Skip to content

Twitter

Disclosed Dec 15, 20205 years agoSettled

Official notice

Protected tweets bug notified late; Irish DPC fine of EUR 450,000

A bug made protected Twitter for Android accounts public when users changed their email address. Ireland's DPC, investigating after Twitter's 8 January 2019 breach notification, found it notified late and failed to document the breach properly, and fined it EUR 450,000 in its first cross-border GDPR decision.

What is known

People affectedNot stated in the sources we have
DisclosedDec 15, 2020
DiscoveredJan 3, 2019
AttackExposed data
Data exposedMessages
SectorTech · US
StatusSettled
Lawsuit or fineEUR 450,000 Irish DPC fine (Dec 2020) (about $547K)

Sources

Source
Twitter fined ~$550K over a data breach in Ireland's first major GDPR decisiontechcrunch.com · News
Confirmation of Fine: Twitter International Companydataprotection.ie · Regulator
DPC announces decision in Twitter inquirydataprotection.ie · Regulator

Notices filed

WhereFiledPeople
ResearchtotalDec 15, 2020

Other breaches at Twitter

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Twitter

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.