• Contact Us
  • Privacy Policy
Thursday, February 25, 2021
WorldGots.com
  • Home
  • World News
  • Politics
  • Business
  • Technology
  • Sports
  • Health
  • Entertainment
    • Lifestyle
  • Worldgots Ads
No Result
View All Result
  • Home
  • World News
  • Politics
  • Business
  • Technology
  • Sports
  • Health
  • Entertainment
    • Lifestyle
  • Worldgots Ads
No Result
View All Result
WorldGots.com
No Result
View All Result
Home Technology

Twitter fined ~$550k over a data breach in Ireland’s first major GDPR decision – TechCrunch

December 15, 2020
in Technology
5 min read
Twitter rolls out audio tweets – TechCrunch
0
SHARES
5
VIEWS
ShareShareShareShareShareShare

Ireland’s Data Protection Commission (DPC) has issued Twitter with a fine of €450,000 (~$547k) for failing to promptly declare and properly document a data breach under Europe’s General Data Protection Regulation (GDPR).

The decision is noteworthy as it’s the first such cross-border GDPR decision by the Irish watchdog, which is the lead EU privacy supervisor for a number of tech giants — having a backlog of some 20+ ongoing cases at this point, including active probes of Facebook, WhatsApp, Google, Apple and LinkedIn, to name a few.

“The DPC’s investigation commenced in January, 2019 following receipt of a breach notification from Twitter and the DPC has found that Twitter infringed Article 33(1) and 33(5) of the GDPR in terms of a failure to notify the breach on time to the DPC and a failure to adequately document the breach. The DPC has imposed an administrative fine of €450,000 on Twitter as an effective, proportionate and dissuasive measure,” the regulator writes in a press release.

The GDPR requires most breaches of personal data to be notified to the relevant supervisory authority within 72 hours of the controller becoming aware of the breach.

The regulation also requires they document what data was involved and how they’ve responded to the security incident — in order that the relevant data supervisor can check against compliance.

In this case Twitter was found to have failed on both counts.

We’ve reached out to the social media company for comment, including asking whether it plans to accept the decision and pay up — or if it’s considering its legal options.

Update: Twitter has now sent this statement, attributed to Damien Kieran, its chief privacy officer and global data protection officer:

Twitter worked closely with the Irish Data Protection Commission (IDPC) to support their investigation. We have a shared commitment to online security and privacy, and we respect the IDPC’s decision, which relates to a failure in our incident response process. An unanticipated consequence of staffing between Christmas Day 2018 and New Years’ Day resulted in Twitter notifying the IDPC outside of the 72 hour statutory notice period. We have made changes so that all incidents following this have been reported to the DPC in a timely fashion.

We take responsibility for this mistake and remain fully committed to protecting the privacy and data of our customers, including through our work to quickly and transparently inform the public of issues that occur. We appreciate the clarity this decision brings for companies and consumers around the GDPR’s breach notification requirements. Our approach to these incidents will remain one of transparency and openness.

The company also told us that since this specific incident, where inadequate staffing over the 2018 holiday period led to a delay in reporting the breach, it has made all relevant incident reports to the DPC within the required 72 hour period.

The DPC’s decision relates to a breach that Twitter publicly disclosed in January 2019 — when it said a bug in its ‘Protect your tweets’ feature could have meant some Android users who’d applied the setting to make their tweets non-public may have had their data exposed to the public Internet since as far back as 2014. (Though GPDR would only apply to data the bug exposed since May 2018.)

Since fessing up to the ‘Protect your tweets’ bug, Twitter has had plenty more egg on its face where security is concerned — including suffering a high profile account hijacking episode earlier this year, after crypto-scam-spreading hackers gained network access credentials using a social engineering technique.

Ireland’s DPC, meanwhile, continues to face criticism for the length of time it’s taking to reach decisions on major cross-border GDPR cases where impacts on individual rights can scale to hundreds of millions of European Internet users.

Last year commissioner Helen Dixon said its first major GDPR decisions would come “early” in 2020.

In the event the first cross-border decision has crossed the line days before the end of the year — underlining the challenges for the bloc in effectively enforcing its digital rulebook against tech giants. (GDPR technically begun being applied in May 2018, although platform giants have faced precious little enforcement to date.)

In this specific case, some half a year extra was added to the decision timeline after a draft outcome Ireland submitted to other EU DPAs for review, back in May, was not accepted by all of them — triggering a majority vote mechanism in the GDPR for settling disagreement between the bloc’s data supervisors.

The European Data Protection Board has published this Article 65 decision and the full final decision on its website here.

The (now) final outcome on the Twitter case comes at a key time — with EU lawmakers due to set out their next major pieces of digital policy later today, as part of an ambitious push to accelerate regional digitization by rolling out a reassuring promise of European guardrails wrapping around all this tech.

Yet with GDPR enforcement proving such a tedious, friction-filled process that threatens to take the shine off the nascent Digital Services Act and Digital Markets Act many months (or even years) before they can become EU law — raising questions about how the whole strategy can be expected to function in the absence of effective (i.e. fair but fast) enforcement.

The wider risk here is European citizens losing faith in the rights-based framework they’re told they enjoy, under EU law and the bloc’s patchwork of regulatory frameworks, if the animal turns out to be such a plodding house-cat when people do try to obtain relief.

So the Commission’s strategy of claiming expanded digital rules will act as a public trust booster risks falling into a trough of disillusionment at the legislative proposal stage.

