Ireland's privacy watchdog says it is engaging with Twitter about giving data access to outsiders, amid concerns that Twitter could be in violation of GDPR
Elon Musk's desire to stir conspiratorial shit up by giving select outsiders aligned with his conservative agenda access to Twitter systems … Tweets: @julioalexo , @riptari , @the_nerd_skull , and @the_nerd_skull See also Mediagazer Tweets: Julio Alejandro / @julioalexo : @TechCrunch @riptari Nobody cares about Ireland's privacy watchdog has to say. I'm Mexican. How is this even news? @riptari : @julioalexo @TechCrunch Because Ireland in this context speaks for the EU as a whole as its Twitter's lead DPA under the bloc's GDPR - breaches of which can lead to corrective measures being ordered including penalties of up to 4% of global annual turnover @the_nerd_skull : One thing to note here. I'm not even a GDPR expert. I just do web dev for a living, and I've worked for large tech corporations, who have mandated that every developer take training courses on GDPR compliance. This is just the overall gist of what those GDPR courses say. @the_nerd_skull : And revealing PII to unauthorized parties is the biggest possible PII Handling breach. If the GDPR will fuck you for recording anonymized usage info without agreement, you don't wanna know what it'll do for improperly sharing PII. See also Mediagazer
Context & Ripple Effects
The Irish Data Protection Commission — Twitter's lead regulator under GDPR because of the company's EU headquarters — is engaging with Twitter over Elon Musk's move to give select outsiders access to user data, a step that could constitute a GDPR violation. That engagement lands on a regulator whose record is already under scrutiny: critics have long questioned the DPC's willingness to crack down on the tech firms that dominate Ireland's economy, where the sector employs more than 6% of the workforce.
The enforcement track record behind this story is thin. Since GDPR took effect in 2018, the only substantial privacy action against a major platform came from the US, where Facebook was fined $5B, and EU regulators were still clashing over how much to fine Twitter for its 2018 breach as recently as 2020 — a fight that delayed investigations into Facebook and Google. The DPC's handling of the Musk-era data access question is therefore a test of whether that pattern holds.
First-order effects
- Twitter faces a live regulatory inquiry from its lead EU data protection authority, with the DPC signaling it views the outsider data access as a potential GDPR violation that could trigger corrective measures ordered in Ireland and applied bloc-wide.
- The outsiders granted access to Twitter systems are directly exposed: under GDPR, any processing of EU users' personal data by third parties without a lawful basis is the kind of conduct that drew the DPC's attention.
Second-order effects
- The DPC's credibility is on the line — a soft response would reinforce the criticism that it goes easy on firms central to Ireland's economy, while a hard one would force Twitter to choose between Musk's access policy and its EU operating license to process data.
- Other EU regulators watching the outcome gain or lose leverage: the earlier inter-agency clash over Twitter's 2018-breach fine showed how one lead authority's pace can stall parallel investigations into Facebook and Google.
Third-order effects
- If the DPC acts decisively here, it would mark the first substantial EU GDPR enforcement against a major US platform — shifting enforcement gravity from US fines toward Brussels and its lead regulators, with platform owners' discretion over who may touch user data becoming a regulated permission boundary rather than an executive prerogative.
- The episode also previews the compliance regime Twitter later entered with the EU's DSA, where Thierry Breton reported a 'strong willingness' to comply and the company underwent the law's first stress test — suggesting platform governance in the EU is consolidating into layered, overlapping obligations.
The trend: EU platform governance is tightening around data access as a regulated permission boundary, with Ireland's lead-regulator role turning from a bottleneck into the enforcement choke point for US platforms operating in Europe.