Twitter says FTC may soon fine it between $150M-$250M for using users' email addresses and phone numbers for ad targeting; practice was disclosed in Oct. 2019
Twitter said the identifiers were ‘inadvertently’ used for advertising — Twitter said that the Federal Trade Commission …
Context & Ripple Effects
Twitter's FTC exposure traces back to a pattern of privacy missteps: in August 2019 it disclosed bugs that may have shared users' data with ad partners without consent, and that October it admitted identifiers collected for account security had been used for targeting — the disclosure that drew the regulator's attention. The company now expects the FTC to formalize a penalty between $150 million and $250 million for what it calls 'inadvertent' use of those emails and phone numbers.
This is not an isolated hit: Twitter separately agreed to pay $809.5 million to resolve 2016 shareholder claims over misleading engagement metrics, making the FTC action part of a multi-year run of data-integrity and disclosure liabilities. The arc closes with Twitter agreeing to pay $150 million in May 2022 to settle the FTC's allegations that it misrepresented the security and privacy of user data between May 2013 and September 2019.
First-order effects
- Twitter's Q2 2022 advertising revenue of $1.08 billion means even the top of the proposed range would consume roughly a quarter of one quarter's ad sales — a material but absorbable hit, paid against the backdrop of the October 2019 self-disclosure that started the case.
Second-order effects
- The eventual $150 million settlement converts an uncertain fine into fixed compliance obligations — likely audits and consent controls on how security-purpose contact data can be used — raising the operating cost of Twitter's core ad-targeting business relative to rivals.
Third-order effects
- If regulators keep treating repurposed 'security' identifiers as a misrepresentation of privacy practices rather than a technical bug, every platform that collects emails and phone numbers for login faces pressure to firewall that data from ad systems by design — a structural split between trust infrastructure and monetization infrastructure.
The trend: Regulators are shifting from case-by-case privacy penalties toward structural consent requirements that force platforms to wall off security-collected user data from their ad-targeting pipelines.