Meta Ireland Limited – Order (Italy, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Meta Ireland Limited was ordered to provide more information about its election-related activities. This is significant because it shows that even large tech companies must be transparent about how they handle personal data, especially during important events like elections. The order emphasizes the need for accountability in data processing.
What happened
Meta Ireland Limited was asked to clarify its data processing related to election reminders and stickers.
Who was affected
Italian adults who interacted with Meta's election-related features were affected.
What the authority found
The Garante per la protezione dei dati personali required Meta to provide further details about its data processing practices during the election period.
Why this matters
This order indicates that authorities are closely monitoring how tech companies manage personal data, especially in sensitive contexts. Website operators should be transparent about their data practices.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
From 20 September 2022 onwards, five days before the Italian general elections, Meta Platforms Ireland Limited (Meta), the controller, launched a campaign specifically aimed at Italian adults, for the stated purposes of encouraging voting, providing information on the election, and combatting election interference. Specifically, Meta prepared electoral reminders on its Facebook and Instagram services, which redirected users to the website of the Ministry of the Interior where they could find “reliable information about the elections”. These features were available through the Election Day Information (EDI) function on the Facebook service, and by clicking on election day “stickers” (which can be added to shared photos and videos) through the Instagram service. The Italian DPA considered it necessary to acquire further information regarding these activities and, by a letter dated 21 September 2022, sent a list of questions to Meta. In particular, this letter sought to ascertain: the nature and modalities of data processing in relation to the reminders and ‘stickers’, as well as the storage period of the data collected; the agreement allegedly in place with the Ministry of the Interior to redirect users to its website; any relevant corporate and community policies; any agreement with independent fact-checking organisations and the data exchanged with them; the manner in which the processing involved (in particular that which reveals political opinions) had been brought to the data subjects’ attention and the legal basis for such processing; and, finally, the measures put in place to ensure that these features would only be brought to the attention of those over 18 years old. Meta responded to the DPA on 22 September 2022, via a letter which did not contain much of the information requested and did not alleviate many of the concerns raised. As a result, on 23 September 2022, the DPA called upon Meta to temporarily suspend the aforementioned processing activity. Late in
Outcome
Order
A binding order requiring the controller to take specific action.
Related Enforcement Actions (0)
No other enforcement actions found for Meta Ireland Limited in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Order Date
21 December 2022
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-5699About this data
Cite as: Cookie Fines. Meta Ireland Limited - Italy (2022). Retrieved from cookiefines.eu
Last updated: