Sovy
  • Products
    • Data Privacy Essentials℠
    • Consent Management Platform
    • Whistleblowing Portal
    • DPO Services
    • EU/UK Representative Services
    • Compliance Spot Check
    • Managed IT Services
    • All Products
    • Free GDPR Scan
    • Free GDPR Readiness Survey
  • eLearning Solutions
    • Corporate eLearning
    • Sovy Academy℠
      • Introduction to GDPR
      • Introduction to GDPR for Recruitment
      • GDPR for Privacy Managers
      • GDPR for IT Professionals
      • Introduction to Cybersecurity
  • Resources
    • Free GDPR Scan
    • Free GDPR Readiness Survey
    • Knowledge Portal
    • Data Privacy Blog
  • Pricing
    • Data Privacy Essentials
    • myConsentChoice CMP
  • About Sovy
    • Mission
    • Team
    • Investor Relations
    • Partnerships
  • Contact Us
  • Products
    • Data Privacy Essentials℠
    • Consent Management Platform
    • Whistleblowing Portal
    • DPO Services
    • EU/UK Representative Services
    • Compliance Spot Check
    • Managed IT Services
    • All Products
    • Free GDPR Scan
    • Free GDPR Readiness Survey
  • eLearning Solutions
    • Corporate eLearning
    • Sovy Academy℠
      • Introduction to GDPR
      • Introduction to GDPR for Recruitment
      • GDPR for Privacy Managers
      • GDPR for IT Professionals
      • Introduction to Cybersecurity
  • Resources
    • Free GDPR Scan
    • Free GDPR Readiness Survey
    • Knowledge Portal
    • Data Privacy Blog
  • Pricing
    • Data Privacy Essentials
    • myConsentChoice CMP
  • About Sovy
    • Mission
    • Team
    • Investor Relations
    • Partnerships
  • Contact Us

Data Privacy Blog

September 9, 2022  |  By Camelia Nastasi

Instagram was fined a record €405 million by the Irish DPA for violating the privacy of children

fine for gdpr breach

Instagram received a €405 million fine for GDPR (The General Data Protection Regulation). breach of children's data. It all started with the opening of an investigation in 2020. The investigation focused on users between the ages of 13 and 17, who had the possibility to manage business accounts. This facilitated the publication of the phone numbers and email addresses of the users. The conclusion was that Instagram violated the GDPR.

At the EU level, the Irish Data Protection Commission supervises several tech giants, including Apple, Google, and Meta. The tech company Meta owns Instagram, and this fine is the second-largest, after the €746 million fine that Amazon was imposed with.

The fine, which targets Instagram's violation of children's privacy, is currently the biggest for a company owned by Meta, coming after a €225 million fine for WhatsApp and a €17 million fine for Facebook.

Instagram claims that during the investigation, the company worked cooperatively with the Irish DPA. However, the social media platform disagrees with how the DPA determined the fine. According to Instagram, the investigation focused on outdated settings that the tech company modified more than a year ago. Since then, Meta has adopted a lot of new features to support teen safety.

How to avoid the fine for a GDPR breach of children's data?

For the processing of children's personal data, adherence to data protection standards and, in particular, fairness, should be mandatory. Before processing a child's personal information, you must establish a legal basis. Although consent is one ground that could be used, it is not the only one. Sometimes selecting a different legal basis is preferable and provides better protection for child's data.

If you provide a service directly to children and depend on consent as the legal basis for processing personal data, you should confirm that the person providing the consent is of legal age to do so. Unless the service you provide is an online preventative or counseling service, you must get the approval of individuals who have parental control over children under the age of 16.

Make sure the person granting consent genuinely has parental responsibility for the child as well. In most circumstances, if this would have a legal or comparable substantial effect on children, you should not make choices regarding them based purely on automated processing. The GDPR places restrictions on when you can make these choices. It only applies if you have taken the necessary precautions to safeguard the child's interests.

If you need assistance or have any questions, don't hesitate to get in touch with Sovy team!

Source: https://www.politico.eu/article/instagram-fined-e405m-for-violating-kids-privacy/

Last updated: September 9, 2022

Article by Camelia Nastasi

Previous StoryNew complaints have been filed against misleading cookie banners. How can you maintain GDPR compliance with your cookie banner?
Next StoryHow are GDPR fines calculated? EDPB guidelines on the Calculation of Administrative Fines

SEARCH

CATEGORIES

  • CCPA (1)
  • compliance (1)
  • consent management (2)
  • CPRA (2)
  • Cybersecurity (2)
  • Data Privacy Fines (2)
  • Data Protection Officer (2)
  • Data security and privacy (9)
  • elearning (1)
  • GDPR (22)
  • GDPR fines (8)
  • GDPR guidance (10)

TAG CLOUD

2020 cookie policy data privacy data protection fines GDPR tik tok

ARCHIVES

  • September 2024 (1)
  • July 2024 (1)
  • June 2024 (1)
  • April 2024 (1)
  • March 2024 (1)
  • October 2023 (1)
  • July 2023 (1)
  • June 2023 (2)
  • May 2023 (1)
  • April 2023 (2)
  • March 2023 (1)
  • February 2023 (1)
  • January 2023 (2)
  • December 2022 (1)
  • October 2022 (1)
  • September 2022 (1)
  • August 2022 (1)
  • July 2022 (1)
  • June 2022 (3)
  • May 2022 (2)
  • April 2022 (1)
  • March 2022 (1)
  • February 2022 (1)
  • January 2022 (2)
  • December 2021 (1)
  • November 2021 (1)
  • September 2021 (1)
  • August 2021 (1)
  • July 2021 (2)
  • June 2021 (2)
  • May 2021 (2)
  • January 2021 (1)

LATEST POSTS

  • Top 10 Benefits of Outsourcing Your Data Protection Officer
  • custom eLearning Development Services
    Custom eLearning Development Services: Everything You Need to Know for Success
  • compliance management system
    The Ultimate Guide to Compliance Management System
  • GDPR compliance checklist
    GDPR Compliance Checklist: Ensuring Data Protection
  • why is cybersecurity important?
    Why is cybersecurity important? How to Keep your company safe

QUICK LINKS

  • About Us
  • Resources
  • Privacy Policy
  • Terms
  • Manage Consent
  • Contact Us

Sovy GDPR Privacy Essentials

  • Subscription Benefits
  • Pricing
  • Log in
  • GDPR for Small Businesses
  • GDPR for Enterprises
  • GDPR for Sole Traders
  • GDPR for Charities

SOVY LOCATIONS

Ireland HQ

Registered Office
St Gall's House
St Gall Gardens South
Milltown, Dublin 14
D14 Y882
Ph: +353 (4)6 929-3537

London

Registered Office
Kemp House
152-160 City Road
London EC1V 2N

ASSOCIATIONS

Copyright © 2024 Sovy Trust Solutions Limited. All Rights Reserved. Registered in Ireland, No. 610835 and No. 605069