The encyclopedia · Legal & Compliance · Legal decision · 2019–2024
Meta left some user passwords in plaintext — the Irish DPC fined it €91M
Hundreds of millions of passwords sat readable inside Meta's own systems; the Irish DPC fined it €91M even though no outsider ever got hold of them.
Meta Platforms · 2024-09-27
What happened
On 27 September 2024 Ireland's Data Protection Commission fined Meta Platforms Ireland €91 million ($102M) after a subset of user passwords was stored in plaintext — unencrypted and readable — inside the company's internal systems. Hundreds of millions of Facebook Lite users, tens of millions of other Facebook users and millions of Instagram users were affected.
The fine came even though no passwords ever reached outsiders and no abuse was found. The regulator ruled that Meta had failed GDPR's security duties by not assessing the risks of how passwords were processed, and had also failed to formally report the matter as a personal data breach or document it as required.
Meta itself had brought the issue to the DPC in March 2019, saying the passwords were temporarily logged in a readable format and the error was fixed. The inquiry opened the following month and the decision landed five and a half years later. The DPC said storing passwords in plaintext is widely accepted as unacceptable, because anyone reaching the data reaches the accounts.
Why it happened
- Internal logging pipelines are built for debugging, not for secrets — passwords ended up readable because nobody decided otherwise.
- The GDPR punishes the state of the data, not only the harm done: unencrypted passwords are a sanctionable breach even if no outsider ever touches them.
- Disclosure starts the clock but is not the obligation itself — formal breach notification and documentation are separate duties, and both were missed.
The lesson
Secrets that land in logs or internal stores by accident are still personal data — reviewing what your systems record costs less than explaining plaintext passwords to a regulator five years on.
Sources
- DPC announces €91 million fine of Meta — Data Protection Commission
- Meta fined for passwords stored in plaintext — CyberScoop
spotted an error? The club wants to know.
More like this
Amazon's €746M GDPR record fine was scrapped on a technicality
AliExpress got a €550M EU fine — the DSA's first big test landed on Alibaba
Italy fines Replika's maker €5 million over GDPR and children's data
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.