Twitter International Company – €450,000 Fine (Ireland, 2020)

€450,000Data Protection Commission15 December 2020Ireland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Twitter was fined €450,000 by Ireland's data protection authority for not reporting a data breach on time and failing to document it properly. This is important because it underscores the need for companies to act quickly and thoroughly when handling data breaches. Social media platforms must ensure they meet GDPR's strict timelines and documentation standards.

What happened

Twitter failed to notify the Irish DPA of a data breach within the required 72-hour period and did not document the breach adequately.

Who was affected

Twitter users whose private posts were accidentally made public due to a bug in the Android app.

What the authority found

The Irish DPA concluded that Twitter did not comply with GDPR's requirements for timely breach notification and proper documentation.

Why this matters

This case emphasizes the importance of quick and thorough responses to data breaches. It serves as a warning to companies about the consequences of failing to meet GDPR's reporting and documentation obligations.

GDPR Articles Cited

AI-verified

Art. 33(1) GDPR
View original scraped data
Art. 33(1) GDPR
(5) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary
Detailed

The Irish DPA (DPC) fined Twitter International Company EUR 450,000 for violating Art. 33 (1) GDPR and Art. 33 (5) GDPR for failing to notify the DPA in a timely manner of a data breach and not adequately documenting that breach. The data breach concerned the privacy settings of user posts on the social media platform Twitter. There, users have the option to set the visibility of their posts to private or public. Private posts can only be seen by subscribers of the respective user profile, while public posts are visible to the public. A programming bug in Twitter's Android app resulted in some private posts being visible to the public. The DPA found that Twitter had not properly fulfilled its reporting and documentation obligations. Twitter's legal team became aware of the error on January 2nd, 2019, and it was not until January 8th that the company informed the DPC. Consequently, the company failed to inform the DPC within the 72-hour period required by Art. 33 (1) GDPR. Furthermore, it had failed to adequately document the incident in accordance with Art. 33 (5) GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Twitter International Company in IE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

15 December 2020

Authority

Data Protection Commission

Fine Amount

€450,000

Enforcement Tracker ID

ETid-485

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Twitter International Company - Ireland (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: