Twitter says it may have shared users' data with its ad partners without user consent due to two ad targeting-related bugs that it says were fixed on August 5
Twitter has disclosed more bugs related to how it uses personal data for ad targeting that means it may have shared users data …
Context & Ripple Effects
This disclosure extends a pattern: Twitter's 2018 admission that a bug had routed users' direct messages with business accounts to third-party developers since May 2017, followed in May by word that it shared some iOS users' location data with an ad partner — again without naming the partner or the duration.
What makes the August 5 ad-targeting bugs consequential is where the pattern led: two months later Twitter disclosed it had used email addresses and phone numbers submitted for account security for ad targeting, a practice that by 2020 had the FTC weighing a fine of $150M–$250M. The recurring shape — security and consent data flowing into the ad engine — is what regulators and advertisers will read into each new disclosure.
First-order effects
- Users whose data flowed to ad partners through the two bugs now learn of the exposure only after the fact, since Twitter fixed the bugs on August 5 before naming affected users, partners, or data types.
- Twitter's ad partners received targeting data without a documented consent basis, leaving both sides of those relationships exposed to questions about what was shared and under what terms.
Second-order effects
- Each disclosure raises the compliance bar for Twitter's ad business: the FTC's eventual $150M–$250M fine over the security-data-for-targeting practice shows these bugs convert directly into regulatory liability, and the same scrutiny now attaches to this one.
- Advertisers buying Twitter targeting must weigh the risk that audience data rests on shaky consent foundations, pressuring Twitter to prove provenance for its targeting segments or accept discounted inventory.
Third-order effects
- If the pattern holds — security inputs, location, and now ad-targeting data all crossing the line regulators later penalized — platform ad systems will face structural requirements for consent auditing and data-lineage records, not just post-hoc bug fixes and disclosures.
- Repeated self-disclosures without partner names or affected-user counts may push regulators toward mandating standardized breach-notification formats, ending the era of vague 'may have shared' statements.
The trend: Ad-targeting systems at major platforms are becoming a recurring source of privacy enforcement, as data collected for one purpose (security, consent flows) leaks into advertising pipelines and turns engineering bugs into FTC-scale liabilities.