This decision is from the Irish data privacy regulator, DPC. They are "in charge" of this investigation because Facebook's EU subsidiary is in Ireland. They are not a "lead" regulator in any sense of the word.
In fact, this decision does not come from the DPC. The DPC's decision was to pussy out and issue a smaller fine, and rubber-stamp several of Facebook's arguments. Their authority to do so was overturned by the regulators for other countries, and by the EDPB (EU-level agency). The EDPB is also requiring the DPC to do more investigations which will probably eventually result in even more fines.
I have a comment downthread about the "meat" of this decision. Before GDPR went into effect, WhatsApp updated their terms of service so that some processing used Contract instead of Consent as a legal basis, which changes what rights users have with respect to that data processing. They go fined because this change was not well-communicated, and because other regulators (not the DPC) say that the processing is not actually part of the contract users have with Whatsapp.
GDPR fines tend to be about specific issues related to specific complaints. Whatsapp was fined previously 250 million Euro for having terribly confusing privacy policy; this fine is related to two rather specific parts of their data processing. There has NOT been a general "is Whatsapp in its entirety compliant with GDPPR" investigation yet. The EDPB-mandated investigation is creeping closer to that.