HomeSecurityTwitter: Fined for using user data for targeted advertising

Twitter: Fined for using user data for targeted advertising

The Federal Trade Commission (FTC) has fined Twitter $150 million for using users' personal data for targeted advertising. Specifically, the FTC accuses the platform of using phone numbers and email that were collected to enable two-factor authentication.

Twitter Fine advertising

According to court documents [PDF], since 2013, Twitter has requested this information from over 140 million users to protect their accounts with 2FA. However, it appears to have failed to inform them that this data would also be used to allow advertisers to target them with ads.

See also: Clearview AI: Fined by the UK for data collection

This is a direct violation of the FTC Act and a 2011 Commission administrative order , which prohibited the company from misrepresenting its security and privacy practices and profiting from data collected deceptively .

This order was issued following a settlement that had been reached for the company's failure to protect its users' personal information after hackers gained admin control of Twitter between January and May 2009. Twitter's failure to comply with the above order led to the fine.

“As the current complaint notes, Twitter obtained data from users under the guise of using it for security purposes, but then ended up using the data to target users with ads. This practice affected more than 140 million Twitter users while boosting the company’s primary source of revenue,” said FTC Chairwoman Lina M. Khan.

See also: FTC to Frontier: Stop deceiving customers and increase internet speed

“ The $150 million penalty reflects the seriousness of the allegations against Twitter, and the significant new compliance measures that will be imposed as a result of today’s proposed settlement will help deter further deceptive tactics that threaten user privacy ,” added U.S. Attorney Stephanie M. Hinds.

ftc fine

Beyond the Twitter fine, there are some additional provisions in the FTC's proposed order, which state:

  • Twitter cannot profit from data collected deceptively;
  • Twitter should allow users to use other multi-factor authentication methods (e.g. mobile authentication apps or security keys)
  • Twitter should notify users about the misuse of phone numbers and email addresses collected for targeted advertising.
  • The company is required to implement and maintain a comprehensive privacy and information security program . In this context, the platform should consider and address the potential risks that its new products pose to the privacy and security of users.
  • Employee access to users' personal data must be restricted ; and
  • Finally, the FTC must be notified in the event of a Twitter data breach.

See also: Twitter: Elon Musk says lower-priced acquisition not out of the question

Twitter agreed to settle the FTC's allegations by paying the $150 million fine and implementing new compliance measures to improve privacy practices.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS