Meta, the parent company of Facebook, has been hit with a €91 million (£75 million) fine by the Irish Data Protection Commission (DPC) following an investigation into its password storage practices. The inquiry began in April 2019 after Meta reported that certain user passwords were inadvertently stored in plaintext on its internal systems, lacking proper encryption.
The DPC submitted its draft decision to other European data protection authorities in June 2024, and no objections were raised. The investigation revealed that Meta had committed four breaches of the General Data Protection Regulation (GDPR).
Graham Doyle, the DPC’s deputy commissioner, emphasized the seriousness of the violation: “It is widely accepted that user passwords should not be stored in ‘plaintext’ considering the risks of abuse that arise from persons accessing such data. The passwords in question are particularly sensitive, as they enable access to users’ social media accounts.”
The decision, made by data protection commissioners Dr. Des Hogan and Dale Sunderland, includes a formal reprimand alongside the financial penalty, which was communicated to Meta on September 26.
This fine adds to a series of penalties Meta has faced in recent years. In May 2023, the company was fined €1.2 billion (£1 billion) for mishandling data transfers between Europe and the United States, marking the largest fine under the EU’s GDPR privacy law. Additionally, in 2022, Meta was fined €265 million (£220 million) after data from 533 million users was published on a hacking forum following a previous data breach.



