Information Commissioner's Office
Statement on an agreement reached between Facebook and the ICO
In 2017 the Information Commissioner's Office ("ICO") commenced a formal investigation into the misuse of personal data in political campaigns.
As part of that investigation, on 24 October 2018, the ICO issued a monetary penalty notice under section 55A of the Data Protection Act 1998 against Facebook Inc and Facebook Ireland Limited (together, "Facebook"), in the sum of £500,000 (the "MPN"). The MPN identified suspected failings related to compliance with the UK data protection principles covering lawful processing of data and data security.
On 21 November 2018, Facebook filed an Appeal with the First Tier Tribunal (General Regulatory Chamber) (the "Tribunal"), against the MPN (the "Appeal").
On 14 June 2019, the Tribunal issued an interim decision holding that procedural fairness and allegations of bias on the part of the ICO should be considered as part of the Appeal, and that the ICO should be required to disclose materials relating to its decision-making process regarding the MPN. The ICO appealed that interim decision on 2 September 2019.
An agreement has now been reached between the parties. As part of this agreement, Facebook and the ICO have agreed to withdraw their respective appeals. Facebook has agreed to pay the £500,000 fine but has made no admission of liability in relation to the MPN. The fine is not kept by ICO but is paid to HM Treasury’s consolidated fund. As is usually the case in such proceedings before the Tribunal, the ICO and Facebook will each pay their own legal costs of the proceedings. Further, the agreement enables Facebook to retain documents disclosed by the ICO during the appeal for other purposes, including furthering its own investigation into issues around Cambridge Analytica. Parts of this investigation had previously been put on hold at the ICO's direction and can now resume.
The Commissioner considers that this agreement best serves the interests of all UK data subjects who are Facebook users. Both Facebook and the ICO are committed to continuing to work to ensure compliance with applicable data protection laws.
James Dipple-Johnstone (Deputy Commissioner) yesterday said:
"The ICO welcomes the agreement reached with Facebook for the withdrawal of their appeal against our Monetary Penalty Notice and agreement to pay the fine. The ICO’s main concern was that UK citizen data was exposed to a serious risk of harm. Protection of personal information and personal privacy is of fundamental importance, not only for the rights of individuals, but also as we now know, for the preservation of a strong democracy. We are pleased to hear that Facebook has taken, and will continue to take, significant steps to comply with the fundamental principles of data protection. With this strong commitment to protecting people’s personal information and privacy, we expect that Facebook will be able to move forward and learn from the events of this case."
Harry Kinmonth, Director and Associate General Counsel, Facebook yesterday said:
“We are pleased to have reached a settlement with the ICO. As we have said before, we wish we had done more to investigate claims about Cambridge Analytica in 2015. We made major changes to our platform back then, significantly restricting the information which app developers could access. Protecting people’s information and privacy is a top priority for Facebook, and we are continuing to build new controls to help people protect and manage their information. The ICO has stated that it has not discovered evidence that the data of Facebook users in the EU was transferred to Cambridge Analytica by Dr Kogan. However, we look forward to continuing to cooperate with the ICO’s wider and ongoing investigation into the use of data analytics for political purposes.”
Latest News from
Information Commissioner's Office
Greater Manchester claims management company fined £250,000 for making millions of nuisance calls30/10/2020 12:25:00
The Information Commissioner’s Office (ICO) has fined Reliance Advisory Limited (RAL) £250,000 for breaking electronic marketing law.
ICO takes enforcement action against Experian after data broking investigation28/10/2020 12:25:00
The Information Commissioner’s Office (ICO) orders the credit reference agency Experian Limited to make fundamental changes to how it handles people’s personal data within its direct marketing services.
Blog: Simplifying subject access requests – new detailed SARs guidance22/10/2020 12:25:00
The right of access is a fundamental right under data protection law. And it has never been more necessary. In a world where personal data is used almost everywhere – by everyone – it’s vital that people have the right to be able to find out what’s happening to their information.
ICO fines British Airways £20m for data breach affecting more than 400,000 customers19/10/2020 12:25:00
The Information Commissioner’s Office (ICO) has fined British Airways (BA) £20m for failing to protect the personal and financial details of more than 400,000 of its customers.
Blog: Engagement key in protecting people’s privacy across the UK during the pandemic14/10/2020 12:25:00
Information Commissioner Elizabeth Denham highlights the positive results of the ICO’s engagement with the UK devolved administrations on the use of data in the fight against COVID-19.
ICO takes action against company for sending spam emails selling face masks during pandemic09/10/2020 12:25:00
A company that sent spam emails selling face masks during the pandemic has been fined £40,000 by the ICO and issued with an enforcement notice.
Statement on the outcome of the ICO’s compulsory audit of the Department for Education08/10/2020 09:10:00
The Information Commissioner’s Office (ICO) has published the outcome of a compulsory audit of the Department for Education DFE carried out in February 2020.
Blog: Elizabeth Denham on the conclusion of the ICO’s investigation into the use of personal data in political campaigning07/10/2020 09:10:00
There can be few cases that better illustrate how mainstream data protection has become than the ICO’s investigation into the use of personal data in political campaigning, including by the now defunct Cambridge Analytica.