Inquiry concerning the Department of Social Protection

The Data Protection Commission (DPC) has completed an inquiry into the Department of Social Protection’s (DSP) processing of biometric facial templates and the use of associated facial matching technologies as part of the Public Services Card (PSC) registration process, referred to as “SAFE 2 registration”.

Background

This own-volition inquiry, which commended in July 2021, follows a prior DPC investigation into certain aspects of the DSP’s processing of personal data in connection with the issuance of PSCs. That investigation resulted in legal proceedings, in which the DSP appealed an Enforcement Notice issued by the DPC, which were subsequently withdrawn. A joint agreement between the DPC and the DSP as well as the final investigation report from that inquiry were published in December 2021. The final investigation report stated that processing of personal data, including biometric data, by the DSP in respect of SAFE 2 registration was to be addressed separately by the DPC. The current inquiry was established to separately examine the processing of biometric data under SAFE 2 registration, as highlighted in the final investigation report.

Rationale for the Inquiry

SAFE 2 registration is mandatory for applicants seeking a PSC, which is required to access a range of DSP services, including welfare payments. Individuals who do not undergo SAFE 2 registration are unable to access these services. The process involves the collection, storage, and processing of biometric data, specifically facial templates, in relation to a substantial proportion of the population of the State. As biometric data is classified as special category data under the GDPR, it attracts enhanced protections and safeguards.

Given the nature and scale of the processing, the DPC considered that it was essential for the DSP to have a clear and precise legal basis for this processing, accompanied by appropriate safeguards to protect personal data and the fundamental rights of individuals.

Scope of the Inquiry

The inquiry focused on assessing whether:

  • the DSP had a valid lawful basis for collecting biometric data as part of SAFE 2 registration;
  • the DSP’s retention of biometric data collected as part of SAFE 2 registration was lawful;
  • the DSP had complied with its transparency obligations to data subjects; and
  • the Data Protection Impact Assessment conducted by the DSP for SAFE 2 registration was adequate.

Findings

The DPC’s decision found that the DSP:

  • Failed to identify a valid lawful basis for the collection of biometric data, thus infringing Articles 5(1)(a), 6(1), and 9(1) of the GDPR;
  • Consequently, unlawfully retained biometric data in breach of Article 5(1)(e) GDPR;
  • Did not provide data subjects with sufficiently transparent information about SAFE 2 registration, violating Articles 13(1)(c) and 13(2)(a) GDPR; and
  • Did not include required details in the Data Protection Impact Assessment, breaching Articles 35(7)(b) and (c) GDPR.

Corrective Powers Exercised

The DPC imposed the following sanctions:

  • A formal reprimand was issued to the DSP;
  • Administrative fines totalling €550,000 were imposed; and
  • An order was issued requiring the DSP to cease processing of biometric data related to SAFE 2 registration within nine months unless a valid lawful basis can be identified.

Additional Observations

The DPC noted that the findings and corrective measures do not challenge the principle or policy of SAFE 2 registration itself. Furthermore, the inquiry found no evidence of inadequate technical or organisational security measures implemented by the DSP in relation to biometric data processing.

The full decision[1] can be downloaded at this link: Inquiry into Department of Social Protection June 2025 (17MB, PDF).

 

[1] For completeness, the DSP has noted that the facial matching software provider referenced in the Decision is no longer the current provider in respect of the processing of biometric data that was the subject of the inquiry.

Inquiry into City of Dublin Education and Training Board (CDETB)

This decision arises from an own-volition inquiry that the DPC commenced in July 2019. The inquiry related to a personal data breach notified by City of Dublin Education and Training Board (‘CDETB’) in November 2018. CDETB is the state education and training authority for Dublin city and is also responsible for Student Universal Support Ireland (‘SUSI’), the national awarding authority for student grants.

Summary of the breach

SUSI was created in 2012 as a business unit of CDETB. CDETB, through SUSI, operates a website (https://www.susi.ie) on which third-level students can apply, and find information relating to their eligibility, for a higher education grant.

The breach, as notified to the DPC, arose due to a combination of two factors. Firstly, CDETB discovered that its webserver was retaining the personal data of student grant applicants who had uploaded information connected to their grant applications through CDETB’s website. Prior to this discovery, CDETB had assumed that personal data being submitted through its website were being emailed to the relevant SUSI team and were not been retained locally. Secondly, CDETB discovered that there was also malware present on the webserver, which presented a risk that the retained personal data had been unlawfully disclosed.

The breach impacted approximately 13,000 data subjects, identifiable by email address, who had submitted supplementary forms through the SUSI website during 2017 and 2018. The personal data impacted by the breach included names, surnames, birth dates, PPSNs, contact details, identification data and special categories of data (such as data revealing racial or ethnic origin and health data).

The DPC’s inquiry assessed CDETB’s technical and organisational measures for ensuring the security of the personal data that it processed, including whether it had carried out an appropriate risk assessment prior to its implementation of certain additional functionality to its website, and also examined CDETB’s compliance with its obligation to notify the breach to both the DPC and to affected data subjects.

Technical and organisational measures for security

The SUSI website was not originally intended to process personal data. Subsequently, in April 2017, CDETB added functionality to enable grant applicants to submit supplementary requests and information (including personal data) through the website. However, due to inadequate project scoping and risk assessment by CDETB, this information was stored locally on the webserver. The processing affected the personal data of a large number of individuals, so the DPC determined that the risks to be addressed in CDETB’s technical and organisational measures for security were high. As CDETB was not aware that personal data were being stored locally on the webserver, there were no technical and organisational measures in place to ensure that this personal data were being kept secure. The DPC’s inquiry found that, while CDETB had implemented a number of appropriate security measures, some significant failings and omissions were evident:

  • CDETB did not undertake a risk analysis to identify, analyse or address any threats to its processing activities in relation to the susi.ie website prior to the breach.
  • CDETB did not adequately archive access, event and error logs, did not undertake penetration testing and did not operate a web application firewall at the relevant time. 
  • CDETB did not carry out appropriate testing of its technical and organisational measures in order to evaluate their effectiveness and identify weaknesses.

While CDETB subsequently adopted a wide range of measures to remediate the deficiencies identified during the inquiry, the DPC found that CDETB had infringed Articles 5(1)(f), 32(1) and 32(2) GDPR at the material time by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data on its website, and by failing to assess the appropriate level of security.

Prompt notification of personal data breach

Article 33 GDPR requires data controllers to notify their supervisory authority of every personal data breach that is likely to pose a risk to rights and freedoms of persons. The notification must be made ‘without undue delay, and where feasible, not later than 72 hours after having become aware of it’.

CDETB informed the DPC that it became aware on 16 October 2018 that a breach relating to the security of the processing of personal data had occurred on its SUSI webserver. Following this discovery, CDETB commissioned an investigation into the breach. However, CDETB did not notify the DPC of the breach until 16 November 2018, approximately one month after it had become aware of it. CDETB’s notification to the DPC offered no explanation for this delay.

The DPC’s inquiry established that the personal data breach resulted in a risk to the rights and freedoms of data subjects which CDETB became aware of on 16 October 2018. The breach therefore became notifiable to the DPC at that time and CDETB was obliged to notify the DPC without undue delay. As CDETB did not notify the DPC of the breach until 16 November 2018, the DPC found that CDETB infringed Article 33(1) GDPR by failing to notify the DPC of the breach without undue delay.

Notification to data subjects

Article 34(1) GDPR requires data controllers to communicate a personal data breach to data subjects without undue delay, where the breach is likely to result in a high risk to the rights and freedoms of those data subjects. Article 34(4) GDPR requires data controllers to notify data subjects of a data breach where the relevant supervisory authority (in this case the DPC) requires the controller to do so, after the supervisory authority determines that it is necessary to do so having considered the likelihood of the personal data breach resulting in a high risk to data subjects.

CDETB initially informed the DPC that they would be informing affected data subjects of the data breach. However, CDETB subsequently stated that it would not notify data subjects of the incident until it had considered legal advice. CDETB would eventually inform the DPC that, as a result of receiving an incident report about the data breach, it was of the opinion that the risk to data subjects was low and therefore, there was no obligation to inform data subjects of the breach.

However, the DPC determined that due to the high number of data subjects affected and the broad nature of the personal data involved, there was a high risk to the data subjects concerned. The DPC found that CDETB was under an obligation to notify the affected data subjects without undue delay and that, by failing to do so, CDETB infringed Article 34(1) GDPR.

On 15 January 2019, the DPC issued CDETB with a formal direction under Article 34(4) GDPR to notify all affected data subjects of the breach. The DPC informed CDETB that, due to the nature of the breach and the nature of the personal data potentially impacted, the DPC considered that the risk posed to data subjects could be severe. However, CDETB declined to comply with the DPC’s direction at that time, because in CDETB’s view the threshold for notification to data subjects had not been met. CDETB did not communicate the personal data breach to the affected data subjects until 16 December 2020. As a result, the DPC found that that CDETB infringed Article 34(4) GDPR by failing to communicate the personal data breach to data subjects when required to do so by the DPC as its supervisory authority on 15 January 2019.

Corrective measures

The DPC exercised a number of corrective measures on foot of the infringements found in the inquiry. In deciding on the corrective measures to be exercised, the DPC took account of all required factors including the risks posed by the processing, the types of personal data and numbers of persons affected, as well as the remedial steps taken by CDETB. The DPC also had regard to section 141(4) of the Data Protection Act 2018, which sets a maximum of €1,000,000 for administrative fines that may be imposed on ‘public authorities’, a category that includes bodies such as CDETB.

Corrective measures exercised by the DPC were:

  • a reprimand to CDETB in respect of the infringements identified,
  • an order to CDETB to bring its processing into compliance with the GDPR’s security requirements and to report to the DPC on the steps taken,
  • an administrative fine of €50,000 in respect of CDETB’s infringement of Articles 5(1)(f), 32(1)(b), 32(1)(d) and 32(2) GDPR,
  • an administrative fine of €15,000 in respect of CDETB’s infringement of Articles 33(1) GDPR,
  • an administrative fine of €10,000 in respect of CDETB’s infringement of Article 34(1) GDPR, and
  • an administrative fine of €50,000 in respect of CDETB’s infringement of Article 34(4) GDPR.

However, the DPC commends the tenor and tone of CDETB’s engagement with the DPC since being presented with the DPC’s proposed findings in a draft version of its Decision. These fines, totalling €125,000, are substantially lower than the fining range proposed in the draft Decision, the maximum of which was €210,000. The final fines reflect the mitigation occasioned by CDETB accepting each of the findings of infringements set out in the draft Decision, acknowledging full responsibility for the breach, apologising to both the data subjects affected and the regulator and in proactively taking steps, without having specifically been directed to do so by the DPC, to reduce the likelihood of similar breaches occurring in future.

Key Takeaways

  • Carry out proper risk assessments when making changes to ICT systems in order to determine whether personal data may be impacted and to ensure proper organisational and technical security measures are put in place if so.
  • Act promptly and diligently in notifying data breaches to the DPC and to data subjects, where required – do not cause undue delay while awaiting the outcome of third party investigations in order to determine whether each risk threshold has been met; the controller is responsible for ensuring the required notifications are made without undue delay.
  • Where, as in this case, the DPC specifically directs that a breach be notified to data subjects pursuant to Article 34(4), controllers should act without delay in doing so.

The full decision is now available for download (20MB, PDF).

The corrigendum to the decision is also available for download (4.5MB, PDF)

Inquiries into Meta Platforms Ireland Limited (Token Breach)

On 12 December 2024, the Irish Data Protection Commission (‘DPC’) adopted final decisions in two own-volition statutory inquiries reprimanding Meta Platforms Ireland Limited (‘MPIL’) and imposing administrative fines. The DPC opened the inquiries in response to a personal data breach reported by MPIL (then known as Facebook Ireland Ltd) in September 2018. The inquiry was carried out in accordance with the Data Protection Act 2018 and Article 60 of the EU General Data Protection Regulation (‘GDPR’).

The decisions considered aspects of the fundamental right to data protection under Article 8 of the Charter of Fundamental Rights of the EU as given effect in the GDPR, including the controller’s obligation to report and maintain records of breaches, and to implement measures to protect personal data both by design and default.

Background to the Inquiries

The breach arose from MPIL’s use of user tokens in connection with certain features on the Facebook platform. User tokens are coded identifiers that can be used to verify the user of a platform or utility, and to control access to particular platform features and personal data of the user and their contacts. In 2017 MPIL introduced a new video uploading feature. When used in conjunction with Facebook’s ‘View As’ feature (which allows a user’s page to be viewed as another user would see it) and the ‘Happy Birthday Composer’, the video uploader would generate a fully permissioned user token that gave full access to the Facebook profile of that other user. That token could then be used to exploit the same combination of features on other accounts, allowing access to multiple users’ profiles and the data accessible through them. Between 14 and 28 September 2018 unauthorised persons used scripts to exploit this vulnerability and gained access to approximately 29 million Facebook accounts globally, of which approximately 3 million were based in the EU/EEA. Facebook security personnel were alerted to the vulnerability by an anomalous increase in video upload activity and removed the functionality that caused the vulnerability shortly thereafter. MPIL notified the DPC of the breach on 28 September 2018.

The DPC commenced inquiries to investigate compliance with aspects of the GDPR.

Summary of Findings: IN-18-10-1

 Number

 Article of the GDPR

 Findings

 1

Article 33(3)

MPIL’s breach notification did not include information about the breach that MPIL could and should have included. This included information on the nature of the breach, categories of data subjects affected by the breach, the categories of personal data records affected by the breach, and the likely consequences of the breach.

 2

Article 33(5)

MPIL failed to create a contemporaneous documentary record of the facts relating to the breach.

 

Summary of Findings: IN-18-11-1

Number

Article of the GDPR

Findings

1

Article 25(1)

MPIL failed to implement appropriate technical and organisational measures to ensure that processing was secure against attack and upheld the integrity and confidentiality principles. Separately from the vulnerabilities specifically attributable to the tokens, MPIL failed to make use of alternative and more appropriate measures to ensure that, by design, processing met the required standards of data protection.

2

Article 25(2)

In the context of the processing for which they were deployed, the tokens deployed by MPIL gave unnecessarily broad access to personal data of Facebook users. This failure to ensure that only personal data necessary for the specific purpose of the processing were processed infringed the principle of data protection by default.

Corrective Measures

Where the DPC makes a decision under section 111(1)(a) of the Data Protection Act 2018, it must also make a decision under section 111(2) as to whether a corrective power should be exercised in respect of the controller or processor concerned, and if so, the corrective power to be exercised.

Having considered the infringements of the GDPR as set out above, the DPC decided to exercise the following corrective powers, in accordance with Article 58(2) GDPR:

  • a reprimand, pursuant to Article 58(2)(b) GDPR, regarding the infringements identified in the Decision; and
  • administrative fines totalling €251 million, as follows:
    1. In respect of MPIL’s infringement of Article 33(3) GDPR, a fine of €8 million.
    2. In respect of MPIL’s infringement of Article 33(5) GDPR, a fine of €3 million.
    3. In respect of MPIL’s infringement of Article 25(1) GDPR, a fine of €130 million.
    4. In respect of MPIL’s infringement of Article 25(2) GDPR, a fine of €110 million

The purpose of the reprimand is to formally recognise the serious nature of the infringements in order to deter future similar non-compliance by MPIL and other controllers or processors carrying out similar processing operations. The infringements concerned the personal data of millions of Facebook users. Furthermore, the DPC found both infringements contributed to a risk of fraud, identity theft and spamming in respect of the data subjects, including children and other vulnerable persons.

In deciding to impose administrative fines totalling €251 million, the DPC gave due regard to the factors set out in Article 83(2) GDPR. The DPC also considered that the administrative fines met the requirements set out in Article 83(1) GDPR of being effective, proportionate and dissuasive.

Before adopting the Decisions, the DPC submitted drafts of them to the other European data protection supervisory authorities (‘Concerned Supervisory Authorities’ or ‘CSAs’) in September 2024, as required by Article 60(3) GDPR. The CSAs did not raise any objections under Article 60(4) GDPR to the draft decisions. Three comments were received from CSAs with regard to each of the draft decisions. The DPC had due regard to these comments, and to final submissions by MPIL, when finalising the Decisions for adoption.

 

The full decision IN-18-10-1 is now available for download (36MB, PDF).

The full decision IN-18-11-1 is now available for download (36MB, PDF).

Inquiry into Maynooth University

This decision arises from an own-volition inquiry that the DPC commenced in July 2019. The inquiry related a personal data breach notified by Maynooth University in November 2018.

The breach affected the email accounts of university employees and allowed unauthorised persons to gain control of up to six accounts. The unauthorised persons used their control of one account to create email rules that concealed messages received from certain addresses. By means of this, the unauthorised persons perpetrated a fraud, leading to a financial loss by one person whose email account had been affected. That person was subsequently compensated by Maynooth University for that loss. The DPC assessed Maynooth University’s technical and organisational measures for ensuring the security of personal data that it processed, and also examined compliance with the controller’s obligation to notify breaches promptly.

Technical and organisational measures for security

The DPC determined that the email system was used for a broad range of purposes affecting the general scope of activities carried out in Maynooth University including HR and related matters. The types of personal data processed included detailed identification, financial and contact information, as well as health and other sensitive categories of personal data. The processing affected the personal data of a large number of individuals, so the DPC determined that the risks to be addressed in Maynooth University’s technical and organisational measures for security were high. The DPC’s inquiry found that, while Maynooth University had implemented a number of appropriate security measures, some significant failings and omissions were evident:

  • Technical measures found by the DPC to be inadequate included failure to employ multi-factor authentication (‘MFA’) in appropriate situations, a lack of control of email configuration rules and inadequate measures to keep systems updated and prevent malware.
  • Organisational measures found to be inadequate included policies and staff training on email security and data protection, supervision of email use, password policy, and policies regarding the control and management of personal data breaches.

The DPC’s decision finds that Maynooth University’s technical and organisational measures did not properly address the risks posed by its processing, taking account of the nature of the personal data, the purposes for which it was used, and the numbers of persons affected. While Maynooth University subsequently adopted measures to remediate deficiencies identified during the inquiry, and compensated the victim of the financial fraud, the DPC determined that Maynooth University had infringed Articles 5(1)(f) and 32 GDPR by failing to ensure appropriate security for the personal data that it processed, and to implement appropriate technical and organisational measures to ensure such security.

Prompt notification of personal data breach

Article 33 GDPR requires data controllers to notify their supervisory authority of every personal data breach that is likely to pose a risk to rights and freedoms of persons. The notification must be made ’without undue delay, and where feasible, not later than 72 hours after having become aware of it’.

The DPC’s inquiry established that, while Maynooth University was aware at an early stage of all facts showing that a personal data breach had occurred which posed risks to persons’ rights and freedoms, it did not report the breach to the DPC until more than 3 weeks later. Instead, after discovering the breach, Maynooth University commissioned an external IT security advisor to report on it and the surrounding circumstances. The report confirmed that the breach should be notified to the DPC, but that step was not taken until 4 days after delivery of the report. The DPC noted that the purpose of requiring prompt notification of breaches includes enabling the supervisory authority to advise and direct action to protect persons from the considerable risks that can be posed by breaches. It followed that, by unnecessarily delaying notification of this breach, Maynooth University had infringed Article 33(1) GDPR.

Corrective measures

The DPC’s decisions on corrective measures took account of all required factors including the risks posed by the processing, the types of personal data and numbers of persons affected, as well as the remedial steps taken by Maynooth University. The DPC also had regard to section 141(4) of the Data Protection Act 2018, which sets a maximum of €1,000,000 for administrative fines that may be imposed on ‘public authorities’, a category that includes bodies such as Maynooth University.

Corrective measures taken by the DPC were:

  • a reprimand to Maynooth University in respect of the infringements identified,
  • an administrative fine of €25,000 in respect of the infringement of Article 5(1)f and 32(1) GDPR
  • an administrative fine of €15,000 in respect of the infringement of Article 33(1) GDPR,
  • an order to Maynooth University to bring its processing into compliance with the GDPR’s security requirements and to report to the DPC on the steps taken .

The full decision can be downloaded at this link: Inquiry into Maynooth University November 2024 - (PDF, 1.3MB)

Inquiry into Sligo County Council

This inquiry is one of a number of own-volition inquiries into a broad range of issues pertaining to surveillance technologies deployed by State authorities. The inquiry sought to assess whether Sligo County Council was processing personal data in compliance with the GDPR and the Data Protection Act 2018. The inquiry examined a number of the Council’s processing operations including its use of CCTV cameras in public places used for the purposes of prosecuting crime or other purposes.

The findings made in the decision include:

  • Findings that Sligo County Council lacked a valid legal basis for processing of personal data from CCTV and Automated Number Plate Recognition (ANPR) cameras.
  • Findings that Sligo County Council failed to erect appropriately worded and located signage in respect of the processing of personal data collected via CCTV cameras.
  • The other findings in the decision include infringements relating to Sligo County Council’s obligations to carry out data protection impact assessments, to maintain data logs for specific accesses to CCTV recordings, and to implement appropriate technical and organisational measures.

Corrective measures exercised:

  • A temporary ban on the processing of personal data through CCTV cameras and ANPR cameras at a number of locations until a valid legal basis can be identified.
  • An order to Sligo County Council to bring its processing of personal data into compliance taking certain actions specified in the decision.
  • A reprimand in respect of Sligo County Council’s infringement of section 79 of the Data Protection Act 2018.
  • An administrative fine of €29,500

For more information, you can download the full decision at this link: Inquiry into Sligo County Council November 2024 - (PDF, 7.6MB)

Inquiry into LinkedIn Ireland Unlimited Company

This Decision concerns an Inquiry by the Data Protection Commission (the DPC) into LinkedIn Ireland Unlimited Company (LinkedIn), a data controller with its main establishment in Ireland. The Decision relates to a complaint-based inquiry, which was commenced on 20 August 2018, following a complaint made by the French non-profit organisation, La Quadrature Du Net (the Complaint).

The Complaint was initially made to the French Data Protection Authority, on behalf of affected data subjects pursuant to Article 80(1) GDPR, and later transmitted to the DPC as lead supervisory authority for LinkedIn. The Complaint asserted that LinkedIn had processed certain personal data relating to the data subjects, for the purposes of behavioural analysis and targeted advertising (BA & TA), without a valid legal basis and in an unfair and non-transparent manner.

The DPC commenced a statutory inquiry (the Inquiry), on 20 August 2018, to examine LinkedIn’s compliance with Articles 5(1)(a), 6(1), 13(1)(c), 13(1)(d), 14(1)(c) and 14(2)(b) of the GDPR. The inquiry was commenced pursuant to Section 110 of the Data Protection Act 2018 (the 2018 Act).

