High Court - 2016 IEHC 323
Meta fined €1.2M by Ireland's DPC for GDPR violations related to data access requests.
Summary
Meta Platforms Ireland Limited (MPIL) has been fined €1.2 million by Ireland's Data Protection Commission (DPC) for failing to comply with GDPR access and portability requests. The DPC found that MPIL, formerly Facebook Ireland Limited, did not provide a data subject with all the personal data requested from its internal 'Hive' data warehouse, citing computational infeasibility. The DPC's inquiry concluded that MPIL failed to meet its obligations under Articles 15 and 20 of the GDPR.
Full text
Help High Court - 2016 IEHC 323: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 09:57, 26 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators279 editsTag: Visual edit← Older edit Latest revision as of 10:07, 26 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators279 editsTag: Visual edit Line 133: Line 133: === Facts ====== Facts === On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under [[Article 15 GDPR]], including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under [[Article 20 GDPR]].On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under [[Article 15 GDPR]], including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under [[Article 20 GDPR]]. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on [[Article 12 GDPR|Article 12(5) GDPR]], [[Article 15 GDPR|Article 15(4) GDPR]] and [[Article 20 GDPR|Article 20(4) GDPR]]. The data subject subsequently lodged a complaint with the Data Protection Commission (DPC), the DPA, arguing that the controller had failed to comply with his rights under [[Article 15 GDPR|Articles 15]] and [[Article 20 GDPR|20 GDPR]] and had unjustifiably relied on restrictions to those rights.On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on [[Article 12 GDPR|Article 12(5) GDPR]], [[Article 15 GDPR|Article 15(4) GDPR]] and [[Article 20 GDPR|Article 20(4) GDPR]]. The data subject subsequently lodged a complaint with the Data the DPA arguing that the controller had failed to comply with his rights under [[Article 15 GDPR|Articles 15]] and [[Article 20 GDPR|20 GDPR]] and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under [https://www.legislation.gov.uk/ukpga/2018/12/contents Section 110(1) Data Protection Act 2018]. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under [[Article 15 GDPR|Article 15(1)(a)]], [[Article 15 GDPR|(d)]] and [[Article 15 GDPR|(g) GDPR]].On 27 July 2018, the DPA opened a complaint-based inquiry under [https://www.legislation.gov.uk/ukpga/2018/12/contents Section 110(1) Data Protection Act 2018]. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under [[Article 15 GDPR|Article 15(1)(a)]], [[Article 15 GDPR|(d)]] and [[Article 15 GDPR|(g) GDPR]]. Latest revision as of 10:07, 26 August 2026 High Court - 2016 IEHC 323 Court: High Court (Ireland) Jurisdiction: Ireland Relevant Law: Article 12 GDPR Article 15 GDPR Article 20 GDPR Article 57 GDPR Article 58 GDPR Article 77 GDPR Article 83 GDPR Section 110 Data Protection Act 2018Section 113 Data Protection Act 2018Section 115 Data Protection Act 2018 Decided: 21.08.2026 Published: Parties: Data Protection Commission (DPC) Meta Platforms Ireland Limited (MPIL) National Case Number/Name: 2016 IEHC 323 European Case Law Identifier: Appeal from: Appeal to: Unknown Original Language(s): English Original Source: Bailii (in English) Initial Contributor: bms The High Court held that a complaint-based GDPR inquiry may address systemic issues and result in system-wide corrective measures and fines without being converted into an own-volition inquiry. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under Article 15 GDPR, including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under Article 20 GDPR. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on Article 12(5) GDPR, Article 15(4) GDPR and Article 20(4) GDPR. The data subject subsequently lodged a complaint with the Data the DPA arguing that the controller had failed to comply with his rights under Articles 15 and 20 GDPR and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under Section 110(1) Data Protection Act 2018. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under Article 15(1)(a), (d) and (g) GDPR. On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed Article 15(1) and (3) GDPR by refusing access to and a copy of relevant personal data; Article 15(1)(a), (d) and (g) GDPR by providing inadequate information; Article 20(1) GDPR by refusing to provide relevant portable data; and Article 12(3) and (4) GDPR by failing to comply with the applicable time limits. The DPA also proposed a reprimand, a compliance order concerning the controller's general access and portability practices and administrative fines totalling between €360 million and €430 million. In determining the proposed corrective measures, the DPA took into account that the practices identified through the individual complaint potentially affected millions of users. The controller challenged the PDD before the High Court. It argued that the DPA had unlawfully transformed an inquiry concerning a single complaint into a systemic, EEA-wide own-volition inquiry. According to the controller, the DPA acted ultra vires by proposing systemic corrective measures and fines based on broader effects on other users. It also alleged breaches of fair procedures and legitimate expectations. Holding The High Court dismissed the controller's action. The Cou