Twitter International Company – €450,000 Fine (Ireland, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Twitter was fined €450,000 by Ireland's data protection authority for not reporting a data breach on time and failing to document it properly. This is important because it underscores the need for companies to act quickly and thoroughly when handling data breaches. Social media platforms must ensure they meet GDPR's strict timelines and documentation standards.
What happened
Twitter failed to notify the Irish DPA of a data breach within the required 72-hour period and did not document the breach adequately.
Who was affected
Twitter users whose private posts were accidentally made public due to a bug in the Android app.
What the authority found
The Irish DPA concluded that Twitter did not comply with GDPR's requirements for timely breach notification and proper documentation.
Why this matters
This case emphasizes the importance of quick and thorough responses to data breaches. It serves as a warning to companies about the consequences of failing to meet GDPR's reporting and documentation obligations.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Irish DPA (DPC) fined Twitter International Company EUR 450,000 for violating Art. 33 (1) GDPR and Art. 33 (5) GDPR for failing to notify the DPA in a timely manner of a data breach and not adequately documenting that breach. The data breach concerned the privacy settings of user posts on the social media platform Twitter. There, users have the option to set the visibility of their posts to private or public. Private posts can only be seen by subscribers of the respective user profile, while public posts are visible to the public. A programming bug in Twitter's Android app resulted in some private posts being visible to the public. The DPA found that Twitter had not properly fulfilled its reporting and documentation obligations. Twitter's legal team became aware of the error on January 2nd, 2019, and it was not until January 8th that the company informed the DPC. Consequently, the company failed to inform the DPC within the 72-hour period required by Art. 33 (1) GDPR. Furthermore, it had failed to adequately document the incident in accordance with Art. 33 (5) GDPR.
Related Enforcement Actions (0)
No other enforcement actions found for Twitter International Company in IE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 December 2020
Authority
Data Protection Commission
Fine Amount
€450,000
Enforcement Tracker ID
ETid-485
About this data
Cite as: Cookie Fines. Twitter International Company - Ireland (2020). Retrieved from cookiefines.eu
Last updated: