European Commission faces first-ever fine for violating its own privacy laws
Written by Rebecca Uffindell Thu 9 Jan 2025

Under a historic ruling, the General Court has ordered the European Commission to pay £335 ($412) in damages for violating its own privacy regulations by facilitating the transfer of an individual’s personal data to the US.
The European privacy ruling highlighted a breach of EU data protection laws by the Commission in connection with the Conference on the Future of Europe website.
The individual registered for a ‘GoGreen’ event via the Commission’s EU Login service, opting to sign in using Facebook. This action led to the transfer of his IP address, classified as personal data, to Meta Platforms in the US. At the time of the transfer in March 2022, no agreement ensured an adequate level of data protection for EU citizens in the US.
The court found the Commission failed to demonstrate the existence of appropriate safeguards, such as standard contractual clauses, to justify the transfer. As a result, the Commission violated EU data protection regulations.
“The General Court finds that the Commission committed a sufficiently serious breach of a rule of law that is intended to confer rights on individuals. The individual concerned suffered non-material damage, in that he found himself in a position of some uncertainty as regards the processing of his personal data, in particular of his IP address,” said the General Court.
Although other claims in the case were dismissed, the court ordered the Commission to pay £335 ($412) in compensation for the breach of data protection rules.
Written by Rebecca Uffindell Thu 9 Jan 2025

