← All enforcement actions
GDPRB2C Tech

Meta / Instagram€405M GDPR fine (2022)

Children's business-account email + phone exposed publicly

Penalty
€405M
Regulator
Irish DPC
Jurisdiction
European Union

What happened

Instagram allowed users aged 13-17 to operate 'business accounts' that made their email addresses and phone numbers publicly visible. Ireland's DPC found violations of GDPR Articles 5, 6, 12, 24, 25, and 35.

Root cause

What every team should do

  1. Run a Data Protection Impact Assessment (DPIA) before launching any feature processing children's data
  2. Restrict public disclosure of contact data for minor accounts
  3. Document Article 6 legal basis per processing purpose, not per product
Source: Irish DPC final decision (Sep 5, 2022).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
Amazon Europe Core
€746M
Largest GDPR fine at the time — behavioural ad targeting without valid consent
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
British Airways
£20M
Magecart-style skimmer on payment page — 429K records exposed