The encyclopedia · Legal & Compliance · Legal decision · 2020-2023
Meta kept sending EU user data to the US after Schrems II — a €1.2B fine
Meta relied on standard contractual clauses it knew couldn't shield EU data from US surveillance law, and Ireland's regulator finally made it stop.
Meta Platforms Ireland · 2023-05-22
What happened
Since the CJEU's 2020 Schrems II ruling, transferring EU users' personal data to the US on standard contractual clauses alone was legally shaky: US surveillance law gave American intelligence agencies access that no contract clause could override. Meta kept transferring Facebook users' data to US servers anyway, arguing its clauses and supplementary measures were enough.
Ireland's Data Protection Commission disagreed, and the European Data Protection Board's April 2023 binding decision pushed the DPC toward the maximum penalty. On May 22, 2023, the DPC fined Meta Platforms Ireland €1.2 billion — a GDPR record — and ordered it to suspend future EU-to-US transfers within five months and bring existing processing into compliance within six.
Meta called the fine 'unjustified and unnecessary' and said the underlying legal conflict — between EU privacy law and US surveillance law — was not one it could resolve alone. A new EU-US Data Privacy Framework, adopted two months later, gave it a fresh legal basis to keep transferring data without paying again.
Why it happened
- Meta transferred EU user data to the US on standard contractual clauses after Schrems II (2020) found those clauses insufficient against US surveillance law.
- The EDPB's binding April 2023 decision pushed Ireland's regulator toward the statutory maximum rather than a negotiated penalty.
- The €1.2B fine was the largest GDPR penalty ever issued, but the 5-month transfer-suspension order carried more operational weight than the money.
- A new US-EU framework arrived two months later, so the underlying transfer mechanism, not the willingness to keep transferring, was the actual defect.
The lesson
A data transfer mechanism a court has already called inadequate doesn't become adequate by being the only one you have — the regulator will eventually price the gap.
Aftermath
Meta paid the fine and continued EU operations under the new Data Privacy Framework from July 2023. The DPC's decision remains the reference point for how the EU calculates penalties for unlawful international transfers.
Sources
- Irish Data Protection Commissioner imposes a €1.2 billion fine on Meta — BDO
- Meta's €1.2 Billion GDPR Fine: Why It Still Matters — GDPR Local
spotted an error? The club wants to know.
More like this
Amazon's €746M GDPR record fine was scrapped on a technicality
AliExpress got a €550M EU fine — the DSA's first big test landed on Alibaba
Italy fines Replika's maker €5 million over GDPR and children's data
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.