(before you post a link to enforcementtracker.com please first compare the fine amounts with Facebook's revenue)
And, I might add, it's to their benefit. What we're entering is a future where only Amazon, Google, Facebook, and Apple can handle data.
You see this constantly on HN. "Don't handle your own auth, just let Firebase do it!" People are against anyone other than AWS touching their data. And, well, we're getting the dystopia we deserve. What else can I say.
Not having the data encrypted at rest seems to me a different infraction than the previous ones. The scale also matters, and that it isn't the first infraction.
And as I read it, not encrypting at rest is a breach of Article 6 and fined under Article 83 (5) (https://www.privacy-regulation.eu/en/article-83-general-cond...), which puts the fine limit at 4% of the annual turn-over.
Yes, it doesn't mean they have to fine as much, but the point remains, that this is in the category of the most severe infractions.
I'd argue this is a much bigger issue than the lack of at-rest data encryption, and yet nothing has been done.
They also appear to be ignoring Subject Access Requests with total impunity: https://ruben.verborgh.org/facebook/
which is not the same as data much be encrypted at rest.