Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsIreland’s Data Protection Commission (DPC) fined Meta Platforms Ireland Limited €91 million after finding that it stored some Facebook users’ passwords in readable plaintext on internal systems and failed to meet GDPR security, breach-notification and record-keeping duties. The penalty was announced on 27 September 2024. The $102 million figure is an approximate contemporaneous conversion, not the official amount of the fine.
What happened to Facebook users’ passwords?
Meta Platforms Ireland Limited (MPIL) notified Ireland’s DPC in 2019 that it had inadvertently stored some social-media users’ passwords in plaintext—readable without cryptographic protection or encryption—on internal systems. The inquiry concerned Facebook. The decision addressed two password-logging incidents that came to MPIL’s attention in January 2019.
Plaintext storage is a security failure because someone able to access the relevant records could read the passwords, which can open access to users’ accounts. But the DPC’s findings about storage and compliance do not, by themselves, establish that an outsider accessed or misused the passwords.
How much was the fine?
The DPC imposed a reprimand and administrative fines totaling €91 million. The Associated Press described that amount as approximately $101.6 million, which explains the rounded $102 million headline figure. The regulator’s penalty was denominated in euros.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
What GDPR rules did Meta break?
The DPC found that MPIL infringed four GDPR provisions, covering security, breach notification and documentation:
- Article 5(1)(f): the principle that personal data must be processed with appropriate integrity and confidentiality.
- Article 32(1): the requirement to use security measures appropriate to the risk.
- Article 33(1): the obligation to notify the supervisory authority of a personal data breach. The DPC found MPIL failed to notify it of a breach involving plaintext password storage.
- Article 33(5): the requirement to document personal data breaches. The DPC found MPIL failed to document the breaches.
The DPC’s announcement summarizes the findings and the reprimand and fine. Its final decision was adopted on 26 September 2024 and announced the next day. The DPC said no objections to its draft decision were raised by the other concerned supervisory authorities in the EU/EEA cooperation process; Ireland’s DPC issued the final decision.
Rank #2
Did anyone access or abuse the passwords?
The DPC announcement establishes the password-storage and GDPR findings; it does not say that the passwords were actually abused. Meta told the Associated Press that its security review found a “subset” of Facebook users’ passwords had been “temporarily logged in a readable format.” The company said it fixed the error and had no evidence that the passwords were abused or accessed improperly. Those statements are Meta’s account, reported by the Associated Press, not a separate finding by the DPC.
Who was fined?
The legal subject of the DPC decision was Meta Platforms Ireland Limited, not the European Commission. The decision concerned Facebook’s password logging; it should not be read as a finding that every Meta service stored passwords in this way.
Rank #3
Why did the lapse lead to a large penalty?
The DPC’s decision addressed more than the underlying storage problem. It found that the company failed to use appropriate security measures and also failed to notify the regulator and document the breaches as required. DPC Deputy Commissioner Graham Doyle said: “It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data. It must be borne in mind, that the passwords the subject of consideration in this case, are particularly sensitive, as they would enable access to users’ social media accounts.”
Quick Recap
Rank #4
- Know when people have seen your messages.
- Forward messages or photos to people who weren't in the conversation.
- Search for people and groups to quickly get back to them.
- Turn on location to let people know when you're nearby.
- See who's available on Messenger and who's active on Facebook.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




