案例库 · 法务与合规 · 法务决策 · 2020-2023
这条还没译成中文,下面是英文原文。
Meta kept sending EU user data to the US after Schrems II — a €1.2B fine
Meta relied on standard contractual clauses it knew couldn't shield EU data from US surveillance law, and Ireland's regulator finally made it stop.
Meta Platforms Ireland · 2023-05-22
怎么回事
Since the CJEU's 2020 Schrems II ruling, transferring EU users' personal data to the US on standard contractual clauses alone was legally shaky: US surveillance law gave American intelligence agencies access that no contract clause could override. Meta kept transferring Facebook users' data to US servers anyway, arguing its clauses and supplementary measures were enough.
Ireland's Data Protection Commission disagreed, and the European Data Protection Board's April 2023 binding decision pushed the DPC toward the maximum penalty. On May 22, 2023, the DPC fined Meta Platforms Ireland €1.2 billion — a GDPR record — and ordered it to suspend future EU-to-US transfers within five months and bring existing processing into compliance within six.
Meta called the fine 'unjustified and unnecessary' and said the underlying legal conflict — between EU privacy law and US surveillance law — was not one it could resolve alone. A new EU-US Data Privacy Framework, adopted two months later, gave it a fresh legal basis to keep transferring data without paying again.
为什么会这样
- Meta transferred EU user data to the US on standard contractual clauses after Schrems II (2020) found those clauses insufficient against US surveillance law.
- The EDPB's binding April 2023 decision pushed Ireland's regulator toward the statutory maximum rather than a negotiated penalty.
- The €1.2B fine was the largest GDPR penalty ever issued, but the 5-month transfer-suspension order carried more operational weight than the money.
- A new US-EU framework arrived two months later, so the underlying transfer mechanism, not the willingness to keep transferring, was the actual defect.
教训
A data transfer mechanism a court has already called inadequate doesn't become adequate by being the only one you have — the regulator will eventually price the gap.
后来呢
Meta paid the fine and continued EU operations under the new Data Privacy Framework from July 2023. The DPC's decision remains the reference point for how the EU calculates penalties for unlawful international transfers.
资料来源
- Irish Data Protection Commissioner imposes a €1.2 billion fine on Meta — BDO
- Meta's €1.2 Billion GDPR Fine: Why It Still Matters — GDPR Local
发现哪里写错了?告诉我们。
类似的案例
这家公司栽倒的地方,别处有人漂亮地解开过。 第二意见 →

Comments · 0
登录 后就能评论。