The Data Protection Commission (DPC) in Ireland has imposed a €91 million fine on Meta Platforms Ireland Limited (MPIL) for storing user passwords in plain text (without encryption).

This happened five years ago, in 2019. At that time, Meta publicly disclosed that it had accidentally stored some user passwords in “plain text” on its internal systems. It notified the DPC, which launched an investigation into its practices for storing sensitive data .
Meta had said it found “certain passwords” stored in readable form during a security review earlier this year.
See also: EU: Fine on Meta for advertising practices?
The company did not say how many users were affected by the incident, but it estimated that it would have to notify “hundreds of millions of Facebook Lite users, tens of millions of other Facebook users,” and millions of Instagram users.
It is worth noting that the passwords were available to external parties, but no evidence of abuse or inappropriate access.
Storing account passwords without appropriate protections, such as encryption and access control, is a violation of the GDPR:
Article 33(1) – Personal data breach notification: Meta failed to timely notify the DPC of the storage of passwords in plain text, which constitutes a breach.
Article 33(5) – Documentation of personal data breach: Meta failed to properly document personal data related to the storage of user passwords in plain text, failing to maintain adequate records of the incident.
Article 5(1 )(f) – Integrity and confidentiality: Meta did not implement adequate security measures to ensure the protection of users' passwords.
Article 32(1) – Security of processing: Meta failed to implement appropriate technical and organizational measures to protect passwords (such as encryption), which would reduce the risk of unauthorized access.
The Irish Data Protection Authority has decided that for the above violations, and taking into account that Meta voluntarily informed the DPC, a formal reprimand should be issued and an administrative fine of 91 million euros should be imposed.
See also: TD Bank fined for sharing inaccurate customer data
The DPC will publish its full decision and information regarding the incident at a later date.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This breach highlights the critical importance of strong data protection practices for companies that handle sensitive user information. Storing passwords in plain text is a significant security flaw, exposing users to potential data breaches and unauthorized access. The DPC fine serves as a stark reminder to all organizations about the need to implement strong security measures, such as encryption password and regular auditing of security protocols, to protect user data. In addition, companies must remain vigilant and comply with data protection regulations to maintain user trust and avoid potential penalties.
See also: Clearview AI: Fined by the Netherlands for violating GDPR
As technology continues to advance and more data is generated, the need for strong security practices becomes even more critical. The consequences of a data breach can be devastating, not only for users but also for a company’s reputation and financial stability. Organizations must invest in strong security measures and continually update their processes to adapt to ever-evolving threats.
Source: www.bleepingcomputer.com
