Republic of Ireland v. Meta (2023): Data Sovereignty

This article is written by Al-Zahraa Ahmed Elsenbawy, Faculty of Law, Alexandria University, Egypt. This article examines the Irish proceedings involving Meta, the EDPB’s binding decisions of 2022, the subsequent fines, and the CJEU’s ruling in Meta Platforms v. Bundeskartellamt (C-252/21). Together, these decisions establish a new framework for data sovereignty in the digital Single Market, with implications for competition law, platform governance, and digital constitutionalism.

The architecture of digital governance within the European Union rests on the interaction between supranational regulation and the enforcement powers of individual Member States. This tension emerged clearly in the jurisdictional dispute surrounding Meta Platforms Ireland Limited, which culminated in landmark decisions between 2022 and 2023 and reshaped the enforcement of the General Data Protection Regulation (GDPR).

The proceedings raised a central question: when a multinational data controller designates an establishment in one Member State as its EU headquarters, does the supervisory authority of that state possess exclusive jurisdiction over cross-border data processing? The answer, developed through the Irish Data Protection Commission (DPC), the European Data Protection Board (EDPB), and the Court of Justice of the European Union (CJEU), was a qualified no, carrying important consequences for European data governance.

Case Laws and Legal Analysis

1. The Irish Supervisory Framework and Its Structural Tensions

Meta Platforms Ireland Limited acts as data controller for Facebook users outside the United States and Canada because the company’s regional headquarters are located in Dublin. Under Article 56 GDPR, the supervisory authority hosting the controller’s main establishment acts as the lead supervisory authority for cross-border processing under the one-stop-shop principle.

This arrangement created significant tensions. Supervisory authorities in Germany, France, Belgium, and Austria repeatedly argued that the DPC’s draft decisions failed to provide adequate protection. Acting as concerned supervisory authorities under Article 60(4) GDPR, they objected to the DPC’s position regarding Meta’s legal basis for behavioural advertising. When these objections could not be resolved, the dispute-resolution mechanism under Article 65 GDPR transferred the matter to the EDPB for binding resolution.

2. EDPB Binding Decisions 3/2022 and 4/2022 — The €390 Million Fines

In December 2022, the EDPB adopted Binding Decision 3/2022 concerning Instagram and Binding Decision 4/2022 concerning Facebook. Both decisions rejected Meta’s claim that Article 6(1)(b) GDPR, relating to the performance of a contract, justified behavioural advertising. The Board distinguished between processing necessary for service delivery and processing undertaken for commercial convenience. Personalised advertising fell within the latter category. Including advertising as a platform feature did not make it contractually necessary.

By directing the DPC to issue infringement findings and fines, the EDPB exercised its Article 65 powers for only the second and third times since the GDPR entered into force, highlighting the importance of these decisions. Following those instructions, the DPC issued final decisions in January 2023 imposing fines totalling €390 million on Meta. Their significance lay not in their amount, but in the fact that they resulted from a supranational override of the lead supervisory authority. The decisions confirmed that the EDPB can effectively review national regulators within the one-stop-shop framework.

2. Meta Platforms v. Bundeskartellamt (C-252/21) — July 2023

The CJEU’s July 2023 ruling originated from the German Federal Cartel Office’s investigation into Meta’s cross-platform data aggregation practices. The referring court asked whether a national competition authority could assess GDPR compliance within an Article 102 TFEU abuse-of-dominance inquiry.

The Court established three principles. First, competition authorities may examine GDPR compliance when necessary to determine abuse of dominance, but they cannot replace data protection authorities or contradict their binding decisions. Second, the Court reaffirmed that consent under Article 7 GDPR requires genuine freedom of choice. A dominant platform conditioning access on intrusive processing cannot rely on coerced consent. Third, aggregating personal data across Facebook, Instagram, WhatsApp, and third-party websites without purpose-specific consent may violate the GDPR while simultaneously strengthening market dominance contrary to Article 102 TFEU.

This approach reflects what scholars describe as regulatory intersectionality. A single act of data processing may constitute a GDPR infringement, an abuse of dominance, and a Digital Markets Act violation. These legal frameworks must therefore operate in a coordinated manner.

4. The ‘Pay or Consent’ Model and EDPB Opinion 8/2024

Following the 2023 decisions, Meta introduced a subscription model in the EU and EEA that allowed users either to pay for an ad-free experience or accept behavioural advertising. In Opinion 8/2024 issued in April 2024, the EDPB concluded that such binary structures generally do not satisfy GDPR requirements for valid consent when applied by large online 5 platforms. Genuine freedom of choice cannot exist where the alternative to consent involves a significant financial burden.

These developments establish an important principle: where platforms possess substantial economic power, consent to advertising-related processing requires a genuinely equivalent and accessible alternative. Consequently, the data-or-pay model is unlikely to provide a sustainable compliance strategy for dominant platforms.

Conclusion

The Meta proceedings of 2022 and 2023 represent an important stage in the development of European data protection law. They revealed the limitations of the one-stop-shop mechanism and demonstrated the willingness of the EDPB to exercise Article 65 powers when national authorities provide insufficient protection.

The CJEU’s ruling in C-252/21 also weakened the traditional separation between competition law and data protection law. Data are no longer viewed solely as a privacy concern; they have become a source of market power, and their unlawful accumulation may constitute both a regulatory violation and an anticompetitive practice.

As the Digital Markets Act expands obligations for gatekeepers and the EDPB continues refining consent standards, the Meta decisions will remain central to the development of digital constitutionalism. Their central lesson is clear: the exploitation of structural power to obtain personal data without genuinely free consent is incompatible with both fundamental rights and fair competition.

Frequently Asked Questions

1. What is the one-stop-shop mechanism, and why was it criticised in the Meta case?

    Under Article 56 GDPR, the supervisory authority of a controller’s main establishment acts as the lead regulator for cross-border processing. In Meta’s case, this role belonged to Ireland’s DPC. Criticism emerged because several Member States considered the DPC’s approach insufficient, ultimately requiring intervention by the EDPB.

    2. Can a national competition authority enforce the GDPR?

      Not directly. In C-252/21, the CJEU held that competition authorities may assess GDPR compliance within abuse-of-dominance investigations but cannot assume the role of data protection authorities or contradict their decisions.

      3. Why did the contractual necessity argument fail?

        The EDPB distinguished between processing necessary for providing a service and processing that is merely commercially beneficial. Behavioural advertising was considered commercially useful rather than objectively necessary.

        4. Why are the €390 million fines legally significant?

          Their importance extends beyond their size. They resulted from binding EDPB instructions overriding the DPC’s preferred approach, confirming the Board’s supervisory role within the GDPR framework.

          5. Does the ‘pay or consent’ model satisfy GDPR requirements?

            According to EDPB Opinion 8/2024, it generally does not for large platforms. Requiring users to pay substantial fees in order to avoid behavioural advertising undermines the voluntary nature of consent required under Article 7 GDPR.