Meta Ordered To Pay $567M Fine Over Child Safety Violations
August 11, 2026Read also: Piaggio fined €460,000 over employee email monitoring; Vietnam fines Grab for consumer protection violations; and more.

Meta ordered to pay a $567 million fine over child safety violations
A New Mexico judge ordered Meta to pay a $567 million fine over claims that its social media platforms harm and addict young users. The new fine comes on top of a $375 million penalty issued in March, bringing the total to $942 million.
The money will go into a fund created to reduce the harm caused by Meta’s platforms. The judge said the fund will support efforts to address the “wide-ranging impacts of the harm.” About $420 million will be used to help people already affected by Meta’s platforms. The money will fund clinical and behavioral health programs and professionals who can provide treatment. Other funds will support awareness and prevention efforts, including training for teachers and health professionals on how to identify and respond to social media-related harms affecting children.
The court also ordered Meta to make changes to its platforms in the state. Like counts must be removed for users under 18 unless a parent or guardian approves them. Push notifications for children must also be paused from 10 p.m. to 7 a.m.
The ruling also limits underage users to 90 hours of platform use per month, or about three hours a day.
The judge said Meta’s platforms have contributed to problems including sexual exploitation, disruption to education, and poor mental health among young people in New Mexico. He called the company’s actions a significant “public nuisance.” Meta said it plans to appeal the ruling.
Romanian watchdog fines a limited liability company for personal data violations
Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP) has fined the limited liability company Amato Bestseller SRL for multiple violations of personal data protection and electronic communications rules.
The investigation, which followed complaints from several customers, found violations of Article 32(4), Article 14, and Article 5(1)(c) in relation to Article 9 of Regulation (EU) 2016/679 (GDPR), as well as Article 12(1) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
Amato Bestseller SRL was fined a total of 285,395 lei (~€54,503). The company received a fine of 78,465 lei (~€15,000) for violating Article 32(4) of the GDPR, a fine of 52,310 lei, equivalent to €10,000, for violating Article 14, and a fine of 104,620 lei, equivalent to €20,000, for violating Article 5(1)(c) in relation to Article 9. The company was also fined 50,000 lei (~€9,550) for violating Article 12(1) of Law No. 506/2004.
The authority found that the company had failed to properly train employees and establish procedures to ensure the secure processing of personal data. Employees and former employees had unauthorized access for a period of time to customers’ personal data, including names, telephone numbers, family and marital details, profession, residence, income, social category, and health data.
The investigation also found that the company did not provide customers with correct and complete information as required by Article 14 of the GDPR. In addition, it processed excessive amounts of personal data, including health data, which violates the data minimization principle under Article 5(1)(c) in relation to Article 9 of the GDPR.
The authority also found that Amato Bestseller SRL made commercial calls using automated calling and communication systems without obtaining the prior express consent of the people contacted. This was considered a violation of Article 12(1) of Law No. 506/2004.
The authority also ordered the company to improve how it handles personal data and documents. The company must set clear rules for employee access and provide regular data protection training. It must also give people clear, complete, and accurate information about how their data is used, as required by Articles 14 and 12 of the GDPR. The company must only collect and use the data it needs, in line with Article 5(1)(c), and must obtain clear consent before sending unsolicited marketing messages.
Separately, the watchdog fined the Romanian retail company Homelux a total of 108,570 lei (€15,000 plus 30,000 lei) following a security incident affecting the firm’s website. The investigation found that the company had inadequate security measures, including outdated software and weak passwords, which exposed personal data such as names, addresses, emails, and passwords. The authority also found that the company used non-essential cookies without obtaining users’ consent.
Italian regulator fines Piaggio €460,000 over employee email monitoring
Italy’s data protection authority Garante has fined the motor vehicle maker Piaggio €460,000 for improperly monitoring and storing employees’ company emails.
The decision followed complaints from two former employees. Garante found that Piaggio had accessed more than 100 emails during their employment while investigating suspected misconduct. Some of the emails were nearly two years old.
According to Garante, Piaggio backed up employees’ emails throughout their employment and kept them for up to five years after they left the company. Email logs were also stored for six months. The regulator said the practices violated the EU’s General Data Protection Regulation (GDPR) and Italian employment law.
Piaggio later shortened its email retention period to three months after an employee leaves. However, Garante said the company’s handling of the complainants’ data was still unlawful. The watchdog also ordered Piaggio not to access the stored email content collected through its company systems.
In a separate case, the data protection authority fined Italy’s largest non-profit consumer protection organization Altroconsumo €280,000 for unlawfully using personal data for marketing and failing to respond to data protection requests on time. The company sent promotional emails to people who had not completed registration and had not agreed to the contractual relationship.
The Metropolitan City of Sassari was also fined after a misconfigured IT system allowed unauthorized employees to access documents containing personal data. The Garante found violations of GDPR principles on confidentiality, security, accountability, and data protection by design and by default.
NYDFS fines money transmitter $250,000 over cybersecurity failures
The New York State Department of Financial Services (NYDFS) has fined money service business Order Express $250,000 for violations of New York’s cybersecurity regulation.
The investigation, launched after the company reported a ransomware attack, found weaknesses in Order Express’s cybersecurity protections, including inadequate policies for system updates and weak cybersecurity risk assessments. Order Express has since fixed the issues found by the NYDFS investigation.
The company is exempt from many requirements under the state’s cybersecurity regulation because of its limited revenue. However, the NYDFS said the company still failed to meet certain applicable cybersecurity requirements.
New York’s cybersecurity regulation, known as 23 NYCRR Part 500, took effect in March 2017. An updated version became effective in November 2023, with stronger requirements aimed at improving cybersecurity governance, reducing risks, and protecting businesses and consumers from cyber threats.
Vietnam fines Grab VND 1.36 billion for consumer protection violations
Vietnam’s National Competition Commission has fined the ride-hailing app Grab VND 1.36 billion (about €44,000) for violating consumer protection regulations.
The commission said Grab failed to provide consumers with a clear choice over whether their personal information could be shared with third parties. It also found problems with Grab’s general transaction terms, including prohibited provisions and the failure to clearly state when the terms would take effect.
The watchdog also said Grab did not properly disclose sponsorships involving influencers, failed to fully and accurately display customer reviews and ratings, and did not make certain policies for vulnerable consumers publicly available.
Grab was ordered to stop the violations and review and update its policies to comply with the law.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program