Apple & Meta Fined €700m By EU Commission

The Commission of the European Union (EU) has fined Apple and Meta a combined total of €700m (£599m). These fines are for the companies' violation of the Digital Markets Act (DMA) and are the first penalties to be applied since the 2024 legislation came into force.

It is aimed at reducing the market power of big technology firms and both companies have 60 days to comply or risk further fines.

The penalties threaten to cause more tension between the EU and US President Trump, as the two sides discuss a deal to avoid imposition of sweeping tariffs on the EU.

Apple has been fined €500 million for stopping app developers from offering cheaper deals outside the App Store. Meta has a €200 million fine for its “pay or share data” model on Facebook and Instagram, which the EU said violated users’ rights. "We have a duty to protect the rights of citizens and innovative businesses in Europe," Commissioner Henna Virkkunen said in a statement.

The two tech firms have reacted angrily, with Meta accusing the EU of "attempting to handicap successful American businesses" and Apple saying it was being "unfairly targeted" and forced to "give away our technology for free."

The fines are lower than some of those issued by the EU in the past but come at an extremely sensitive time, with trade tensions with the US heightened.

The European Commission started both investigations in 2024 following introduction of the DMA. 

  • This case against Apple was over its App Store. The Commission says it must freely offer alternative app marketplaces to users and app developers, and says Apple was in breach of this.

Apple said the Commission had made "a series of decisions that are bad for the privacy and security of our users, bad for products, and force us to give away our technology for free." It also accused the Commission of moving the goal posts during their meetings.

  • Meta's fine was over the way it handled cookies, the bits of code embedded into websites, which collect information data about users. Meta introduced a "consent or pay" model on Facebook and Instagram, which meant users had to choose between allowing cookies to track them, or pay a monthly subscription. 

The Commission says this model did not allow users to freely consent to how their data was used.
In both cases, the Commission says the size of the fine takes into account "the gravity and duration of the non-compliance". 

Meta said the ruling means Chinese and European companies are allowed to operate to different standards compared to American businesses. "This isn't just about a fine; the Commission forcing us to change our business model effectively imposes a multi-billion-dollar tariff on Meta while requiring us to offer an inferior service," it said in a statement.

Both organisations strongly denied wrongdoing. Apple said it will appeal, calling the fine unfair and harmful to user privacy and security. Meta also hit back, saying the EU was hurting successful US firms while giving others easier treatment. They claimed the rules force them to change their business models unfairly.

The size of the fines highlight the EU’s seriousness about data and technology regulation, even though it risks upsetting trade talks with the US. Despite vocal criticism, the EU has been resolute in requiring US  companies operating in EU jurisdictions to follow the law and treat their European users fairly. 

EU Commission  |   WSJ   |    BBC   |   Zero Hedge   |    Arab News   |   Daily Times   |   IT Daily  

Image: Ideogram

You Might Also Read: 

Google's Online Advertising Technology Ruled Illegal:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 





 

« How CISOs Can Speak The Language Of Risk & Resilience 
M&S Chaos: Leading British Retail Chain Attacked »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Law Enforcement Cyber Center (LECC)

Law Enforcement Cyber Center (LECC)

LECC is designed to assist police, digital forensic investigators, detectives, and prosecutors who are investigating and preventing crimes that involve technology.

Bounga Informatics

Bounga Informatics

Bounga Informatics provides Digital Forensics, E-Discovery, and Endpoint Security software, hardware, and training in Singapore and other countries in Asia Pacific.

Telelogos

Telelogos

Telelogos is a European provider of Enterprise Mobility Management software, Digital Signage software and Data Transfer and Synchronization software.

Data Protection People

Data Protection People

Data Protection People are specialists in Data Privacy, Governance, and Information Security.

OcuCloud

OcuCloud

OcuCloud protects businesses' valuable information in the cloud, preventing security breaches caused by employees and remote vendors.

Asset Guardian Solutions (AGSL)

Asset Guardian Solutions (AGSL)

Asset Guardian are dedicated to protecting the integrity of process control systems software that is used to control operations and production processes.

Onfido

Onfido

Onfido is building the new identity standard for the internet. We digitally prove people’s real identities using a photo ID and facial biometrics.

Seknox

Seknox

Seknox TRASA™ protects your business from insider threats.

Sec-Ops

Sec-Ops

Sec-Ops is a forward thinking cyber security company, formed by a group of security enthusiasts with years of experience and backgrounds in the technology and the government industries.

Magna5

Magna5

Magna5 is a managed IT service provider focusing in network and server monitoring, backup and disaster recovery, cybersecurity, help desk and SD-WAN.

Kubus Hitam

Kubus Hitam

Kubus Hitam are a research-based company focused on cyber security. we strongly believe that innovation and safety are the two keywords for the future business market.

TriCIS

TriCIS

TriCIS design and engineer highly secure integrated solutions that meet the highest government and military security standards, providing information assurance to organisations across the globe.

Chugach Government Solutions (CGS)

Chugach Government Solutions (CGS)

CGS performs work for the Federal Government across 4 unique core lines of business, including: Facilities Management and Maintenance, Construction, Technical IT and Cyber Services, and Educational Se

Lightpath

Lightpath

Lightpath is revolutionizing how organizations connect to their digital destinations by combining our next-generation network with our next-generation customer service.

Health Sector Cybersecurity Coordination Center (HC3) - USA

Health Sector Cybersecurity Coordination Center (HC3) - USA

HC3 was created by the US Department of Health and Human Services to aid in the protection of vital, controlled, healthcare-related information.

CodeSecure

CodeSecure

CodeSecure provides industry-leading static application security testing (SAST) tools that help organizations identify and remediate vulnerabilities early in the development lifecycle.