Twitter fined $546,000 for violating the EU's GDPR privacy law, marking the first time a US firm has been penalized over the 2-year-old law
Advertisement
Trending News
Advertisement
Twitter is the first US company to be fined for violating the European Union's relatively new GDPR privacy law, The Wall Street Journal reported on Tuesday.
Ireland's Data Protection Commission said Tuesday that it's fining Twitter $546,000 for failing to note or alert regulators within 72 hours of discovering a data breach over the 2018 holiday period, which left some users' private tweets vulnerable. The General Data Protection Regulation (GDPR) includes a mandate that if companies that handle EU citizens' data realize there has been a breach, they must inform those affected within 72 hours.
In a statement to Business Insider, Twitter's Chief Privacy Officer Damien Kieran said the company takes "responsibility for this mistake and remain fully committed to protecting the privacy and data of our customers, including through our work to quickly and transparently inform the public of issues that occur." He also said the issue was the result of an "unanticipated consequence of staffing between Christmas Day 2018 and New Years' Day."The fine comes after officials deliberated for nearly two years over this specific Twitter case. Helen Dizon, head of the Irish Data Protection Commission, told the outlet that the process was "too long," but it still marks the first time that EU authorities have completed such a process. Twitter said it fixed the issue in January 2019, as the WSJ notes.
The EU's GDPR privacy law was passed in May 2018 and marked a sweeping step toward holding tech companies more accountable. The law includes a series of stipulations, like granting customers the right to have their data deleted if they ask and requiring companies to inform people on how or why their data is being processed.Copyright © 2021. Times Internet Limited. All rights reserved.For reprint rights. Times Syndication Service.
Next