Don’t do SECURITY. Do business SECURELY.

Ireland fines Instagram €405m over handling of children’s data

Ireland's Data Protection Commission fined Instagram €405m for exposing teenagers' contact details and making their accounts public by default.

Ireland’s Data Protection Commission fined Instagram, owned by Meta, €405m over its handling of children’s personal data. At the time it was the second-largest fine issued under the GDPR.

What happened

  • The investigation found that teenagers who switched to business accounts had their email addresses and phone numbers displayed publicly.
  • Accounts belonging to users aged 13 to 17 had been set to public by default.
  • The final decision followed intervention by the European Data Protection Board, which pushed for a higher penalty.
  • Meta said it disagreed with how the fine was calculated and planned to appeal.

Why it mattered

The fine signalled that European regulators would treat children’s privacy as a priority and would penalise design choices that expose young users. It followed a two-year inquiry by the DPC, which opened in 2020.

Lessons for organisations

Organisations whose services may be used by children should apply privacy by default and data minimisation, and use tools such as the UK Age Appropriate Design Code to guide product decisions. Default settings should protect users, with any exposure of contact details being a deliberate and informed choice.

Sources: Euronews, The Irish Times

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights