Ireland’s Data Protection Commission fined Instagram, owned by Meta, €405m over its handling of children’s personal data. At the time it was the second-largest fine issued under the GDPR.
What happened
- The investigation found that teenagers who switched to business accounts had their email addresses and phone numbers displayed publicly.
- Accounts belonging to users aged 13 to 17 had been set to public by default.
- The final decision followed intervention by the European Data Protection Board, which pushed for a higher penalty.
- Meta said it disagreed with how the fine was calculated and planned to appeal.
Why it mattered
The fine signalled that European regulators would treat children’s privacy as a priority and would penalise design choices that expose young users. It followed a two-year inquiry by the DPC, which opened in 2020.
Lessons for organisations
Organisations whose services may be used by children should apply privacy by default and data minimisation, and use tools such as the UK Age Appropriate Design Code to guide product decisions. Default settings should protect users, with any exposure of contact details being a deliberate and informed choice.
Sources: Euronews, The Irish Times
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.