European General Court Fines European Commission for Violating Data Privacy Regulations
A Historic Decision
The European General Court has fined the European Commission, the primary executive arm of the European Union, for violating the bloc’s own data privacy regulations. This marks the first time the Commission has been held liable for infringing stringent data protection laws in the region.
Background
The Commission was found to have violated the General Data Protection Regulation (GDPR) by transferring a German citizen’s personal data, including their IP address and web browser metadata, to Meta’s servers in the United States when visiting the now-inactive futureu.europa[.]eu website in March 2022.
The Incident
The individual registered for one of the events on the site by using the Commission’s login service, which included an option to sign in using a Facebook account. The Commission created the conditions for transmission of the IP address of the individual concerned to the U.S. undertaking Meta Platforms.
The Court’s Decision
The Court of Justice of the European Union stated that the Commission created the conditions for transmission of the IP address of the individual concerned to the U.S. undertaking Meta Platforms. The court determined that a "sufficiently serious breach" was committed by transferring the personal data.
Compensation
As a result, the court has ordered the Commission to pay the individual €400 ($412), which they sought as compensation for the non-material damage they claimed to have sustained as a result of the data transfer.
Background Context
In July 2023, the E.U. adopted a new personal data transfer mechanism with the U.S. called the E.U.-U.S. Data Privacy Framework following the invalidation of the Privacy Shield, enabling the transatlantic transfer of personal data between the two regions.
Conclusion
The European General Court’s decision marks a significant step in protecting data privacy in the European Union. The Commission’s actions demonstrate the importance of adhering to data protection regulations and the consequences of non-compliance.
Related Content
- Cybersecurity: Gartner Endpoint Protection D-V1
- Data Privacy Framework: E.U.-U.S. Data Privacy Framework
Follow Us
- Twitter: @thehackersnews
- LinkedIn: The Hacker News