Simple put: You can’t allow your regulators to move so slowly and expect your rulebook to touch tech giants whose playbook is to move fast in order to disrupt the rule of law in their own business’ interests.

The DPC’s decision in the Twitter case is thus a measure of how sizeable a gap sits between the rhetoric EU policymakers ply around the bloc’s ‘powerful’ digital rules — and the messier and more faltering reality: Nearly two years since Twitter disclosed the breach and waiting for a hammer to drop in what should be a relatively straightforward case.

A data breach is not an investigation into the lawfulness of Facebook’s business model vs GDPR, after all, nor does it delve into the intricacies of Google’s adtech — both of which are still open case files on the DPC’s desk.

The penalty itself is also a fraction (a little over 0.1%) of Twitter’s full-year 2019 revenue; a far cry from the up to 4% of global annual turnover maximum allowed for under the GDPR (or the up to 2% max for the specific infringements involved in the breach case).

The size of the fine calculated by Ireland was one of the objections raised by other EU DPAs during the dispute of the draft decision — the DPC initially proposed an even smaller fine (in the range of 0.005% and 0.01% of Twitter’s annual turnover; or between €135k and €275k). The Article 65 intervention forced Ireland to increase the size of the penalty (though not by much). 

EU DPAs also disagreed on the controller/processor status of Twitter’s Irish business vs its US entity — with Ireland accepting Twitter Ireland as the data controller and Twitter Inc as the processor, a designation that seems intended to reduce its liability.

So this first cross-border GDPR decision looks more millstone than milestone for the Commission, at the fag end of 2020.

There’s not a lot for commissioners to celebrate here, even though they suggested in the summer that the best answer to GDPR enforcement concerns would be for Ireland to get a decision out. The problem now is the black marks against the bloc’s record on digital enforcement look stubbornly set in — just as the Commission is laying out a plan to go all in on platform regulation.

The questions over enforcement are going to keep coming.

This report was updated with additional detail on the dispute from the Article 65 decision

Credit: Source link

ADVERTISEMENT
Previous Post

Kelly Loeffler, David Perdue ‘Adamantly Oppose’ Changing Atlanta Braves’ Name

Next Post

We Need A National Day Of Mourning For COVID-19 Victims

Related Posts

James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch
Technology

James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

February 25, 2021
Plant-based food startup Next Gen lands $10M seed round from investors including Temasek – TechCrunch
Technology

Plant-based food startup Next Gen lands $10M seed round from investors including Temasek – TechCrunch

February 24, 2021
Pilot CEO Waseem Daher tears down his company’s $60M Series C pitch deck – TechCrunch
Technology

Pilot CEO Waseem Daher tears down his company’s $60M Series C pitch deck – TechCrunch

February 24, 2021
Meet Smash Ventures, the low-flying outfit that has quietly funded Epic Games, among others – TechCrunch
Technology

Meet Smash Ventures, the low-flying outfit that has quietly funded Epic Games, among others – TechCrunch

February 24, 2021
Load More
Next Post
We Need A National Day Of Mourning For COVID-19 Victims

We Need A National Day Of Mourning For COVID-19 Victims

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Prince Philip Makes Rare Public Appearance To Hand Over Patronage To Camilla

Buckingham Palace Reveals Cause Of Prince Philip’s Hospitalization

February 23, 2021
NBA trade rumors: Bucks, Lakers among teams expressing interest in Rockets’ P.J. Tucker

NBA trade rumors: Bucks, Lakers among teams expressing interest in Rockets’ P.J. Tucker

February 22, 2021
Lakers rumors: Los Angeles unlikely to pursue DeMarcus Cousins, could target Hassan Whiteside

Lakers rumors: Los Angeles unlikely to pursue DeMarcus Cousins, could target Hassan Whiteside

February 24, 2021
Prince William Gives Update On Hospitalized Grandfather Prince Philip

Prince William Gives Update On Hospitalized Grandfather Prince Philip

February 23, 2021
Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

February 25, 2021
James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

February 25, 2021
7 Things You Should Do In The Morning If You Want More Energy

7 Things You Should Do In The Morning If You Want More Energy

February 25, 2021
Malaysian Brand That Made Corn In A Cup A Popular Snack

Malaysian Brand That Made Corn In A Cup A Popular Snack

February 25, 2021

Recent News

Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

February 25, 2021
James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

February 25, 2021
7 Things You Should Do In The Morning If You Want More Energy

7 Things You Should Do In The Morning If You Want More Energy

February 25, 2021
Malaysian Brand That Made Corn In A Cup A Popular Snack

Malaysian Brand That Made Corn In A Cup A Popular Snack

February 25, 2021
WorldGots.com

This is an online news portal that aims to share latest trendy news around US News, World News, Business, Tech, Sports, Entertainment & Lifestyle. Feel free to get in touch with us!

Recent News

Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

Don Lemon: GOP Hypocrisy Is ‘Off The Charts’

February 25, 2021
James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

James Murdoch’s Lupa Systems leads $31 million investment in India’s Doubtnut – TechCrunch

February 25, 2021

Subscribe Now

Loading
  • Contact Us
  • Privacy Policy

© 2020 worldgots.com - All rights reserved!

No Result
View All Result
  • Home
  • World News
  • Politics
  • Business
  • Technology
  • Sports
  • Health
  • Entertainment
    • Lifestyle
  • Worldgots Ads
  • en English
    ar Arabicen Englishfr Frenches Spanish

© 2020 worldgots.com - All rights reserved!

en English
ar Arabicen Englishfr Frenches Spanish