WhatsApp has been hit with a fine of €225m euros by the Irish data protection commissioner, following an investigation into GDPR practices at the company.
The record fine came after the probe found WhatsApp had breached European Union laws on transparency, and the sharing of user information with other companies owned by Facebook.
Whatsapp reprimanded
In addition to the fine, the office of the data protection commissioner (DPC) in Dublin has issued a “reprimand” to WhatsApp, and ordered it to bring its processing into compliance with EU standards.
The investigation began on December 10 2018 and examined if WhatsApp had complied with its obligations under the EU’s General Data Protection Regulation (GDPR).
It is the second, and largest fine issued by the DPC under the GDPR, after Twitter was hit with a €450,000 penalty in 2020 over a security breach.
The investigation into the Facebook-owned messaging service examined if the company had met its transparency obligations around the provision of information to both users and non-users.
This included whether users had been provided with information about data sharing between WhatsApp and other Facebook companies.
Disproportionate?
In a press statement, WhatsApp said the fine was “disproportionate” and said it will appeal the ruling.
They said:
WhatsApp is committed to providing a secure and private service.
We have worked to ensure the information we provide is transparent and comprehensive and will continue to do so.
We disagree with the decision today regarding the transparency we provided to people in 2018 and the penalties are entirely disproportionate.
The DPC initially imposed a smaller fine, but this was objected to by regulators in other EU member states.
A binding decision
On July 28 2021, the European Data Protection Board (EDPB) adopted a binding decision which was then notified to the DPC. A DPC statement said:
This decision contained a clear instruction that required the DPC to reassess and increase its proposed fine on the basis of a number of factors contained in the EDPB’s decision and following this reassessment the DPC has imposed a fine of 225 million euro on WhatsApp,
In addition to the imposition of an administrative fine, the DPC has also imposed a reprimand along with an order for WhatsApp to bring its processing into compliance by taking a range of specified remedial actions.
The Irish DPC is the lead supervisor of GDPR rules in the EU, because a large number of firms, including Facebook, WhatsApp and others, have their European headquarters based in Dublin.