October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why Twitter Was Fined €450,000 in Europe Over a Bug That Exposed Protected Tweets

Twitter’s €450,000 GDPR fine followed a finding that its Irish company notified the DPC late and kept inadequate breach records after an Android bug could make protected tweets public.
From TheFinanceBase Team3 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Twitter’s Irish regulator imposed a €450,000 fine after finding that Twitter International Company (TIC) reported a data breach late and failed to keep adequate records about it. The case followed an Android bug that could make protected tweets public when an account holder changed their email address. The frequently reported “nearly $550,000” is an approximate conversion: the Irish Data Protection Commission (DPC) stated the fine as $500,000 and estimated it at €450,000 in its decision.

What the Android bug did

The bug affected Twitter for Android. If someone with a protected account changed the email address associated with it, the account could become unprotected, making tweets that had been limited to followers publicly accessible. TIC’s breach notification form described the issue as follows: “if a Twitter user with a protected account, using Twitter for Android, changed their email address the bug would result in their account being unprotected.” The DPC decision quotes that wording from TIC’s form.

According to the DPC’s decision, the bug was introduced on 4 November 2014 and fully fixed on 14 January 2019. TIC reported that 88,726 users in the EU and European Economic Area were affected. That is the reported count, not a confirmed complete total: the DPC noted that retention limits on available logs prevented Twitter from identifying everyone who might have been affected.

Why the DPC said Twitter reported the breach late

The case concerned TIC’s obligations to notify the regulator and document a personal data breach—not whether creating the software bug itself violated every possible GDPR security requirement. The DPC found that TIC should have been aware of the breach by 3 January 2019 at the latest, even though TIC said it first learned of it from its processor on 7 January.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Date What happened
26 December 2018 An external contractor in Twitter’s Bug Bounty Program first reported the bug.
29 December 2018 The contractor communicated its assessment to Twitter Inc.
2 January 2019 Twitter Inc. began an internal Information Security review.
3 January 2019 Twitter Inc. assessed the incident as a potential personal data breach and decided to start its incident response plan.
4 January 2019 An incident-management ticket was opened, but a process failure meant TIC’s Data Protection Officer was not added, delaying notification to TIC.
7 January 2019 TIC said it first became aware of the breach through its processor.
8 January 2019 TIC notified the DPC.

The DPC considered both the gap between the contractor’s assessment and the start of Twitter’s security review, and the later failure to alert TIC’s Data Protection Officer. Twitter attributed the earlier delay to the winter holiday schedule; the DPC did not consider the holiday period a reasonable basis for neglecting data-protection risks.

What GDPR requirements were breached

The DPC found that TIC infringed two provisions of the General Data Protection Regulation:

  • Article 33(1): The regulator concluded that TIC’s notification was late, applying the standard that notification should be made without undue delay.
  • Article 33(5): TIC’s records did not adequately set out the breach’s facts and effects, explain the notification delay, or show how the risk to affected users had been assessed. The DPC had to make multiple inquiries to clarify the circumstances.

The decision was limited to breach notification and recordkeeping. The European Data Protection Board (EDPB) could not establish additional or alternative infringements under Articles 5(1)(f), 5(2), 24, or 32 on the factual record before it. The fine therefore should not be described as a penalty for the bug alone or as a finding that Twitter violated every security-related GDPR duty.

How the fine reached €450,000

The DPC adopted its final decision on 9 December 2020. Other supervisory authorities objected to parts of the draft decision, including the proposed fine. When the authorities could not reach consensus, the matter went to the EDPB under Article 65 of the GDPR. The EDPB issued a binding decision directing the DPC to reassess and increase the fine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The DPC’s final decision expressed the fine as $500,000 and estimated that amount as €450,000. The regulator’s announcements identify the administrative fine as €450,000, which is the appropriate figure to use for the official European penalty. In October 2021, the Dublin Circuit Court confirmed the €450,000 fine. The DPC described the sanction as “an effective, proportionate and dissuasive measure.”

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the decision does—and does not—establish

The decision illustrates that a breach-reporting case can turn on internal escalation and documentation as well as on the underlying technical issue. The DPC’s finding rested on when TIC ought to have known about the incident, when it notified the regulator, and whether its records captured the required information. It does not establish that 88,726 was the maximum number of people affected, nor does it resolve claims outside the notification and documentation questions addressed in the inquiry.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.