Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: The October 3, 2022 headline meant that Ireland’s Data Protection Commission (DPC) had submitted a draft decision in its investigation of Meta Platforms Ireland. The case was not finally resolved that day. On November 25, 2022, the DPC adopted its final decision and imposed a €265 million administrative fine, along with a reprimand and corrective orders.
The case concerned personal data associated with approximately 533 million Facebook users that resurfaced online in April 2021. It focused on whether Facebook and Instagram features were designed with adequate safeguards against large-scale data scraping—not on proof that 533 million accounts were individually hacked or taken over.
What happened to the 533 million-user dataset?
The dataset contained information associated with approximately 533 million Facebook users worldwide. Reported fields included phone numbers, email addresses and other profile information, although the information varied between records.
The data became publicly visible on a hacker website in April 2021. Meta said the information was old and related to a vulnerability reported in 2019. In other words, the April 2021 event was principally the public reappearance of an assembled dataset, rather than evidence of a new database intrusion on that date.
#1 Best Overall
The more precise description is a data-scraping incident. Scrapers abused platform functionality to collect and match information at scale. That is different from saying that every affected user’s password, private messages, payment details or entire account was accessed.
Contemporary reporting described the dataset and Meta’s position at the time. Data Center Knowledge’s summary also explained the potential GDPR fine framework.
The timeline
| Date | What happened |
|---|---|
| May 25, 2018–September 2019 | The period examined by the DPC, including the operation of relevant Facebook and Instagram features. |
| April 2021 | The assembled dataset resurfaced publicly online. |
| April 14, 2021 | Ireland’s DPC opened its inquiry. |
| October 3, 2022 | The DPC submitted a draft decision through the EU’s GDPR cooperation process. The final fine had not yet been imposed. |
| November 25, 2022 | The DPC adopted its final decision. |
| November 28, 2022 | The DPC publicly announced the €265 million fine and corrective measures. |
The original Bloomberg headline was accurate for October 3, 2022, but it is now a historical account of the draft-decision stage rather than a current regulatory development.
What did Ireland investigate?
The DPC examined Meta’s processing and technical and organizational measures relating to:
- Facebook Search;
- Facebook Messenger’s contact-importer functionality; and
- Instagram’s contact-importer functionality.
These features could allow phone numbers or related information to be matched with Facebook or Instagram profile data. The regulator’s inquiry asked whether the systems had adequate protections against unauthorized scraping during the relevant period.
The case reference was IN-21-4-2. The DPC’s case summary describes the examined period and the relevant GDPR provisions.
Why was Ireland’s regulator involved?
Meta’s European headquarters and relevant EU operations were based in Ireland, making the Irish DPC the lead supervisory authority for this cross-border GDPR matter. Other European data-protection authorities could participate as concerned authorities under the EU’s cooperation and consistency process.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Under this “one-stop-shop” structure, a lead regulator investigates a company’s cross-border processing while coordinating with regulators in other affected countries. A draft decision can be reviewed through that process before becoming final. The other EU supervisory authorities agreed with the DPC’s final decision.
Rank #3
What did “draws to a close” mean?
It meant that the DPC had completed its draft decision and sent it to EU counterparts for review or approval. It did not mean that Meta had already received the final penalty.
At that point, the amount of any fine and the final corrective measures had not yet been publicly announced. Those came later, when the DPC adopted its decision on November 25 and announced it on November 28, 2022.
The final outcome: a €265 million fine
The DPC found that Meta Platforms Ireland infringed Articles 25(1) and 25(2) of the GDPR. Those provisions concern data protection by design and by default—essentially, the obligation to build appropriate privacy safeguards into processing systems and their default configurations.
The final decision included:
- a €265 million administrative fine;
- a reprimand;
- an order requiring Meta to bring its processing into compliance; and
- additional corrective measures to be completed within a specified timeframe.
Read the DPC’s announcement and the European Data Protection Board’s summary for the official outcome. The DPC also published a redacted copy of the final decision.
Rank #4
How large could the fine have been?
Contemporary coverage noted that the GDPR can permit fines of up to 4% of a company’s annual worldwide turnover for certain violations. That figure was a statutory ceiling, not the amount Meta automatically owed and not a prediction of the final penalty.
The actual penalty in this case was €265 million. It was an administrative fine payable to the regulator, not an announced compensation program for individual users.
What Meta said
Meta characterized unauthorized scraping as unacceptable and contrary to its rules. It said it had engaged with the Irish regulator and continued investing in systems designed to prevent scraping. Meta also argued that the data was old and had already been reported in 2019.
Recommended Free Tools
Those statements describe Meta’s position; they do not replace the DPC’s formal findings. The regulator’s decision concerned the adequacy of data-protection-by-design and default safeguards during the period under investigation.
Best Value
What the decision does—and does not—establish
It does establish
- That the DPC found infringements involving GDPR Articles 25(1) and 25(2).
- That Meta Platforms Ireland was fined €265 million and ordered to take corrective action.
- That the case involved safeguards around Facebook and Instagram functionality that could be abused for large-scale scraping.
It does not establish
- That all 533 million users had identical information exposed.
- That all affected accounts were taken over.
- That every user suffered identity theft or financial loss.
- That the data was newly stolen in 2021.
- That a password database or private-message archive was publicly released.
- That Meta intentionally sold the dataset or deliberately enabled the exposure.
A GDPR penalty can address inadequate preventive controls even when the public record does not show that every affected person suffered direct financial harm.
What should potentially affected users do?
People cannot reliably erase information that has already been copied and circulated online. The practical response is to reduce the risk of follow-on fraud:
- Be cautious with unexpected contact. Treat unsolicited texts, calls, emails and password-reset messages as potentially fraudulent.
- Never share one-time codes. Legitimate support staff should not need an unsolicited verification code or account-recovery secret.
- Verify independently. Open the organization’s official app or type its website address yourself instead of clicking a suspicious message link.
- Use unique passwords. Reusing a password lets a criminal combine exposed contact information with credentials from another breach.
- Turn on multifactor authentication. An authenticator app or security key can reduce reliance on a phone number, although SMS-based MFA is still generally better than no second factor.
- Review account security. Check important accounts for unfamiliar logins, recovery-email changes, new devices or other unauthorized changes.
- Protect the mobile account. If a phone number is used for login or recovery, consider carrier-account protections and whether a stronger recovery method is available.
A phishing attempt after the exposure does not prove that the sender accessed private messages, financial accounts or the user’s full Facebook account. It may simply reflect the value of a phone number or email address for social engineering.
Why the case matters
The central regulatory lesson is that information being visible or accessible through a platform feature does not automatically remove the platform’s responsibility to limit large-scale misuse. Privacy obligations can include designing systems and default settings to make mass collection harder.
The case also illustrates why headlines about data “leaks” need a timeline. The dataset surfaced publicly in 2021, the DPC investigated earlier processing from 2018 to 2019, the October 2022 announcement concerned a draft decision, and the final outcome arrived in November 2022.
This was a specific Facebook data-scraping case involving Meta Platforms Ireland. It should not be combined with separate Meta investigations involving advertising practices, children’s privacy, password storage, access tokens or other security incidents.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

