# DPC Ireland IN-19-9-3: Structural Analysis of the Meta Decision and Consequences for DACH Controllers

> DPC IN-19-9-3 against Meta: analysis of the legal bases under Art. 6 GDPR, the fine and the consequences for Swiss and DACH controllers.

- Source: https://www.sidd.swiss/en/insights/dpc-ireland-in-19-9-3-an-overview-of-data-protection-measures-and-their-impact/
- Language: en
- Published: 2026-02-25
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Inquiry IN-19-9-3 of the DPC: subject matter and key data

With the final decision in proceeding IN-19-9-3 of 31 December 2022 (notified in January 2023) Ireland's DPC (Data Protection Commission) closed an inquiry opened in 2018 against Meta Platforms Ireland Limited regarding the Facebook service. The parallel decision IN-18-5-5 concerned the Instagram service. Based on the published decision text, the core issue was the legal basis for processing personal data for the purposes of personalised advertising and service improvement.

The DPC imposed on Meta a fine of EUR 210 million for the Facebook service and a corrective order under Art. 58(2)(d) GDPR requiring adjustment of the processing within three months. The decision was adopted under the consistency mechanism pursuant to Art. 65 GDPR and followed a binding decision of the European Data Protection Board (EDPB) of 5 December 2022. Dr. M. Hofstetter classifies the proceeding as one of the structurally most consequential supervisory cases to date.

## Legal basis: contract versus legitimate interests

The central question was whether personalised advertising can be classified as part of the contractual main service within the meaning of Art. 6(1)(b) GDPR. Meta had argued that personalisation was an integral component of the service offered. The EDPB and the DPC rejected this interpretation. Contractual necessity requires that the processing be objectively necessary for the performance of the agreed main service; mere desirability or commercial benefit is not sufficient.

This interpretation is in line with EDPB Guidelines 2/2019 on contractual necessity and with the CJEU judgment Meta Platforms of 4 July 2023 (Case C-252/21, ECLI:EU:C:2023:537). The consequence is a clear narrowing of the legal basis under Art. 6(1)(b) GDPR. Controllers that have based their processing model on this provision are obliged to switch to another legal basis, typically consent under Art. 6(1)(a) GDPR or legitimate interests under Art. 6(1)(f) GDPR.

## Transparency duties under Art. 13 GDPR

The DPC further found an infringement of the transparency duties under Art. 5(1)(a) in conjunction with Art. 12 and Art. 13 GDPR. The privacy notices were criticised for not presenting the legal basis for the individual processing purposes in a sufficiently clear and distinguishable manner. The DPC requires that the data subject be able to discern, without further research, on which legal basis which specific processing purpose rests.

This requirement reaches well beyond the individual case. It concretises the principle of transparency to the effect that a blanket enumeration of all theoretically conceivable legal bases is not sufficient. Controllers in the DACH region should review their privacy notices to determine whether the legal basis actually relied upon is identifiable for each processing purpose. This regularly also affects the privacy notices of Swiss controllers, which are subject to comparable duties under Art. 19 DSG.

## Fine, order and the consistency mechanism

The differentiation between fine, order and decision is particularly evident in proceeding IN-19-9-3. The fine covers the administrative fine under Art. 83 GDPR. The order under Art. 58(2)(d) GDPR required Meta to bring the processing operations into compliance with the GDPR within a three-month deadline. The decision as an administrative act additionally contains the reasoning and the information on legal remedies.

A particularity lies in the consistency mechanism. The DPC had foreseen a significantly lower fine in its draft decision. The EDPB decided in binding fashion under Art. 65 GDPR that the fine was to be increased and that an additional breach of the transparency duties was to be found. This constellation shows that the lead supervisory authority under Art. 56 GDPR does not decide autonomously but is embedded in the European cooperation model. For controllers this means that the expectations of the strictest authority involved become the factual common benchmark.

## Operational weaknesses: the lead auditor's view

A. Brunner classifies the structural deficiencies criticised in the proceeding from the perspective of an ISO 27001 lead auditor. Three weaknesses are transferable. First, a clean allocation of legal basis to the respective processing purpose in the Records of Processing Activities (ROPA) under Art. 30 GDPR is often missing. Second, privacy notices and ROPA are not maintained consistently, so that external information and internal documentation diverge. Third, changes of legal basis are not documented in versioned form, which substantially complicates evidence under the accountability principle of Art. 5(2) GDPR.

An effective countermeasure is the integration of the data protection management system with the ISMS under ISO/IEC 27001. In particular controls A.5.34 (Privacy and protection of PII) and A.5.31 (Legal, statutory, regulatory and contractual requirements) of ISO/IEC 27002:2022 provide the structural framework. A deeper classification is offered in our [ISO 27001 guide](https://www.sidd.swiss/en/insights/iso-27001-guide-2026/).

## What this means for Swiss companies

K. Aebischer brings the perspective of a Swiss SME CISO. Swiss controllers are directly affected in three constellations. First, where they fall within the scope of the GDPR under Art. 3(2) GDPR. Second, where they act as processors for European controllers and are drawn into the scope via the contractual chain. Third, where the DSG (Federal Act on Data Protection / FADP) triggers comparable transparency duties under Art. 19 DSG.

The operational consequence is unambiguous. Controllers should conduct an inventory of their processing purposes and, for each purpose, identify, document and communicate the legal basis in the privacy notices. Processing operations previously based on Art. 6(1)(b) GDPR should be critically reviewed for objective necessity. A comparative overview of the Swiss requirements is provided in our [DSG guide](https://www.sidd.swiss/einblicke/dsg-fadp-leitfaden/) (German-language pillar); the parallel EU view is covered in our [GDPR guide](https://www.sidd.swiss/en/insights/gdpr-guide-2026/).

## Implementation duties for DACH clients

Four concrete implementation duties for DACH clients can be derived from decision IN-19-9-3. First, all processing purposes are to be reviewed against their legal basis, with contractual necessity to be interpreted narrowly. Second, the privacy notices under Art. 13 GDPR must be structured so that for each purpose the legal basis is identifiable. Third, when relying on consent the requirement of freely given consent under Art. 7(4) GDPR must be observed, in particular in tying situations.

Fourth, the interface to cookie and tracking compliance under Art. 5(3) of the ePrivacy Directive must be reviewed, since many personalised advertising operations technically rely on storage and reading on end devices. N. Köhler notes that the update of the privacy notices requires a textual clarity that many standard templates fail to deliver. A comparative consideration of the roles is set out in our overview [DPO vs. CISO](https://www.sidd.swiss/en/insights/dpo-vs-ciso/).

## How SIDD supports you

SIDD supports controllers in implementing the requirements derivable from IN-19-9-3. In our mandate as [external DPO under GDPR Art. 37](https://www.sidd.swiss/en/services/data-protection-officer-eu) we accompany the review of legal bases, the adjustment of privacy notices and the communication with the lead supervisory authority. In our mandate as [Swiss data protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) under Art. 10 DSG we manage the parallel DSG duties under Art. 19 DSG.

For controllers without an establishment in the Union we provide the [EU Representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative). This function is especially relevant in DPC proceedings, since reachability of the responsible entity in the Union is a central criterion for the communication with the authority. As at the time of publication, further DPC proceedings on the platform economy are to be expected. The structural lessons from IN-19-9-3 remain the central reference point.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