Summary of Findings

The Decision concluded that:

  • LinkedIn could not validly rely on Article 6(1)(a) GDPR to process third party data of its members for the purpose of BA & TA, excluding analytics, on the basis that the consent obtained by LinkedIn was not freely given, sufficiently informed or specific, or unambiguous.
  • LinkedIn could not validly rely on Article 6(1)(f) GDPR for its processing of first-party data personal data of its members for BA and TA or third party data for analytics.
  • LinkedIn could not validly rely on Article 6(1)(b) GDPR to process first party data of its members for the purpose of BA & TA.
  • LinkedIn infringed Article 13(1)(c) and 14(1)(c) in respect of the information it provided to data subjects regarding its reliance on Article 6(1)(a), Article 6(1)(b) and Article 6(1)(f) as lawful bases.
  • LinkedIn infringed the principle of fairness in Article 5(1)(a) GDPR.

Corrective Measures

Under Section 113(4)(a) of the 2018 Act, where the DPC adopts a decision (in accordance with Section 113(2)(b)), it must, in addition, make a decision as to whether a corrective power should be exercised in respect of the controller or processor concerned and, if so, the corrective power to be exercised. Article 58(2) GDPR sets out the corrective powers that supervisory authorities may exercise in respect of non- compliance by a controller or processor.

Having carefully considered the infringements identified in the Decision, the DPC decided to exercise certain corrective powers in accordance with Section 115 of the 2018 Act and Article 58(2) GDPR. The corrective powers that the DPC decided were appropriate to address the infringements in the particular circumstances were:

  • Issuing a reprimand to LinkedIn in respect of its infringements of the GDPR identified in the Decision (i.e. Articles 5(1)(a), 6(1), 13(1)(c) and 14(1)(c) GDPR).
  • Imposing an order to LinkedIn to bring its processing into compliance with the GDPR. This order requires:
    • firstly, that LinkedIn to bring its Privacy Policy into compliance with Articles 13(1)(c) and 14(1)(c) GDPR as regards information provided on data processed pursuant to Articles 6(1)(a), 6(1)(b) and 6(1)(f) GDPR, if those legal bases continue to be relied upon by LinkedIn for the purposes of BA & TA and analytics;
    • secondly, that LinkedIn to take the necessary action to bring its processing of personal data for the purpose of BA & TA into compliance with Article 6(1) GDPR, in particular, to take the necessary action to address the findings in the Decision that LinkedIn did not validly rely in Articles 6(1)(a), 6(1)(b) and 6(1)(f) GDPR to carry out the identified processing.
  • Imposing three administrative fines totalling €310 million, which were effective, proportionate and dissuasive, as follows:
    • With regard to LinkedIn’s reliance on the lawful basis in Article 6(1)(a) GDPR, and in respect of LinkedIn’s infringements of Articles 5(1)(a) and 6(1) GDPR for the processing of third party data of its members for BA & TA without a valid lawful basis, a fine of €105 million.
    • With regard to LinkedIn’s reliance on the lawful bases in Articles 6(1)(b) and 6(1)(f) GDPR, and in respect of LinkedIn’s infringements of Articles 5(1)(a) and 6(1) GDPR for the processing of first party data of its members for BA & TA and third party data for analytics without a valid lawful basis, a fine of €110 million.
    • In respect of LinkedIn’s infringements of Article 13(1)(c) GDPR and 14(1)(c) GDPR, a fine of €95 million.

The DPC did not impose a separate fine for the infringement of the Article 5(1)(a) GDPR principle of fairness in circumstances where the infringement was based on conduct that the DPC had already fully taken into account in imposing separate administrative fines.

Prior to its adoption, the DPC submitted a draft of its decision to the Concerned Supervisory Authorities in July 2024, as required under Article 60(3) of the GDPR. The Concerned Supervisory Authorities did not raise any objections (for the purpose of Article 60(4) GDPR) to the draft decision.


For more information, you can download:

Inquiry into Meta Platforms Ireland Limited

On 26 September 2024, the Irish Data Protection Commission (DPC) adopted a final decision in an own-volition statutory inquiry, concerning the processing of user passwords on the Facebook service by Meta Platforms Ireland Limited (MPIL). The inquiry was carried out in accordance with the Data Protection Act 2018 and Article 60 of the EU General Data Protection Regulation (GDPR). The DPC was competent to act as lead supervisory authority for the processing at issue, pursuant to Article 56 GDPR.

The Decision considered particular aspects of the fundamental right to data protection under Article 8 of the Charter of Fundamental Rights of the EU, as expressed in the GDPR’s specific data protection rules concerning personal data breaches, and the obligation to ensure the security of personal data.

Background to the Inquiry Process

MPIL uses cryptographic and encryption techniques when storing users’ passwords, and does not store the individual characters that make up a password. On 21 March 2019, MPIL informed the DPC that it had inadvertently stored certain passwords of social media users in ‘plaintext’ on its internal systems. On 24 April 2019, the DPC commenced an own-volition inquiry in response to this issue.

Summary of Findings

 Number  Article of the GDPR  Findings
 1  Article 4(12) The Data Protection Commission found that each of the instances of plaintext password logging, as identified by MPIL on 7 January 2019 and 31 January 2019, constituted a personal data breach within the meaning of Article 4(12) GDPR.
 2  Article 33(1) The Data Protection Commission found that MPIL infringed Article 33(1) GDPR by failing to notify a personal data breach to the Data Protection Commission without undue delay and within 72 hours of the discovery on 31 January 2019 of the passwords stored in plaintext.
 3  Article 33(5) The Data Protection Commission found that MPIL infringed Article 33(5) GDPR on two occasions by failing to document the personal data breach discovered on 7 January 2019 and by failing to document the personal data breach discovered on 31 January 2019.
 4  Article 5(1)(f), 32(1) The Data Protection Commission found that MPIL did not comply with the requirements of Article 5(1)(f) GDPR and Article 32(1) GDPR (in particular having regard to Article 32(1)(b)) by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

 

Corrective Measures

Where the DPC makes a decision under Section 111(1)(a) of the Act, it must also make a decision under Section 111(2) as to whether a corrective power should be exercised in respect of the controller or processor concerned, and if so, the corrective power to be exercised.

