European regulators are close to imposing a penalty on Twitter for a violation that the platform itself disclosed in 2019.

Twitter revealed the flaw in its “Protect your tweets” feature early last year. Some Android who had implemented the setting to make their tweets non-public may have had their data exposed to the public internet since 2014.
Meanwhile, a new data protection regime came into force in the European Union in May 2018 – meaning the 2014-2019 breach falls under the EU’s General Data Protection Regulation (GDPR).
The Irish DPC is the lead supervisory authority in the Twitter case, but the cross-border nature of the platform means that all EU data protection authorities have an interest and the ability to raise “relevant and reasoned” objections to the draft. Objections to the DPC’s draft decision were particularly vocal over the summer, triggering a dispute resolution process for cross-border cases set out in the GDPR.

The Irish DPC now has up to a month to issue a final decision on the incident.
“The Irish SA [supervisory authority] shall issue its final decision on the basis of the EDPB decision, which shall be addressed to the controller, without undue delay and at the latest one month after the notification of its decision by the EDPB,” the European Data Protection Board said.
Details of any penalties Twitter could face, such as a fine, have yet to be confirmed. Twitter's breach case is likely to be far less complex than some other GDPR cases, which are based on complaints being brought against major tech platforms, including investigations into the legal basis for Facebook to process user data and how Google targets internet users.
