Inquiry into a Consultancy Provider

This inquiry was commenced in respect of a personal data breach that the Personal Injuries Assessment Board (‘PIAB’) reported to the Data Protection Commission on 10 December 2019. PIAB is an independent statutory body that deals with personal injury claims. The personal data breach occurred when a Consultancy Provider sent an unencrypted USB storage device, containing personal data to PIAB, despite PIAB expressly stating the data was not to be sent. The Inquiry considered whether the Consultancy Provider had complied with its obligation to implement an appropriate level of security under Article 32 GDPR.

  • The decision found that the Consultancy Provider had infringed Article 32(1) GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data.

The corrective powers exercised

  • The decision issued the Consultancy Provider with a reprimand in respect of the infringement.

For more information, you can download a copy of the full decision at this link: A Consultancy Provider January 2022 (PDF, 947 KB).

Inquiry into the Personal Injuries Assessment Board

This inquiry was commenced in respect of a personal data breach that the Personal Injuries Assessment Board (‘PIAB’) notified to the DPC on 10 December 2019. PIAB is an independent statutory body that deals with personal injury claims. The personal data breach occurred when a third party organisation (‘the Third Party’) contracted by PIAB returned materials containing personal data to PIAB on an unencrypted USB key in a paper envelope, which USB key was ultimately lost in the post with only a ripped envelope delivered to PIAB.

The Inquiry considered whether the PIAB had complied with its obligation to implement an appropriate level of security under Article 32 GDPR. The Inquiry established that PIAB had requested in advance that the Third Party not send the personal data to PIAB. In those circumstances, the Decision found that PIAB could not possibly have foreseen that without consultation with it, the Third Party would post an unencrypted USB storage device in an unpadded envelope by ordinary (not registered) post.

The corrective powers exercised

  • No corrective powers were exercised by the Data Protection Commission in this instance because no provision of the GDPR was found to have been infringed by PIAB.

For more information, you can download a copy of the full decision at this link: Personal Injuries Assessment Board January 2022 (PDF, 628 KB).

Inquiry into Slane Credit Union

This inquiry was commenced in respect of a personal data breach that Slane Credit Union notified to the DPC on 30 November 2018. Slane Credit Union was established on 16 February 1968 as a member of the Irish League of Credit Unions. It is regulated by the Central Bank of Ireland under section 84 of the Credit Union Act 1997. The personal data breach related to an unauthorised disclosure of personal data in the form of an unintended publication of member data on the internet. Certain board reports relating to membership enquiries stored within the Slane Credit Union website inadvertently became publicly available through search engine results for a period in 2018. According to Slane Credit Union, this incident occurred due to an update to a search engine optimisation tool installed on the website that Slane Credit Union had not anticipated.

The decision found infringements of the following provisions of the GDPR:

  • Article 5(1)(f) and 32(1) were infringed by Slane Credit Union by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of the personal data of its members;
  • Article 24 and 30(1) were infringed by Slane Credit Union by failing to implement organisational measures that took account of the nature, scope, context and purposes of its processing, and by failing to include all appropriate information in its record of processing; and
  • Article 28(1) and (3) were infringed by Slane Credit Union by failing to conduct due diligence on its processor and by failing to put in place an agreement with its processor that met the requirements of Article 28(3) of the GDPR.

The corrective powers exercised

  • The decision imposed an administrative fine on Slane Credit Union in the amount of €5,000 in respect of the infringement of Article 5(1)(f) of the GDPR (principle of security of processing).
  • The decision issued Slane Credit Union with a reprimand in respect of all of the infringements.

For more information, you can download a copy of the full decision at this link: Slane Credit Union January 2022 (PDF, 898 KB).

Inquiry into Limerick City and County Council

This inquiry sought to assess whether Limerick City and County Council was processing personal data in compliance with the GDPR and the Data Protection Act 2018. The inquiry examined a number of the Council’s processing operations including its use of CCTV cameras, Automatic Number Plate Recognition technology and drones in public places which were used for the purposes of prosecuting crime or other purposes.

The findings made in the decision include:

  • The Council has no lawful basis for the processing of personal data by CCTV cameras for traffic management purposes.
  • The Council lacked a lawful basis for a number of CCTV cameras used for the purposes of countering crime on account of failing to demonstrate it had obtained a Garda Commissioner authorisation pursuant to section 38(3) of the Garda Síochána Act 2005 which was sufficiently clear, precise and foreseeable as specified by the GDPR.
  • The Council lacked a lawful basis to carry out surveillance with CCTV cameras which employed Automatic Number Plate Recognition technology.
  • The Council infringed Article 15 of the GDPR by rejecting subject access requests in respect of CCTV cameras used for traffic management purposes.
  • The Council did not fulfil its transparency obligations under Article 13 by failing to erect signage in respect of its CCTV processing operations.
  • The Council infringed Article 12 of the GDPR by failing to make its CCTV Policy more easily accessible and transparent.

The corrective powers exercised

  • A temporary ban on the processing of personal data with CCTV cameras at a number of locations used for the purposes of criminal law enforcement until a legal basis can be identified. 
  • A temporary ban on the processing of personal data with CCTV cameras used for traffic management purposes until a legal basis can be identified.
  • An order to Limerick City and County Council to bring its processing of personal data into compliance taking certain actions specified in the decision.
  • A reprimand in respect of a number of Limerick City and County Council’s infringements.
  • An administrative fine of €110,000.

For more information, you can download a copy of the full decision at this link: Inquiry into Limerick City and County Council December 2021 (PDF, 1,622 KB).

Inquiry into the Teaching Council

This inquiry was commenced in respect of a personal data breach that the Teaching Council (the Council) notified to the DPC on 9 March 2020. The Council is the professional standards body for the teaching profession and its purpose is to promote and regulate professional standards in teaching.

The personal data breach occurred when a phishing email was accessed by two staff members of the Council, allowing then for the creation of an auto-forward rule from their email accounts to a malicious email account. As a result, between 17 February 2020 and 6 March 2020 when the auto-forward rule was discovered, 323 emails were forwarded to the unauthorised external email address. The emails contained the personal data of 9,735 data subjects and the sensitive personal data of one data subject.

  • The decision found that the Council infringed Article 5(1) and Article 32(1) of the GDPR between 25 May 2018, when the GDPR came into application, and the dates of the personal data breaches, by failing to process personal data in a manner that ensured the appropriate security of the personal data using appropriate technical and organisational measures.
  • The decision found that the Council infringed Article 33(1) of the GDPR by failing to notify the DPC of the personal data breach(es) when it ought to have been aware of them.

The corrective powers exercised

  • The decision imposed an administrative fine on the Council in the amount of €60,000 in respect of the infringements.
  • The decision issued the Council with a reprimand in respect of the infringements.
  • With due regard to the measures already implemented by the Council since the personal data breach and during the inquiry, a date of 2 June 2022 was given to the Council to bring its processing operations into compliance with Articles 5(1) & 32(1) of the GDPR.

For more information, you can download a copy of the full decision at this link: Inquiry into the Teaching Council December 2021 (PDF, 1 MB).

Inquiry into MOVE (Men Overcoming Violence) Ireland

This inquiry was commenced in respect of a personal data breach that MOVE notified to the DPC on 3 February 2020. MOVE is a registered charity, which works in the area of domestic violence, with a primary aim of supporting the safety and wellbeing of women and their children who are experiencing, or have experienced violence/abuse in an intimate relationship. MOVE does this by facilitating men (participants) in weekly group sessions with a facilitator encouraging them to take responsibility for their violence and changing their attitude and behaviour. The personal data breach concerned the loss of eighteen SD Cards that may have contained recordings of group sessions of MOVE’s programme where participants discuss their behaviour and attitudes with regard to domestic violence with a facilitator. Whilst the recording of group sessions focused on the delivery of sessions by the facilitators, some of the participants may have been seen and heard in the recordings; furthermore the personal data on the SD Cards included participants’ disclosure of behaviours, feelings and attitudes towards current or ex partners, other family members and friends, who may have been named by the participants. MOVE submitted that 80 to 120 men may have been affected by this personal data breach and, at least, one facilitator per each recorded session.

  • The decision found that MOVE infringed Articles 5(1)(f) and 32(1) of the GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing by means of recording group sessions on SD Cards containing participants’ and facilitators’ personal data.

The corrective powers exercised

  • The decision issued MOVE with a reprimand in respect of the infringements.
  • The decision ordered MOVE to bring its processing by means of recording group sessions on SD Cards into compliance with Articles 5(1)(f) and 32(1) of the GDPR.
  • The decision imposed an administrative fine on MOVE in the amount of €1,500 in respect of the infringements.

For more information, you can download a copy of the full decision at this link: MOVE Ireland August 2021 (PDF, 649 KB).

Decision concerning WhatsApp Ireland Ltd

This inquiry, which was commenced by the Data Protection Commission (DPC) on 10 December 2018, examined whether WhatsApp Ireland Ltd had discharged its GDPR transparency obligations with regard to the provision of information and the transparency of that information to both users and non-users of WhatsApp’s service. This includes information provided to data subjects about the processing of information between WhatsApp and other Facebook companies.