Having considered the infringements of the GDPR as set out above, the DPC decided to exercise the following corrective powers, in accordance with Article 58(2) GDPR:

  • a reprimand, pursuant to Article 58(2)(b) GDPR, regarding the infringements identified in the Decision; and
  • three administrative fines totalling €91 million, as follows:
    1. In respect of MPIL’s infringement of Article 33(1) GDPR, a fine of €8 million.
    2. In respect of MPIL’s infringement of Article 33(5) GDPR, a fine of €8 million.
    3. In respect of MPIL’s infringements of Articles 5(1)(f) and 32(1) GDPR, a fine of €75 million.

The purpose of the reprimand is to formally recognise the serious nature of the infringements in order to deter future similar non-compliance by MPIL and other controllers or processors carrying out similar processing operations. The infringements concerned the personal data of tens of millions of Facebook users. Furthermore, the DPC found both infringements contributed to a risk of fraud, impersonation, spamming and potential financial or reputational loss in respect of the data subjects.

In deciding to impose three administrative fines totalling €91 million, the DPC gave due regard to the factors set out in Article 83(2) GDPR. The DPC also considered that administrative fines totalling €91 million met the requirements set out in Article 83(1) GDPR of being effective, proportionate and dissuasive.

Prior to its adoption, the DPC submitted a draft of its decision to the Concerned Supervisory Authorities in June 2024, as required under Article 60(3) of the GDPR. The Concerned Supervisory Authorities did not raise any objections under Article 60(4) GDPR to the draft decision. Four comments were received from CSAs with regard to the draft decision. The DPC had regard to these comments, and to a final submission by MPIL, when finalising the decision for adoption.

For more information, you can download:

Inquiry concerning Mediahuis Ireland Group Limited

The decision in this inquiry relates to a balancing between the fundamental right to data protection and the fundamental right to freedom of expression and information.


Summary of Inquiry

The DPC has completed a complaint based inquiry into MIG’s processing of personal data in relation to a series of news reports in the print and online editions of the Irish Independent, Herald and Sunday Independent newspapers. The purpose of the inquiry was to examine if any obligations on the controller arising under Articles 5(1)(a), 5(1)(c), 5(2), 6 and 9 GDPR had been engaged and, if engaged, whether MIG infringed those obligations in publishing the personal data relating to the Complainant as contained in the relevant newspaper articles.

As a preliminary issue, the DPC examined the jurisdiction of the DPC to conduct an inquiry into a media outlet in light of the exemption set out in section 43 of the Data Protection Act 2018 (‘the 2018 Act’). That section implements the requirements of Article 85 GDPR, to provide that ‘Member States shall by law reconcile the right to the protection of personal data pursuant to [GDPR] with the right to freedom of expression and information.’ The section exempts certain processing of personal information for journalistic purposes from compliance with certain provisions of the GDPR where compliance with the provision would be incompatible with the purpose of exercising the right to freedom of expression and information. The GDPR provisions to be considered include those related to the rights of data subjects, the obligations of controllers and the powers and functions of supervisory authorities.

The DPC held that the DPC has the power to use the provisions of the 2018 Act to inquire into a complaint which raises issues concerning potential infringements of the GDPR and which also directly and centrally engages a data controller’s freedom of expression right. 

Neither the GDPR nor the fundamental right to protection of an individual’s personal data contained in Article 8 of the EU Charter of Fundamental Rights are subordinate to the freedom of expression right.  Article 85 GDPR and section 43 of the 2018 Act expressly recognise the latter right, but also recognise that it must be weighed in individual cases against data protection rights. In some circumstances it may take precedence over certain GDPR provisions, including those related to the principles of processing (apart from the principle of integrity and confidentiality) contained in Article 5 GDPR and the requirement for lawfulness of processing contained in Article 6 GDPR.  The regulatory powers and functions granted by the GDPR may be avoided only to the extent that the exercise of those powers and functions would be incompatible with the exercise of the right to freedom of expression and information.  The potential incompatibility of certain GDPR provisions (including the supervisory and enforcement powers of the DPC) with the exercise of freedom of expression and information does not prevent, or is not inconsistent with, the DPC conducting an inquiry in order to assess the very applicability of the section 43 exemption.  Further, if the DPC finds that the exemption applies to the particular circumstances, then the DPC must carry out a further analysis to examine the extent to which section 43 curtails the exercise of the provisions listed in section 43(2) of the 2018 Act in the particular case.

In this inquiry, the DPC conducted a detailed analysis on the facts of the complaint, in which it carried out a balancing exercise to determine whether the processing of the complainant’s personal data by MIG in exercise of its right to freedom of expression and information for journalistic purposes was permitted because the application of certain GDPR provisions to prevent that publication would have been incompatible with such purposes. This required an assessment of where a fair balance lies between the freedom of expression right and the Complainant’s right to protection of her personal data.

The DPC examined the legal basis for journalistic expression in terms of the Irish Constitution in Article 40.6.1°(i), which sets out that the ‘education of public opinion’ is ‘a matter of such grave import to the common good’ and that the press has a ‘rightful liberty of expression’, along with the text of Article 10 of the European Convention of Human Rights, which highlights that the ‘exercise of the right to freedom of expression may be subject to formalities, conditions, restrictions or penalties as are prescribed by law and are necessary in a democratic society.’ The DPC analysed precedents from Irish decisions on conflict between the right of free expression and the right to privacy or data protection. The DPC then went on to apply case law of the Court of Justice of the EU and of the European Court of Human Rights in determining the appropriate balance of competing human rights.

