Category: Compliance Regulation
Meta Fined €390 Million by Irish DPC for Alleged Breaches of GDPR, Including in Behavioral Advertising Context
On January 4, 2023, the Irish Data Protection Commission (“DPC”) announced the conclusion of two inquiries into the data processing practices of Meta Platforms, Inc. (“Meta”) with respect to the company’s Instagram and Facebook platforms. As a result of the investigations, the DPC fined Meta a combined €390 million for breaches of the EU General Data Protection Regulation (“GDPR”) and, following consultation with the European Data Protection Board (“EDPB”), notably held that Meta can no longer rely on the GDPR’s…
Whole Foods Settles BIPA Voiceprint Class Action
On January 3, 2023, an Illinois state court entered a preliminary approval order for a settlement of nearly $300,000 in a class action lawsuit against Whole Foods for claims that the company violated the Illinois Biometric Information Privacy Act (“BIPA”). The plaintiffs alleged that Whole Foods unlawfully collected voiceprints from employees who worked at the company’s distribution centers. In the case in the Circuit Court of Cook County, Illinois, Chancery Division, the plaintiffs alleged that, by requiring them to use…
Top U.S. court backs WhatsApp suit over Pegasus spyware
The U.S. Supreme Court has rejected a bid by NSO Group to block a WhatsApp lawsuit accusing the Israeli tech firm of allowing mass cyberespionage of journalists and human rights activists. The Supreme Court denied NSO’s plea for legal immunity and ruled that the case, which targets the company’s Pegasus software, can continue in a California federal court, a court filing showed. Pegasus gives its government customers — which have allegedly included Mexico, Hungary, Morocco and India — near-complete access…
EU & Ireland: Meta’s legal basis for targeted ads found to breach GDPR
Ireland’s Data Protection Commission (DPC) announced on January 4, 2023, that it has fined Meta a total of €390 million after finding that the company’s Facebook and Instagram platforms lacked proper legal grounds for processing millions of Europeans’ personal data for targeted advertising. In addition to posing challenges for Meta’s business model, the DPC’s two decisions reflect growing disagreement among European data protection authorities (DPAs) on two fronts. The first relates to the use of ‘contractual necessity’ as an appropriate…
CNIL Fines Apple 8 Million Euros Over Personalized Ads
On December 29, 2022, the French Data Protection Authority (the “CNIL”) announced that it imposed an €8,000,000 fine on Apple for violations of the French rules on targeted advertising and the use of cookies and similar tracking technologies. Background The CNIL received a complaint concerning Apple’s ad personalization practices on the App Store and carried out several investigations between 2021 and 2022. The CNIL’s investigations concluded that Apple was collecting the identifiers of users that visited the App Store using…
Corporate and White-Collar Enforcement in 2023–24
As 2022 comes to a close, is it possible to predict a trend for corporate and white-collar enforcement by the U.S. Department of Justice in 2023? Yes: enforcement will increase in 2023, and it will increase yet more in 2024. Understanding the Department as a dispersed, human institution that responds to incentives explains why.
Honeywell UOP to Pay Over $160 Million to Resolve Foreign Bribery Investigations in U.S. and Brazil
According to the company’s admissions and court documents, between 2010 and 2014, Honeywell UOP conspired to offer an approximately $4 million bribe to a then-high-ranking executive of Petróleo Brasileiro S.A (Petrobras) in Brazil. Specifically, Honeywell UOP offered the bribe to secure improper advantages in order to obtain and retain business from Petrobras in connection with Honeywell UOP’s efforts to win an approximately $425 million contract from Petrobras to design and build an oil refinery called Premium.
Portuguese Data Protection Authority fines the National Institute of Statistics € 4.3 million
On 2 November 2022, the Portuguese Data Protection Authority (“CNPD”) issued a Decision imposing a fine of € 4,300,000 (four million three hundred euros) to the National Institute of Statistics (“INE”) for multiple violations in the processing of data subjects’ sensitive data during the Census 2021 operation. Background On the 27th of April 2021, after launching an investigation into the transfer of personal data from INE to Cloudflare (a U.S. service provider engaged by INE for the operation of the…
Academy Mortgage Corporation to Pay $38.5 Million: False Claims Act Allegations Related to Mortgages Insured by Federal Housing Administration
Thrower alleged that from January 2008 through April 2017, Academy had an underwriting process that led employees to disregard FHA rules and falsely certify compliance with underwriting requirements. Thrower further alleged that, as a result of Academy’s knowingly deficient mortgage underwriting practices, the government paid insurance claims on loans improperly underwritten by Academy.
“Lenders that knowingly cause the government to guarantee loans that are materially deficient put both homeowners and the public fisc at risk,” said Principal Deputy Assistant Attorney General Brian M. Boynton, head of the Justice Department’s Civil Division. “The settlement announced today is a result of the relator’s efforts to develop this case in litigation and complements the department’s actions to prevent abuse of government programs designed to foster home ownership.”
Meta Slapped with €265 Million for Privacy Violations
On November 25, 2022, Ireland’s Data Protection Commission (“DPC”) released a decision fining Meta Platforms, Inc. (“Meta”) €265 million for a 2019 data leak involving the personal information of approximately 533 million Facebook users worldwide. In the decision, the DPC argued that Meta failed to comply with the GDPR’s requirement of providing privacy “by design and default” when it failed to prevent the disclosure of users’ phone numbers, email addresses, full names, dates of birth and other personal information on…
Italian Supreme Court Grants Global Delisting Order Under National Law
On November 15, 2022, the Italian Supreme Court held that an Italian court or competent data protection authority has jurisdiction to issue a global delisting order. A delisting order requires a search engine to remove certain search results about individuals if the data subject’s privacy interests prevail over the general right to expression and information, and the economic interest of the search engine. The case was brought by an Italian individual, who requested a worldwide delisting order, concerning all versions…
Twitter to Pay $150 Million Civil Penalty to Resolve Data Privacy Violations
May 31, 2022. The Department of Justice, together with the Federal Trade Commission (FTC), announced a settlement that, if approved by a federal court, will require Twitter Inc. to pay $150 million in civil penalties and implement robust compliance measures to protect users’ data privacy. The settlement will resolve allegations that Twitter violated the FTC Act and an administrative order issued by the FTC in March 2011 by misrepresenting how it would make use of users’ nonpublic contact information. In…
CDC bought data harvested from millions of phones to monitor trends not related to COVID-19
May 10, 2022. The Centers for Disease Control and Prevention (CDC) bought access to location data harvested from tens of millions of phones in the United States to perform analysis of compliance with curfews, track patterns of people visiting K-12 schools, and specifically monitor the effectiveness of policy in the Navajo Nation, according to CDC documents obtained by Motherboard. The documents also show that although the CDC used COVID-19 as a reason to buy access to the data more quickly,…
Clearview AI settlement: Will stop selling facial recognition tool to private firms and continue working with law enforcement
May 9, 2022. Facial recognition company Clearview AI has agreed to stop its sales to private companies in the United States as part of a landmark settlement reining in a technology criticized as threatening Americans’ privacy rights. The settlement, filed Monday in federal court in Illinois, marks the most significant court action yet against Clearview AI, a company known for downloading billions of people’s photos from social networks and other websites to build a face-search database sold to law enforcement….
New records show DHS are buying & using cell phone location data
The ACLU published thousands of pages of previously unreleased records showing that the Department of Homeland Security (DHS) are sidestepping the constitutional right against unreasonable government search and seizure. DHS has been buying access to and using large volumes of cell phone location information that has been “quietly extracted from smartphone apps” of U.S. citizens and others — using their own tax dollars. In 2018, the Supreme Court ruled in Carpenter v. United States that the government needs a warrant…