Meta’s €1.2B GDPR Fine: Transfers vs. Reality
Ireland's DPC fined Meta €1.2B over EU-US transfers that Schrems II had already doomed — the largest GDPR fine ever, ordering suspension and deletion. Transfer-governance lessons for security teams.
Ireland's DPC fined Meta €1.2B over EU-US transfers that Schrems II had already doomed — the largest GDPR fine ever, ordering suspension and deletion. Transfer-governance lessons for security teams.
In late February 2020, facial recognition startup Clearview AI confirmed that a misconfigured server had exposed its entire client list, days after a major newspaper investigation revealed the company had scraped more than three billion facial images from social networks and the open web to sell face search to police. The leaked list showed U.S. retailers, banks, and investors among users of a tool built on photos most people never knowingly gave. Cease-and-desist letters from Facebook and other platforms followed, along with GDPR complaints across Europe. This is how facial recognition's most aggressive company lost control of its own story in a matter of weeks.