Having regard to the totality of the evidence before it, the DPC found that the exemption under section 43(1) of the Data Protection Act 2018 applies to the reporting by MIG about which complaint was made by the Complainant, and the DPC therefore dismissed the Complaint under section 112(1)(b) of the Data Protection Act 2018.

Key Extracts from the Analysis

  1. The DPC has the power to use the provisions of the 2018 Act to inquire into a complaint which raises issues concerning potential infringements of the GDPR and which also directly and centrally engages a data controller’s freedom of expression right.  Neither the GDPR nor the fundamental right to protection of an individual’s personal data contained in Article 8 of the EU Charter are subordinate to the freedom of expression right.  Article 85 GDPR and section 43 of the 2018 Act (‘Section 43’) expressly recognise the latter right, but also that it must be weighed in individual cases against data protection rights, and may even take precedence over certain GDPR provisions, including those contained in Articles 5 and 6 GDPR [1] and the regulatory powers and functions granted by the GDPR to the extent that the exercise of those powers and functions would be incompatible with the exercise of the right to freedom of expression and information.  The potential incompatibility of certain GDPR provisions (including the supervisory and enforcement powers of the DPC) with the exercise of freedom of expression and information does not prevent, or is not inconsistent with, the DPC conducting an inquiry in order to assess the very applicability of the Section 43 exemption.  Further, if the DPC finds that the exemption applies, then the DPC must carry out a further analysis to examine the extent to which Section 43 curtails the exercise of the provisions listed in section 43(2) in the particular case.
  2. Article 85 and Section 43 make it clear that such restriction of the GDPR provisions would only be necessary in circumstances where the ‘compliance with the provision would be incompatible with [exercising the right to freedom of expression]’. By stating explicitly within the text of Section 43 that Article 5(1)(f) GDPR does not fall within the scope of any potential exemption, it is clear that Section 43 is not intended to exclude the full competency of the DPC to regulate compliance with the GDPR in all cases of journalistic processing.  It is accepted that the DPC would not have power to invoke certain aspects of its supervisory powers (and in particular its enforcement powers) as provided for under Chapter VI of the GDPR in some circumstances; but any such circumstances would need careful analysis to justify any restriction in the application of GDPR provisions provided to vindicate the data protection rights of data subjects. It is clear that the DPC may use its inquiry mechanism under the 2018 Act in order to conduct such assessments.
  3. This balancing assessment is a function granted to the DPC by Section 43 itself. It is within the power of the DPC to determine by inquiry whether the exemption under section 43(1) in fact applies to the processing activities of any controller, including MIG, by considering:
  • the purposes of the processing, i.e. is it for the purposes of exercising the freedom of expression right, for journalistic purposes and/or for the purposes of academic, artistic or literary expression; and
  • whether compliance with aspects of the provisions exempted under section 43(2) would be incompatible with exercising the right to freedom of expression and information or for the purpose of academic, artistic or literary expression.
  1. This Inquiry is the mechanism by which the DPC has considered it appropriate to conduct the relevant assessment in this case, using its powers under section 110 of the 2018 Act, given that the issues were raised as a result of a complaint made to the DPC.  The inquiry mechanism allows the DPC to make its assessment, and (in accordance with the requirements of fair procedures) present each side’s position (data subject and data controller) to the other and allow the parties concerned the facility to provide their reasoned views to the DPC.  If the DPC is satisfied that the exemption applies to the processing activities in question, having regard to the above factors, it can confirm if a controller has properly applied the exemption to the relevant processing activities and if the controller is exempted from complying with particular obligations under section 43(2) in respect of those processing activities. Therefore, the exemption cannot be used at the outset to exempt or prevent such analysis by the DPC as appears to be suggested by MIG, nor does it dictate the manner or mechanism by which this assessment is to be conducted.
  2. The test to establish the need for an inquiry is not whether the DPC has formed a view that there is a ‘suspected infringement’ of a relevant enactment. Rather, under sections 109(5), 109(5)(e) and 110 of the 2018 Act, and when the DPC considers that a complaint cannot be resolved amicably, it can cause such ‘inquiry as it thinks fit’ to be conducted into the complaint (section 109(5)(e)) and, in relation to the inquiry jurisdiction under section 110, the DPC ‘may, in order to ascertain whether an infringement has occurred or is occurring, cause such inquiry as it thinks fit to be conducted.’
  3. The DPC therefore has a broad discretion both as to whether to carry out an inquiry and as to the form and scope of such an inquiry. Once an inquiry has as its purpose ascertaining whether there has been or is an infringement of the GDPR or of the 2018 Act, the DPC may in undertake an inquiry.
  4. Section 43 of the 2018 Act (Data processing and freedom of expression and information) is the provision by which Irish law gives effect to the requirements of Article 85 GDPR.  It provides:-  
  • The processing of personal data for the purpose of exercising the right to freedom of expression and information, including processing for journalistic purposes or for the purposes of academic, artistic or literary expression, shall be exempt from compliance with a provision of the Data Protection Regulation specified in subsection (2) where, having regard to the importance of the freedom of expression right in a democratic society, compliance with the provision would be incompatible with such purposes.
  • The provisions of the Data Protection Regulation specified for the purposes of subsection (1) are Chapter II (principles), other than Article 5(1)(f), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries and international organisations), Chapter VI (independent supervisory authorities) and Chapter VII (cooperation and consistency).
  • The Commission may, on its own initiative, refer any question of law which involves consideration of whether processing of personal data is exempt in accordance with subsection (1) to the High Court for its determination.
  • An appeal shall, by leave of the High Court, lie from a determination of that Court on a question of law under subsection (3) to the Court of Appeal.
  • In order to take account of the importance of the right to freedom of expression and information in a democratic society that right shall be interpreted in a broad manner.
