Security researcher says Twitter retains direct messages for years, including messages users have deleted, which may be illegal under the EU's new GDPR laws
When does “delete” really mean delete? Not always or even at all if you're Twitter . — Twitter retains direct messages for years …
Context & Ripple Effects
This report lands mid-arc in Twitter's European regulatory file: a year earlier, the company had already triggered a formal EU GDPR compliance inquiry after a researcher said it refused to explain how it tracks link clicks. The new claim — that direct messages survive user deletion for years — extends the same pattern from tracking transparency into the data-lifecycle question GDPR was built to settle.
It also cuts against Twitter's own documented deletion behavior elsewhere: sources reported it deleted tweets and user data potentially valuable for the Russia probe in keeping with its privacy policy, so the platform demonstrably can purge content when policy directs — making long-retained 'deleted' DMs a choice rather than a technical limit.
First-order effects
- Users who believe their DMs are gone retain no control over messages still sitting on Twitter's servers, directly contradicting the right-to-erasure GDPR grants them.
- Ireland's Data Protection Commission, already engaged with Twitter on data-access concerns per the related coverage, gains a concrete retention violation to fold into its existing supervision of the company as lead EU regulator.
Second-order effects
- Long retention raises the payoff of any breach — the later case of a hacker demanding $200K to delete data on 400M+ accounts, which prompted an Irish DPC security investigation, shows hoarded user data converts directly into attacker leverage.
- Rival platforms facing the same regulator must be able to demonstrate verifiable deletion end-to-end, turning 'delete means delete' from a support-page promise into an audited engineering requirement.
Third-order effects
- If the DPC enforces against retained deleted messages, GDPR shifts from privacy-policy attestation to lifecycle enforcement, forcing large platforms to architect deletion across backups and archives or price fines into their data strategy.
- The pattern points toward regulators treating message content itself — not just profile and tracking data — as within scope, expanding the audit surface for every consumer messaging product operating in Europe.
The trend: European regulators are moving from checking platforms' privacy policies to auditing what those platforms actually retain and delete, with Twitter's DM practices an early test case.