WhatsApp has just been handed a hefty fine of €55 million by the Irish Data Protection Commission (DPC) for violating GDPR. WhatsApp had failed to comply with numerous obligations under GDPR, including not providing “transparent, intelligible, and easily accessible information about the processing of their users’ personal data for the purpose of their own, third party, and affiliate companies’ benefit.”
In their ruling, the Irish DPC stated that their fine was appropriate, given the severity of the breach and the fact that WhatsApp had put its own benefitting commercial interests over the GDPR’s fundamental principles. WhatsApp had also failed to provide “suitable and specific measures to protect the interests of their users” with regards to the collection and processing of their personal data.
This ruling follows a similar decision by the French data protection authority which fined Google €50 million in 2019 for their own GDPR violation. It serves as a reminder to all companies, especially those operating in multiple jurisdictions, that compliance with GDPR is not optional. Businesses must ensure that they are fully compliant in order to avoid potential fines.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 23 Jan 2023 18:57:29 +0000