The Irish Data Protection Commission (DPC) has formally fined WhatsApp Ireland €5.5 million ($5.95 million) for breaching the European General Data Protection Regulation (GDPR). This is one of the largest GDPR fines to date, underscoring how critical it is for companies to comply with data privacy regulations in order to protect their customers’ information
See also: Learn how to quickly translate messages on WhatsApp

The regulatory authority has ordered WhatsApp to align its data processing practices within half a year, otherwise it risks facing an additional penalty.
On 25 May 2018, the Data Protection Commission opened an investigation into a possible infringement of the regulation, brought to its attention by a German individual. On the same day, WhatsApp issued a new set of Terms of Use and asked all EU-based users to accept them in order to continue using the app's core functionality .
The complaint filed with the DPC alleged that WhatsApp forced users to agree to the changes or they would not be able to continue using its software. Therefore, customers had to agree to the handling of their personal data in order to access the application.
This constitutes a direct violation of article 7 paragraph 32 of the GDPR, which explicitly states that user consent must be given freely without undue influence or manipulation.
After extensive examination, the DPC found:
- WhatsApp Ireland's failure to clearly explain the legal basis or the explicit reasons for its request to process user data violates Articles 12 and 13 of the GDPR.
- WhatsApp Ireland is not at fault for the violation of Article 7 concerning forced consent, given that it does not depend on users' approval for providing its service or its use as a legitimate basis for processing customers' personal data.
See also: WhatsApp Message Yourself: Have a conversation with yourself

The first point will remain exempt from further fines, given that the Personal Data Protection Commission has already imposed heavy penalties on WhatsApp for related issues.
“ After imposing a hefty fine of €225 million on WhatsApp Ireland for breaches of its transparency obligations, the DPC considered that additional fines or remedial measures were unnecessary ,” the decision says .
The second point is that the rejection of the data subject's claims by the DPC does not terminate the case, as the German supervisory authority will now conduct its own investigation.
Irish WhatsApp was forced to pay a hefty fine of 5.5 million euros for violating Article 6 of the GDPR, which requires transparency and lawful conduct regarding data protection procedures.
To ensure compliance with Article 9 of the GDPR on the “processing of special categories of personal data”, the DPC will launch an investigation into all processing operations carried out by WhatsApp on service . The data protection service is making efforts to reveal whether WhatsApp uses and processes sensitive information for marketing and whether access to this data is granted to third parties.
See also: Instagram: €405 million fine for GDPR violation
GDPR stands for General Data Protection Regulation. It’s an EU law passed in 2016 that affects how companies store, process, and protect the personal data of EU citizens. The regulation applies to any business that processes the personal data of EU residents, regardless of where it’s located. So even if a business is based in the United States, if it has customers or potential customers who live in European countries, then it must comply with the GDPR.
