The DPC said it is also imposing a range of corrective measures, writing: “The decision imposed a reprimand and an order requiring MPIL [Meta Platforms Ireland Limited] to bring its processing into compliance by taking a range of specified remedial actions within a particular timeframe.”The penalty relates to an inquiry which was opened by the DPC on April 14, 2021, following media reports of more than 530 million Facebook users’ personal data — including email addresses and mobile phone numbers — being exposed online.The company followed that by saying it believed the data had been scraped from Facebook profiles by “malicious actors” using a contact importer feature it offered up to September 2019, before it tweaked it to prevent data abuse by blocking the ability to upload a large set of phone numbers to find ones that matched Facebook profiles.The DPC confirmed its inquiry looked at a variety of contact search and importer tools the company offers on its platforms between the date the GDPR came into application and the date of changes to the contact importer tool Facebook made in fall 2019.Those supervisory authorities agreed with the decision of the DPC,” the regulator also said — putting a spotlight on the lack of disagreement over this particular decision, which is often not the case with cross-border GDPR enforcements (while disputes between EU regulators can often substantially increase the time it takes to enforce the GDPR — hence this final decision has landed relatively quickly).“Specifically, to the extent that MPIL is engaged in ongoing processing of personal data which includes a default searchability setting of ‘Everyone’, this order requires… MPIL to implement appropriate technical and organisational measures regarding the Relevant Features in respect of any ongoing processing of personal data, for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed, and that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons,” he added, emphasizing: “This order is made to ensure compliance with Article 25(2) GDPR.”“Relevant Features” in this context are Facebook Contact Importer; Messenger Contact Importer; Instagram Contact Importer; and Messenger Search; and its variant Messenger Contact Creator features."