
Views on news
Instagram has been issued a fine totalling €405 million by the Irish Data Protection Commission (DPC) after the social media platform was found to have violated the General Data Protection Regulation (GDPR). The complaint against Instagram focuses on the platform’s processing of children’s data.
Back in 2020, the DPC began investigating a setting that allowed users aged between 13-17 to set up business accounts that publicly displayed their phone numbers and email addresses. The watchdog found that the platform’s user registration system operated in such a way that new accounts would have contact details visibility set to “public” by default – unless the user actively selected “private”.
Although big tech companies are based in Ireland, it wasn’t the Irish Data Protection Commissioner by itself that dished out the fine – the European Data Protection Board played a major role in it too.
Many data breaches happen thanks to human error, but this one doesn’t seem to have, as it was by design that the data was put out in the public domain and therefore it’s considered a confidentiality breach, as well as an infringement, i.e., breaking of the law. But a penalty’s effectiveness can always be measured by the impact it makes. Fines should be combined with other sanctions for data breachers to regard noncompliance with GDPR as a business risk.
Where are we going with cloud security?
Organisations have to work with cloud providers in partnership as a secure infrastructure is as important as the controls that a provider puts in place.
Clarifying what is the providers and what the client’s responsibility is also key. Cloud providers always have best practices that they recommend to their clients, and they talk to different departments to learn about their particular needs. When you store data in the cloud, security is more straightforward, but data is going to be exported from the cloud to different devices.
Companies don’t always put enough emphasis on assurance and audits, partly because standard contractual terms are often pushed back at organisations by cloud providers giving them access to certain reports that are already out but not giving answers to clients’ specific requests. If the provider doesn’t let you do due diligence in the procurement phase, Article 28 (1.) in the GDPR entitles you to exclude the ones that are non-compliant from the procurement process (many still aren’t). See 28 (4) and page 11 of the French Data Protection Authority’s recommendations too.
The panel’s advice
Insist on GDPR compliance if your cloud provider only sends you a pdf and says you are covered.
They will show you their SSAE Certification for Data Centre, SOC 2 Type 1 and 2 reports and will most probably tell you that they are GDPR compliant.
Ask your provider to certify its compliance for the bits that they are responsible for.
If your cloud provider turns out to be non-GDPR compliant, find another one.
Do your homework before putting anything into the cloud. You’re well within your right to ask for evidence of whether they can action right-to-erasure-requests – i.e., whether they can destroy data or just put it in archives or whether they can correct data on command not just at the end of certain periods?
Make a good relationships with your cloud provider’s or processor’s data protection team. They’ll tell you if there is a problem.
Watch on-demand here.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543