News: 1608058748

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Twitter scores a first for big tech after being fined €450,000 by Ireland's data watchdog for violating the EU's GDPR

(2020/12/15)


Ireland's Data Protection Commission (DPC) has fined Twitter €450,000 after ruling a bug in the firm's Android app that allowed users private messages to be publicly viewed infringed the EU's General Data Protection Regulation (GDPR).

The fine is a first levied by the Irish government against one of the so-called Big Tech outfits since the European regulations were introduced in [1]May 2018 . The Emerald Isle is notoriously [2]tech-friendly on the tax and regulation front and the new fine is unlikely to cause the micro-blogging platform sleepless nights.

"The DPC’s investigation commenced in January, 2019 following receipt of a breach notification from Twitter and the DPC has found that Twitter infringed Article 33(1) and 33(5) of the GDPR in terms of a failure to notify the breach on time to the DPC and a failure to adequately document the breach. The DPC has imposed an administrative fine of €450,000 on Twitter as an effective, proportionate and dissuasive measure" the [3]DPC said .

"The draft decision in this inquiry, having been submitted to other Concerned Supervisory Authorities under Article 60 of the GDPR in May of this year, was the first one to go through the Article 65 (“dispute resolution”) process since the introduction of the GDPR and was the first Draft Decision in a “big tech” case on which all EU supervisory authorities were consulted as Concerned Supervisory Authorities," it added.

Article 33(1) requires that notification of a breach be given "without undue delay and, where feasible, not later than 72 hours after having become aware of it." Article 33(5) is more concerned with the documentation process around it. The DPC considered the infringements "to be moderately serious in terms of their gravity" and upped the amount from the previous range in the draft decision ($150,000-$300,000).

Under GDPR, companies can be fined up to 4 per cent of their turnover or up to €20m, whichever is greater.

Things kicked off at the beginning of 2019 when [4]a flaw in the Twitter's Android app came to light that had inadvertently exposed private tweets after a "Protect your Tweets" setting was changed.

It's been a long and winding path for the case and reaching a unified agreement with other supervisory bodies across EU member states had apparently proven challenging amid attempts to harmonise interpretations of the law.

Ireland's Commissioner for Data Protection, Helen Dixon, [5]reportedly said at the Web Summit conference in Lisbon this month that "the process didn't really work".

“It is the first time EU data protection authorities have stepped through the process so maybe it can only get better from here,” she said.

To put the fine into context, Twitter reported revenues of $3.46bn in [6]calendar 2019 and made a net profit of $1.47bn. Today's fine will barely leave a blemish on its balance sheet.

However, the company is not revelling in being the first of the tech giants to be fined under GDPR by Ireland.

"Twitter worked closely with the Irish Data Protection Commission (IDPC) to support their investigation. We have a shared commitment to online security and privacy, and we respect the IDPC's decision, which relates to a failure in our incident response process," aspokesperson for Twitter told The Register .

"An unanticipated consequence of staffing between Christmas Day 2018 and New Years' Day resulted in Twitter notifying the IDPC outside of the 72-hour statutory notice period. We have made changes so that all incidents following this have been reported to the DPC in a timely fashion.

"We take responsibility for this mistake and remain fully committed to protecting the privacy and data of our customers, including through our work to quickly and transparently inform the public of issues that occur. We appreciate the clarity this decision brings for companies and consumers around the GDPR's breach notification requirements. Our approach to these incidents will remain one of transparency and openness." ®

Get our [7]Tech Resources



[1] https://www.theregister.com/2018/05/25/gdprmageddon_do_you_think_its_all_over_its_not/

[2] https://www.theregister.com/2018/09/19/apple_alleged_state_aid_ireland/

[3] https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-twitter-inquiry

[4] https://www.theregister.com/2019/01/18/twitter_bug_protected_tweets/

[5] https://www.irishtimes.com/business/technology/twitter-fined-450-000-by-data-protection-commission-for-gdpr-breach-1.4437306

[6] https://s22.q4cdn.com/826641620/files/doc_financials/2019/q4/Q4-2019-Shareholder-Letter.pdf

[7] https://whitepapers.theregister.com/

The fine could hardly be smaller

Woodnag

I doubt Twitter even care. Ireland's DPC showing their gums, not their teeth.

Just a formality?

chivo243

What would happen if the watchdog didn't issue a required fine?

Re: Jelly of the month

Keven E

There'd be no x-mass bonuses this year!

https://youtu.be/TQXuazYI_YU

How impressive

doublelayer

So, the story is that Twitter had a bug which was clearly not intended and affected a subset of their users, failed to report in time, and got a fine so small they've already forgotten about it. Meanwhile, other companies do deliberate things which impact all of the customers, don't hide it, and get no consequences. Why would any company be worried about this? If this is the size of fines being handed out, they have nothing to worry about. If this is the only kind of investigation that gets done, one which can be completed by a simple program*, they have nothing to worry about. Any Irish out there who can petition their government to make their data protection office do more things?

* if ((reportTime-report.discoveredTime).days >= 3*mercyRatio) { report.company.fine(); }

Re: How impressive

IGotOut

The same government that gives huge tax breaks to the same tech companies?

Good luck with that.

Re: How impressive

nonsequitur

That assertion been proven incorrect so many times (in courts of law) that if I were dead already, you'd bore me back to death.

I. Any body suspended in space will remain in space until made aware of
its situation.
Daffy Duck steps off a cliff, expecting further pastureland. He
loiters in midair, soliloquizing flippantly, until he chances to
look down. At this point, the familiar principle of 32 feet per
second per second takes over.
II. Any body in motion will tend to remain in motion until solid matter
intervenes suddenly.
Whether shot from a cannon or in hot pursuit on foot, cartoon
characters are so absolute in their momentum that only a telephone
pole or an outsize boulder retards their forward motion absolutely.
Sir Isaac Newton called this sudden termination of motion the
stooge's surcease.
III. Any body passing through solid matter will leave a perforation
conforming to its perimeter.
Also called the silhouette of passage, this phenomenon is the
speciality of victims of directed-pressure explosions and of reckless
cowards who are so eager to escape that they exit directly through
the wall of a house, leaving a cookie-cutout-perfect hole. The
threat of skunks or matrimony often catalyzes this reaction.
-- Esquire, "O'Donnell's Laws of Cartoon Motion", June 1980