European Commission fines Meta €91 million for storing passwords in plain text
Guardii Analysis
The Irish Data Protection Commission has imposed a fine of 91 million euros on Meta Platforms Ireland Limited after an investigation found that the company stored millions of user passwords in plain text on internal systems, accessible to thousands of employees, for periods extending up to several years. The ruling, issued under the European Union General Data Protection Regulation, found that Meta failed to implement appropriate technical measures to ensure security of personal data and failed to notify the regulator promptly when the issue was discovered in 2019. The decision has been shared with all EU data protection authorities under the GDPR cooperation mechanism.
Data protection enforcement increasingly scrutinizes not only the fact of breach but the structural adequacy of systems designed to prevent it, and regulators expect proportionality between the sensitivity of data processed and the sophistication of safeguards applied. In the context of child safety, where the data in question includes direct message content revealing grooming, sextortion or abuse, the standard is necessarily higher. Guardii's architecture is designed around that principle: harmful patterns are detected and escalated in real time without creating centralized repositories of message text, meaning that detection occurs at the point of risk and reporting conveys the shape and severity of a conversation rather than a readable transcript, reducing both the attack surface for unauthorized access and the privacy exposure inherent in mass content retention.
