Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Meta’s 533 Million-User Facebook Data-Scraping Probe: What Happened and How It Ended

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Short answer: The October 3, 2022 headline meant that Ireland’s Data Protection Commission (DPC) had submitted a draft decision in its investigation of Meta Platforms Ireland. The case was not finally resolved that day. On November 25, 2022, the DPC adopted its final decision and imposed a €265 million administrative fine, along with a reprimand and corrective orders.

The case concerned personal data associated with approximately 533 million Facebook users that resurfaced online in April 2021. It focused on whether Facebook and Instagram features were designed with adequate safeguards against large-scale data scraping—not on proof that 533 million accounts were individually hacked or taken over.

What happened to the 533 million-user dataset?

The dataset contained information associated with approximately 533 million Facebook users worldwide. Reported fields included phone numbers, email addresses and other profile information, although the information varied between records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The data became publicly visible on a hacker website in April 2021. Meta said the information was old and related to a vulnerability reported in 2019. In other words, the April 2021 event was principally the public reappearance of an assembled dataset, rather than evidence of a new database intrusion on that date.

The more precise description is a data-scraping incident. Scrapers abused platform functionality to collect and match information at scale. That is different from saying that every affected user’s password, private messages, payment details or entire account was accessed.

Contemporary reporting described the dataset and Meta’s position at the time. Data Center Knowledge’s summary also explained the potential GDPR fine framework.

The timeline

Date What happened
May 25, 2018–September 2019 The period examined by the DPC, including the operation of relevant Facebook and Instagram features.
April 2021 The assembled dataset resurfaced publicly online.
April 14, 2021 Ireland’s DPC opened its inquiry.
October 3, 2022 The DPC submitted a draft decision through the EU’s GDPR cooperation process. The final fine had not yet been imposed.
November 25, 2022 The DPC adopted its final decision.
November 28, 2022 The DPC publicly announced the €265 million fine and corrective measures.

The original Bloomberg headline was accurate for October 3, 2022, but it is now a historical account of the draft-decision stage rather than a current regulatory development.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did Ireland investigate?

The DPC examined Meta’s processing and technical and organizational measures relating to:

  • Facebook Search;
  • Facebook Messenger’s contact-importer functionality; and
  • Instagram’s contact-importer functionality.

These features could allow phone numbers or related information to be matched with Facebook or Instagram profile data. The regulator’s inquiry asked whether the systems had adequate protections against unauthorized scraping during the relevant period.

The case reference was IN-21-4-2. The DPC’s case summary describes the examined period and the relevant GDPR provisions.

Why was Ireland’s regulator involved?

Meta’s European headquarters and relevant EU operations were based in Ireland, making the Irish DPC the lead supervisory authority for this cross-border GDPR matter. Other European data-protection authorities could participate as concerned authorities under the EU’s cooperation and consistency process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Under this “one-stop-shop” structure, a lead regulator investigates a company’s cross-border processing while coordinating with regulators in other affected countries. A draft decision can be reviewed through that process before becoming final. The other EU supervisory authorities agreed with the DPC’s final decision.

What did “draws to a close” mean?

It meant that the DPC had completed its draft decision and sent it to EU counterparts for review or approval. It did not mean that Meta had already received the final penalty.

At that point, the amount of any fine and the final corrective measures had not yet been publicly announced. Those came later, when the DPC adopted its decision on November 25 and announced it on November 28, 2022.

The final outcome: a €265 million fine

The DPC found that Meta Platforms Ireland infringed Articles 25(1) and 25(2) of the GDPR. Those provisions concern data protection by design and by default—essentially, the obligation to build appropriate privacy safeguards into processing systems and their default configurations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The final decision included:

  • a €265 million administrative fine;
  • a reprimand;
  • an order requiring Meta to bring its processing into compliance; and
  • additional corrective measures to be completed within a specified timeframe.

Read the DPC’s announcement and the European Data Protection Board’s summary for the official outcome. The DPC also published a redacted copy of the final decision.

How large could the fine have been?

Contemporary coverage noted that the GDPR can permit fines of up to 4% of a company’s annual worldwide turnover for certain violations. That figure was a statutory ceiling, not the amount Meta automatically owed and not a prediction of the final penalty.

The actual penalty in this case was €265 million. It was an administrative fine payable to the regulator, not an announced compensation program for individual users.

What Meta said

Meta characterized unauthorized scraping as unacceptable and contrary to its rules. It said it had engaged with the Irish regulator and continued investing in systems designed to prevent scraping. Meta also argued that the data was old and had already been reported in 2019.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those statements describe Meta’s position; they do not replace the DPC’s formal findings. The regulator’s decision concerned the adequacy of data-protection-by-design and default safeguards during the period under investigation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the decision does—and does not—establish

It does establish

  • That the DPC found infringements involving GDPR Articles 25(1) and 25(2).
  • That Meta Platforms Ireland was fined €265 million and ordered to take corrective action.
  • That the case involved safeguards around Facebook and Instagram functionality that could be abused for large-scale scraping.

It does not establish

  • That all 533 million users had identical information exposed.
  • That all affected accounts were taken over.
  • That every user suffered identity theft or financial loss.
  • That the data was newly stolen in 2021.
  • That a password database or private-message archive was publicly released.
  • That Meta intentionally sold the dataset or deliberately enabled the exposure.

A GDPR penalty can address inadequate preventive controls even when the public record does not show that every affected person suffered direct financial harm.

What should potentially affected users do?

People cannot reliably erase information that has already been copied and circulated online. The practical response is to reduce the risk of follow-on fraud:

  1. Be cautious with unexpected contact. Treat unsolicited texts, calls, emails and password-reset messages as potentially fraudulent.
  2. Never share one-time codes. Legitimate support staff should not need an unsolicited verification code or account-recovery secret.
  3. Verify independently. Open the organization’s official app or type its website address yourself instead of clicking a suspicious message link.
  4. Use unique passwords. Reusing a password lets a criminal combine exposed contact information with credentials from another breach.
  5. Turn on multifactor authentication. An authenticator app or security key can reduce reliance on a phone number, although SMS-based MFA is still generally better than no second factor.
  6. Review account security. Check important accounts for unfamiliar logins, recovery-email changes, new devices or other unauthorized changes.
  7. Protect the mobile account. If a phone number is used for login or recovery, consider carrier-account protections and whether a stronger recovery method is available.

A phishing attempt after the exposure does not prove that the sender accessed private messages, financial accounts or the user’s full Facebook account. It may simply reflect the value of a phone number or email address for social engineering.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the case matters

The central regulatory lesson is that information being visible or accessible through a platform feature does not automatically remove the platform’s responsibility to limit large-scale misuse. Privacy obligations can include designing systems and default settings to make mass collection harder.

The case also illustrates why headlines about data “leaks” need a timeline. The dataset surfaced publicly in 2021, the DPC investigated earlier processing from 2018 to 2019, the October 2022 announcement concerned a draft decision, and the final outcome arrived in November 2022.

This was a specific Facebook data-scraping case involving Meta Platforms Ireland. It should not be combined with separate Meta investigations involving advertising practices, children’s privacy, password storage, access tokens or other security incidents.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.