Turkey's Data Protection Authority (KVKK) has fined Facebook for an API bugthat could have exposed the personal data of 300,000 Turkish users.
The amount that Facebook must pay is $270,000. This is a security issue, which Facebook itself had disclosed in December 2018.
The platform had announced the existence of a bug in its Photo API, which could have exposed photos of 6.8 million users that had not been published by the users themselves.
The bug was present in Facebook's code from September 13 to September 25, 2018. However, the platform stated that there was no evidence that users' photos had been compromised.
Despite Facebook's statement, the Turkish authorities decided to fine it for two reasons. The first reason is the delay in correcting the error and the second reason is that the company did not immediately notify the Personal Data Protection Authority about the incident and the implications this security on Turkish users.
Turkey is also investigating the September 2018 data breach case
Facebook has once again come into conflict with Turkish authorities. In September 2018, hackers exploited three flaws in the platform and stole the personal data of 30 million users. Turkey is investigating that case as well.
In March, Facebook submitted a comprehensive 30-page report explaining the September incident. However, the case is not over yet and Turkish authorities are still investigating.
Facebook has faced a lot of such issues in the past year. Not long ago, it was accused of storing millions of Facebook and Instagram passwords in plain text.
Turkey also investigates Microsoft
Last month, Microsoft said that hackers had breached its systems to view information from user accounts, such as email addresses, folder names, the "subject" of emails and email content.
Turkish authorities believe that this incident may have also affected Turkish users.
