Facebook faces 'mass action' lawsuit over data breach
Digital Rights Ireland is urging European Facebook users who have been affected to sign up


Digital Rights Ireland (DRI) is commencing a “mass action” lawsuit against Facebook on behalf of people who have been caught up in the data breach affecting 533 million users.
Anyone who has been affected and lives in the European Union or European Economic Area should seek monetary damages from Facebook, stated the group, which pointed out that GDPR gives the right to monetary compensation where data protection rights have been breached.
Users who have been affected are being advised to check Have I Been Pwned to see if their data was found in the latest breach, and then to then join the mass action case against Facebook.
“We understand people's concerns, which is why we continue to strengthen our systems to make scraping from Facebook without our permission more difficult and go after the people behind it," a Facebook spokesperson told IT Pro.
"As LinkedIn and Clubhouse have shown, no company can completely eliminate scraping or prevent data sets like these from appearing. That's why we devote substantial resources to combat it and will continue to build out our capabilities to help stay ahead of this challenge.”
News of the lawsuit comes after the Irish Data Protection Commission (DPC) announced last week it has launched an inquiry into the alleged Facebook data leak. As the social network has its European headquarters in Dublin, it falls to the Irish regulator to investigate whether the social media giant complied with its data controller responsibilities when it came to processing personal data of its users.
The regulator found that of the 533 million users affected in the leak, a “significant number” are EU users, and it highlighted that much of the data seems to have been scraped some time ago from public Facebook profiles.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
The data was reportedly published in 2018 and 2019 and is thought to have been scraped between June 2017 and April 2018. This is important, as GDPR came into effect on 25 May 2018. If the social media company can demonstrate the scraping occurred before this date, any potential regulatory action would be referred to under the Data Protection Directive. This devolves the responsibility to member states.
The data, that was published on a low-level hacking forum, was downloadable for free and allowed anyone to look up a user’s record using their phone number. The information available included phone numbers, Facebook IDs, full names, previous locations, birth dates, relationship statuses and biographies.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Why keeping track of AI assistants can be a tricky business
Column Making the most of AI assistants means understanding what they can do – and what the workforce wants from them
By Stephen Pritchard
-
Nvidia braces for a $5.5 billion hit as tariffs reach the semiconductor industry
News The chipmaker says its H20 chips need a special license as its share price plummets
By Bobby Hellard
-
India’s new data protection bill continues to “facilitate state surveillance”
News Although data localisation requirements have now been removed, it’s down to the Indian government to select which countries data is allowed to be sent to
By Zach Marzouk
-
LinkedIn denies data breach that reportedly exposed 700 million user records
News Report claims 'breach' led to profiles belonging to 92% of LinkedIn users being put up for sale on a popular hacker forum
By Bobby Hellard
-
Privacy campaigners rally against "illegal" Clearview AI data scraping
News The notorious facial recognition firm claims to have a database of more than three billion images scraped from social media sites
By Bobby Hellard
-
Germany bans Facebook from using WhatsApp data over GDPR concerns
News Hamburg's data protection commissioner issues three-month ban days before the app's new privacy policy rolls out
By Bobby Hellard
-
Irish data watchdog to investigate Facebook data leak
News The regulator believes that Facebook may have infringed ‘one or more’ GDPR provisions following apparent leak of 533 million user records
By Sabina Weston
-
EU might force tech giants to share data with smaller rivals
News The Digital Services Act draft also suggests that firms may be banned from giving their own services preferential treatment
By Sabina Weston
-
Irish data watchdog orders Facebook to halt EU user data transfers to the US
News Nick Clegg suggests cancelling its transfer mechanism could cause chaos for businesses and the global economy
By Bobby Hellard
-
What is the Data Protection Act 1998?
In-depth Although data protection regulations have been updated, businesses may still find themselves sanctioned under the Data Protection Act 1998
By Dale Walker