Data Protection Authority of Ireland · 15 December 2020
Twitter International Company
Insufficient fulfilment of data breach notification obligations
- Regulator
- Data Protection Authority of Ireland
- Decided
- 15 December 2020
- Country
- Ireland
- Sector
- Media, Telecoms and Broadcasting
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/IE/003
What happened
Having received submissions by Twitter, the Irish Data Protection Commissioner (DPC) proceeded to set out his provisional views as to whether, in notifying the breach to the Commission, Twitter had complied with its obligations under Article 33(1) but as well with Article 33(5). In relation to Article 33(1), the DPC view was that, on the basis of the information and documentation provided by Twitter, it was not possible to ascertain whether TIC had complied with its obligations under Article 33(1) to provide notification about the breach without undue delay. The same was found with Article 33(5); The Data Commissioner’s view was that, on the basis of the information and documentation supplied by the Company, Twitter had failed to comply with its obligation, under Article 33(5), to document the breach of data protection.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
The source doesn’t list which GDPR articles were involved.
- Data breach
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IE/003.