  1. Therefore, a two-part test is applicable to determine whether the exemption in Section 43 applies to processing of personal data:
  • First, the processing in question must be for the purpose of exercising the right to freedom of expression and information, including processing for journalistic purposes or for the purposes of academic, artistic or literary expression.
  • Second, compliance with the relevant provisions of the GDPR must be incompatible with those purposes, having regard to the importance of the freedom of expression right in a democratic society.
  1. The question for the DPC in relation to this issue is whether the particular reporting of the particular personal data and special category data of the Complainant in this case was for the purpose of exercising the freedom of expression right. If so, the DPC must consider whether compliance with the GDPR provisions set out in section 43(2) of the 2018 Act would have been incompatible with that right, noting also that the freedom of expression right is to be given a broad interpretation by the DPC (per section 43(5) of the 2018 Act).  This assessment for the purposes of section 43(2) of the 2018 Act requires the DPC to assess the compatibility of the exercise of freedom of information and expression against certain GDPR rights and obligations, including (in the context of this Complaint):
  • the requirement for data processing to be fair and lawful (Article 5(1)(a) GDPR),
  • the requirement for the controller to ensure that the personal data processed by it is adequate, relevant and limited to what is necessary in relation to the purposes of processing (Article 5(1)(c) GDPR),
  • the requirement for the controller to be accountable for its data processing by being able to demonstrate compliance with the principles of processing set out in Article 5 GDPR (pursuant to Article 5(2) GDPR),
  • the requirement for the controller to have a lawful basis for its data processing as contained in Article 6 GDPR,
  • the requirement for the controller to meet one of the conditions contained in Article 9 GDPR in respect of any special category data processed, and
  • the obligation to be subject to enforcement action or sanctions by the DPC as provided for under Chapter IV of the GDPR.
  1. The balance between media publications in exercise of freedom of information and expression and the right of privacy of the individual about whom information is published will favour the freedom of expression where the information is published in the public interest.  This public interest has been interpreted as being an interest in publishing or disclosing information that contributes to a debate of general interest.  This is sometimes contrasted with the publication or disclosing of information which is merely interesting to the public (e.g. being titillating or at the level of mere gossip) but which does not contribute to any debate of general interest.
  2. Article 85(1) GDPR requires that the right to protection of personal data pursuant to the GDPR must be reconciled with the right to freedom of expression and information, including processing for journalistic purposes. Section 43 requires an assessment of whether, inter alia, processing for journalistic purposes …shall be exempt from compliance with a provision of the [GDPR] specified [including processing principles and rights of the data subject] where, having regard to the importance of the right of freedom of expression and information in a democratic society, compliance with the provision would be incompatible with such purposes. This requires a balancing exercise of the obligation to respect a data subject’s personal data rights against the right of the public to be informed by the media about matters of public interest.
  3. The European Court of Human Rights has said that the role or function of the person concerned and the nature of the activities that are the subject of the report and/or photo constitute important criteria. In that regard, the Court said that a distinction has to be made between private individuals and persons acting in a public context, as political figures or public figures. Accordingly, whilst a private individual unknown to the public may claim particular protection of his or her right to private life, the same is not true of public figures … A fundamental distinction needs to be made between reporting facts capable of contributing to a debate in a democratic society, relating to politicians in the exercise of their official functions for example, and reporting details of the private life of an individual who does not exercise such functions. Whilst in the former case the press exercises its role of ‘public watchdog’ in a democracy by imparting information and ideas on matters of public interest, that role appears less important in the latter case. Similarly,  although in certain special circumstances the public’s right to be informed can even extend to aspects of the private life of public figures, particularly where politicians are concerned, this will not be the case – even where the persons concerned are quite well known to the public – where the published photos and accompanying commentaries relate exclusively to details of the person’s private life and have the sole aim of satisfying the curiosity of a particular readership in that respect. In the latter case, freedom of expression calls for a narrower interpretation. [2]
  4. It is true that the balance will not always favour the freedom of expression right. The ECtHR and the Irish courts have considered that the balance may tip in favour of an individual’s rights (which in many of the cases was their right to privacy), especially where the person was not a public figure and/or the matters reported concerned private activities of the individual (e.g. extra-marital affairs or an individual’s private sexual life). [3]
  5. The DPC does not accept that rules about standards and burdens of proof are relevant to the identification of public interest in media publications. Newspapers are not in the same position as the court and do not decide on the application of legal rights.
  6. The fact that medical information is at play is relevant to, but not determinative of, the balance to be struck between freedom of expression and the right to privacy. Medical information does require a very high level of protection. However, in this case, there was a clear nexus between the personal data published, including the special category data, and the debate in the general interest. Therefore, contrary to the Complainant’s submission, the DPC finds that the fact that the publications included data concerning health does not automatically determine the result of the balance against the right of freedom of expression and information.

[1]       Excluding Article 5(1)(f) GDPR.

[2]       Axel Springer AG -v- Germany App no 39954/08 (ECtHR 7 February 2012), [91].

[3]       E.g. Herrity v Associated Newspapers [2009] 1 IR 316; Von Hannover –v- Germany (Von Hannover I) [2004] ECHR 294; X (Infant) v Sunday World [2014] IEHC 696 (concerning details of an infant’s birth and questions about the infant’s paternity); and Nolan v Sunday World [2019] IECA 141 and paragraph 65 Bladet Tromsø and Stensaas v Norway App No 21980/93 (ECtHR,  20 May 1999) cited by the Complainant in her submissions on the Draft Decision.