The European General Court has fined the European Commission €400 for violating the EU’s data privacy regulations. This marks the first time the Commission has been held liable for infringing data protection laws. The breach occurred when a German citizen’s personal data was transferred to Meta’s servers in the US. The data was transferred through the Commission’s login service, which included an option to sign in using a Facebook account.
The court ruled that the Commission created the conditions for the data transfer, which was a “sufficiently serious breach” of data protection laws. The transfer was made without adequate safeguards, such as standard data protection clauses or contractual clauses. The EU has since adopted a new data transfer mechanism with the US, the EU-US Data Privacy Framework.