacy complaints over schools’ use of 365 Education suite

Since the shock of Russia’s 2022 invasion of Ukraine, solar energy has been having a moment in Europe. Electricity prices have been going up while the investment required to get…

Samara is accelerating the energy transition in Spain one solar panel at a time

Featured Article

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

It’s clear that this year will be a turning point for DEI.

1 day ago
DEI backlash: Stay up-to-date on the latest legal and corporate challenges

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

Hello and welcome back to TechCrunch Space. Unfortunately, Boeing’s Starliner launch was delayed yet again, this time due to issues with one of the three redundant computers used by United…

TechCrunch Space: China’s victory

The court ruling said that Fearless Fund’s Strivers Grant likely violates the Civil Rights Act of 1866, which bans the use of race in contracts.

An appeals court rules that VC Fearless Fund cannot issue grants to Black women, but the fight continues