EU privacy regulators are clashing over how much to fine Twitter for its handling of 2018 data breach, which could delay investigations into Facebook and Google
leading Ireland to for the first time invoke the GDPR's dispute-resolution mechanism. https://www.wsj.com/... Robert Ward / @robertalanward : More evidence that rules/standards an increasingly important strategic battleground for China/US rivalry —> data nationalism/fragmentation. Implications for supply chain digitalisation too. US moves to shut China out of shaping APEC data protections https://asia.nikkei.com/... @caixin : The U.S. has proposed separating a key international framework for data protection from the Asia-Pacific Economic Cooperation forum in its growing rift with China on technology. https://www.caixinglobal.com/ ... Max Schrems / @maxschrems : So @DPCIreland can't even agree on the @Twitter fine (a rather straight forward case) - will be interesting how much the @EU_EDPB will send a clear message that *it* is the supreme decision maker among DPAs now and “cheap” Irish fines are not a way.. 😉 https://www.wsj.com/... Nicholas Vinocur / @nicholasvinocur : 👀 So the *very first* GDPR probe that Ireland's data regulator finalized and submitted to other watchdogs — 2+ years after the law came online — has triggered a formal dispute with other EU regulators. They won't say why, but hard to imagine it's because the remedy was too tough https://twitter.com/... Toomas Hendrik Ilves / @ilvestoomas : Twitter privacy-case disagreement in Europe could delay investigations into Facebook, Google and other U.S. tech companies https://www.wsj.com/... via @WSJ
Context & Ripple Effects
This is the moment GDPR enforcement stops being a one-country affair. The Irish Data Protection Commission holds the lead-regulator file on most big tech cases because their European headquarters sit in Dublin, and critics have long questioned its willingness to crack down on firms dominating Ireland's economy (Irish DPC's reluctance under scrutiny). By late 2019 that showed in the scorecard: since GDPR became law in May 2018, the only substantial privacy action against a major tech company was the US $5B Facebook fine, not any European one.
The Twitter breach case broke the stalemate in the opposite direction — other EU regulators disagreed so sharply with Ireland over the fine size that Ireland invoked GDPR's dispute-resolution mechanism for the first time, freezing decisions on Facebook and Google behind it.
First-order effects
- Twitter's penalty is now decided by committee rather than by its lead regulator, while the pending investigations into Facebook and Google sit queued behind the resolution of this first-ever dispute.
Second-order effects
- The clash forces every future cross-border case through escalation politics instead of the one-stop-shop ideal: regulators who think Dublin is too lenient gain a template for overriding it, and companies under Irish jurisdiction face slower, less predictable timelines.
Third-order effects
- If the pattern holds, GDPR enforcement matures from a single-regulator gatekeeper into collective EU decision-making — the trajectory that later produced record penalties like the EU's €1.2B Meta fine and Ireland's €390M action against Meta, both far beyond what early critics expected of the Irish DPC.
The trend: GDPR enforcement is shifting from Ireland's centralized lead-regulator model toward contested, collective EU rulings as national authorities lose tolerance for Dublin's pace.