Ireland's Data Protection Commission opens a probe into Twitter over reports of a data breach and the leak of approximately 5.4M users' personal details in 2021
Context & Ripple Effects
The Data Protection Commission has been building this case file for years: it opened its first breach probe into Facebook in 2018 after a hack exposed about 3M Europeans' data, then investigated Facebook again in 2021 over the 533M-account phone-number leak. Twitter is already a repeat offender on its docket — the regulator issued Europe's first GDPR decision fining a company for botched breach handling, a €450K penalty in 2020.
This new probe lands days after the DPC said it would examine a hacker's $200K ransom demand over data on 400M+ Twitter accounts, meaning the regulator now has two parallel Twitter security investigations running at once. With Twitter silent publicly and freshly stripped down post-acquisition, the DPC is positioning itself as the main check on the platform's data practices.
First-order effects
- Twitter faces a formal GDPR investigation into the 2021 leak of roughly 5.4M users' details, with the DPC's own €450K breach-handling fine as the precedent that shapes what non-cooperation costs.
- The probe runs alongside the DPC's separate look at the 400M-account scraping claim, so Twitter's privacy and security teams are now answering two Irish inquiries simultaneously while the company has not commented.
Second-order effects
- Other EU regulators tracking the DPC's lead — as they did when its 2020 ruling became Europe's first GDPR breach decision — can piggyback on its findings rather than open their own probes, concentrating enforcement leverage in Dublin.
- Advertisers already wary of Twitter's post-acquisition turbulence get another governance red flag; with Q2 2022 ad revenue of $1.08B as the last clean benchmark, any finding of systemic breach mishandling gives buyers fresh grounds to pull spend.
Third-order effects
- If the pattern holds, breach-response quality — not just the breach itself — becomes the standard GDPR charge against US platforms, since both Twitter fines trace to how incidents were declared and documented rather than the leaks alone.
- The DPC's run of Facebook and Twitter cases cements Ireland's role as the de facto gatekeeper for US multinationals' EU data compliance, raising the stakes of its resourcing and independence as platform headcounts shrink.
The trend: GDPR enforcement is converging on breach disclosure and response conduct, with Ireland's DPC acting as the default investigator for US platforms' European data failures.