Twitter reported for data breach in Spain

May 12, 2023
2 Mins Read

The FACUA-Consumers in Action association has denounced Twitter before the Spanish Agency for Data Protection (AEPD) for a security breach that caused images and other types of private content of thousands of users of this social network to be viewed by anyone.

An error in the Twitter Circles function -which allows tweets to be shared with only a selected number of users- left the images and content, in many cases intimate, visible to anyone with access to the social network, which should have been intended for only to the members of said circles. These tweets – in theory, limited – could appear randomly in the For You section of any user, even if they were not even a follower of the person who published them.

After many users of the social network denounced this failure, the company itself issued a statement informing that a “security incident” had indeed occurred during the month of April, which allowed “users outside of your Twitter Circle see Tweets that should have been confined to the Circle you posted them in.”

Violation of the Data Protection Regulation

In its complaint, FACUA points out that this ruling would have violated several precepts of Regulation (EU) 2016/679, of the European Parliament and of the Council, of April 27, 2016, regarding the protection of natural persons with regard to the treatment of personal data and the free movement of these data (GDPR).

Thus, article 32 of the aforementioned regulations clearly establishes that the person in charge of the processing of personal data must guarantee “the pseudonymisation and encryption of personal data”, “the ability to guarantee the confidentiality, integrity, availability and permanent resilience of the systems and treatment services” and “the ability to quickly restore availability and access to personal data in the event of a physical or technical incident”, among others.

Similarly, article 73 of Organic Law 3/2018, of December 5, Protection of Personal Data and guarantee of digital rights, indicates as a serious infringement “the lack of adoption of those technical and organisational measures that are appropriate to guarantee a level of security appropriate to the risk of treatment, in the terms required by article 32.1 “of the GDPR, as well as” the breach, as a consequence of the lack of due diligence, of the technical and organisational measures that have been implemented”.

In addition, article 83.4 of the GDPR establishes sanctions of up to ten million euro or “an amount equivalent to a maximum of 2% of the total annual global business volume of the company’s previous financial year, opting for the highest amount”, for violations such as those mentioned above.

For all these reasons, FACUA urges the AEPD to investigate the security error that occurred in the social network and initiate the corresponding disciplinary proceedings against Twitter.

The post Twitter reported for data breach in Spain appeared first on Spain Today – Breaking Spanish News, Sport, and Information.

Twitter date breach
Exit mobile version