---
title: GDPR - Irish Supervisory Authority Fines WhatsApp EUR 225m
date: '2021-09-09'
year: 2021
lang: en
type: post
wp_slug: gdpr-irish-supervisory-authority-fines-whatsapp-eur-225m
wp_url: >-
  http://armingaud-avocat.fr/en/gdpr-irish-supervisory-authority-fines-whatsapp-eur-225m/
categories:
  - Privacy
tags:
  - site
Language: English
created: '2021-09-09'
modified: '2021-09-09'
published: '2021-09-09'
---

Further to investigations initiated by the [Data Protection Commission](<https://www.dataprotection.ie/>) (or DPC, the Irish supervisory authority) in 2018, [Whatsapp Ireland Limited has received a EUR 225 million fine](<https://euipo.europa.eu/ohimportal/en/group/guest/dashboardhttps:/edpb.europa.eu/system/files/2021-09/dpc_final_decision_redacted_for_issue_to_edpb_01-09-21_en.pdf>) on 2 September 2021. The company infringed multiple GDPR provisions including in relation with the information provided to data subjects which breached the obligation to ensure transparency of processing ([Articles 13](<https://armingaud-avocat.fr/en/general-data-protection-regulation/#article13>) and [14 GDPR](<https://armingaud-avocat.fr/en/general-data-protection-regulation/#article14>)).

Following GDPR’s one-stop-shop mechanism and as WhatsApp operates cross-border flows of personal data, the DPC had initially been designated as lead supervisory authority (‘LSA’). [Article 60 GDPR](<https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e5285-1-1>) requires the LSA to submit a draft decision to its impacted counterparts across the European Union (the ‘Concerned Supervisory Authorities’). Such draft has been submitted in December 2020 and the Hungarian, Portuguese, Italian, French, Dutch, Polish, German (local and federal) Concerned Supervisory Authorities unanimously raised objections to the DPC in January 2021. The objections mostly addressed the lax approach by the DPC in the assessment of WhatsApp’s breach of GDPR as well as the amount of the initially contemplated fine in view of the dozens of millions of individuals affected by such breach across the European Union.

This resulted in a non-consensual situation, escalading to the dispute resolution process under [Article 65 GDPR](<https://armingaud-avocat.fr/en/general-data-protection-regulation/#article65>) conducted by the [European Data Protection Board](<https://edpb.europa.eu/>) (EDPB). The [binding decision](<https://edpb.europa.eu/system/files/2021-09/edpb_bindingdecision_202101_ie_sa_whatsapp_redacted_en.pdf>), adopted on 28 July 2021 and subsequently notified to the DPC, required the Irish supervisory authority to reassess and increase the fine, thus leading to the second-highest fine under GDPR since its entry into force in 2018.

**First publication** : [Cyber Law Watch](<https://www.cyberlawwatch.com/2021/09/gdpr-irish-supervisory-authority-fines-whatsapp-225-million/>) with [Camille Scarparo](<https://www.klgates.com/Camille-J-Scarparo>) & Léa Fertani
