
The UK Information Commissioner's Office (ICO) has confirmed that Facebook is being fined GBP 500,000 for serious violations of data protection law. The ICO announced its intention to fine the company in July as part of a wider investigation into the use of data analytics for political purposes.
The fine is the maximum amount allowable under laws at that time, the Data Protection Act 1998. This was replaced in May by the new Data Protection Act 2018, which gives the ICO news powers including maximum fines of GBP 17 million or 4 percent of global turnover.
Between 2007 and 2014, Facebook allowed app developers to access the personal information of its users without clear and informed consent. Access was permitted even if users had not downloaded the app themselves and were only 'Facebook friends' with people who had. The ICO found that at least one million UK users had their personal data harvested as a result.