Articles 60 & 65 of the GDPR

Following a lengthy and comprehensive investigation, the DPC submitted a draft decision to all Concerned Supervisory Authorities (CSAs) under Article 60 GDPR in December 2020. The DPC subsequently received objections from eight CSAs. The DPC was unable to reach consensus with the CSAs on the subject matter of the objections and triggered the dispute resolution process (Article 65 GDPR) on 3 June 2021.

Reassessment following EDPB binding decision

On 28 July 2021, the European Data Protection Board (EDPB) adopted a binding decision and this decision was notified to the DPC. This decision contained a clear instruction that required the DPC to reassess and increase its proposed fine on the basis of a number of factors contained in the EDPB's decision. Following this reassessment, the DPC imposed a fine of €225 million on WhatsApp.

In addition to the imposition of an administrative fine, the DPC also imposed a reprimand along with an order for WhatsApp to bring its processing into compliance by taking a range of specified remedial actions.

The EDPB has published the Article 65 decision and the final decision on its website. Binding decision 1/2021 on the dispute arisen on the draft decision of the Irish Supervisory Authority regarding WhatsApp Ireland under Article 65(1)(a) GDPR

For more information, you can download a copy of the full decision at this link: WhatsApp Ireland Ltd. 2021 (PDF, 18.4 MB).

Inquiry into the Department of Employment Affairs and Social Protection

The Data Protection Commission (DPC) commenced this own-volition inquiry after it received a complaint from Digital Rights Ireland alleging a “serious interference with the independence of the Data Protection Officer (DPO) in the Department”. On 4 July 2018, the Department received a media query in relation to the Privacy Statement’s reference to biometric data. This query set off a series of internal email threads and discussions within the Department questioning the reference to biometric data. On 6 July 2018, the Department amended its Privacy Statement and removed the only reference to its processing of biometric data from the Statement. As part of the complaint, Digital Rights Ireland submitted the Department’s internal email threads to the DPC having received them pursuant to the Freedom of Information Act 2014.

The scope of this inquiry concerned whether the Department’s DPO was involved in the issue of amending the Privacy Statement in a proper and timely manner in accordance with Article 38(1) of the GDPR; and whether the DPO received instructions regarding the exercise of his tasks contrary to the requirements of Article 38(3) of the GDPR. The scope of the inquiry did not concern whether the Department’s amendment complied with its transparency obligations under the GDPR. During the inquiry, the DPC gathered all of the relevant information in order to comprehensively consider the background, in addition to the email threads submitted with the complaint. The DPC conducted a voluntary interview with the DPO who held that position at the relevant time. The DPC also had regard to statements submitted to the DPC by the Department’s Secretary General and DPO respectively. The DPC also analysed the Department’s relevant internal emails between 4 - 6 July 2018 concerning the amendment to the Privacy Statement. Having regard to all of the relevant information, the DPC found that:

  • The Department involved their DPO, properly and in a timely manner, in the Department’s amendment to its Privacy Statement as implemented on 6 July 2018. Therefore, the Department did not infringe Article 38(1) of the GDPR in the circumstances.
  • The Department did not provide any instructions to the DPO regarding the exercise of the tasks referred to in Article 39 of the GDPR in respect of the Department’s amendment to its Privacy Statement as implemented on 6 July 2018. Therefore, the Department did not infringe Article 38(3) of the GDPR in the circumstances.

For more information, you can download a copy of the full decision at this link: Department of Employment Affairs and Social Protection May 2021 (PDF, 1,234 KB).

Inquiry into the Irish Credit Bureau DAC

This inquiry was commenced in respect of a personal data breach that the Irish Credit Bureau (‘ICB’) notified to the DPC on 31 August 2018. The ICB is a credit reference agency that maintains a database on the performance of credit agreements between financial institutions and borrowers. The personal data breach occurred when the ICB implemented a code change to its database that contained a technical error. As a result, between 28 June 2018 and 30 August 2018, the ICB database inaccurately updated the records of 15,120 closed accounts. The ICB disclosed 1,062 inaccurate account records to financial institutions or data subjects before fixing the issue. All of the inaccurate account records disclosed to the financial institutions stated that the accounts had been closed more recently than they actually had been, but none misstated that a balance was outstanding on the accounts.

  • The decision found that the ICB infringed Article 25(1) of the GDPR by failing to implement appropriate technical and organisational measures designed to implement the principle of accuracy in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of the GDPR and protect the rights of data subjects.
  • The decision found that the ICB infringed Article 5(2) and 24(1) of the GDPR by failing to demonstrate compliance with its obligation, pursuant to Article 25(1) of the GDPR, to undertake appropriate testing of proposed changes to its database.
  • The decision found that the ICB did not infringe Article 26(1) of the GDPR in circumstances where the ICB members are not joint controllers in respect of the ICB’s database.

The corrective powers exercised

  • The decision imposed an administrative fine on the ICB in the amount of €90,000 in respect of the infringements.
  • The decision issued the ICB with a reprimand in respect of the infringements.
  • Having regard to the measures implemented by the ICB since the personal data breach and during the inquiry, it was not necessary for the decision to order the ICB to take specific action to bring its processing operations into compliance with the GDPR

For more information, you can download a copy of the full decision at this link: Irish Credit Bureau DAC March 2021 (PDF, 1,427 KB).

Inquiry Concerning Twitter International Company (‘TIC’)

This Inquiry, which was commenced by the Data Protection Commission (‘the Commission) on 22 January 2019, examined whether Twitter International Company (‘TIC’) had complied with its obligations under the GDPR in respect of its notification, on 8 January 2019, of a personal data breach (‘the Breach’) to the Commission. The Breach, which occurred at TIC’s processor, Twitter Inc., related to a bug whereby if a Twitter user with a protected account, using Twitter for Android, changed their email address, their account would become unprotected.

The purpose of the Inquiry was to examine certain issues surrounding TIC’s notification of the Breach, as distinct from examining the substantive issues relating to the Breach itself. In this regard, the Inquiry examined whether TIC had complied with Article 33(1) of the GDPR, in terms of the timing of its notification of the Breach to the Commission, and whether it had complied with Article 33(5) of the GDPR, in respect of its documenting of the Breach.

The DPC submitted its draft decision in this inquiry to other Concerned Supervisory Authorities under Article 60 GDPR on 22 May 2020. This was the first draft decision to go through the Article 65 dispute resolution process and was the first Draft Decision in a “big tech” case on which all EU supervisory authorities were consulted as Concerned Supervisory Authorities. The European Data Protection Board adopted its decision under Article 65(1)(a) on 9 November 2020. The DPC issued its final decision to TIC on 9 December 2020.

Facts leading to Inquiry

TIC’s notification of the Breach to the Commission, which led to the Inquiry, took place on 8 January 2019 by way of a completed Cross-Border Breach Notification Form. In the Form, TIC outlined that it had received a bug report through its ‘Bug Bounty Program’ to the effect that “…if a Twitter user with a protected account, using Twitter for Android, changed their email address the bug would result in their account being unprotected.” The Breach Notification Form further outlined, in respect of the reasons for not notifying the Commission within the 72 hour period required by Article 33(1), that

“The severity of the issue - and that it was reportable - was not appreciated until 3 January 2018 [sic] at which point Twitter’s incident response process was put into action.”

The Breach Notification Form identified the potential impact for affected individuals, as assessed by TIC, as being “significant”. In a further follow up notification form submitted by TIC to the Commission on 16 January 2019, TIC confirmed the number of affected EU and EEA users was 88,726. It also confirmed that the bug which had led to the Breach “was introduced on 4 November 2014 and fully remediated by 14 January 2019” and that, as it was not possible to identify all impacted persons (due to retention limitations on available logs), it believed that additional people were impacted during that period.

Inquiry under Section 110, Data Protection Act 2018

As it appeared from the Breach Notification Form submitted by TIC that a period of in excess of 72 hours had elapsed from when TIC (as controller) became aware of the Breach, and having regard to the number of affected data subjects, the Commission commenced the Inquiry, under Section 110(1) of the Data Protection Act 2018 (‘the 2018 Act’) for the purpose of examining whether TIC had complied with its obligations under Article 33, and more particularly, with its obligations under Article 33(1) and Article 33(5).

Compliance with Article 33(1)

In assessing TIC’s compliance with Article 33(1), the Commission examined the timeline relating to TIC’s notification of the Breach to the Commission. In this regard, TIC confirmed to the Commission during the Inquiry that notice of the bug was first received on 26 December 2018 by an external contractor engaged by Twitter to search for and assess bugs via the Bug Bounty Program, a program whereby anyone may submit a bug report. TIC further confirmed that, on 29 December 2018, the external contractor, having assessed the bug report, communicated the outcome of its assessment to Twitter Inc. TIC further confirmed that Twitter Inc. then commenced its internal Information Security review of the issue on 2 January 2019, and that, following this, on 3 January 2019, Twitter Inc. assessed the incident as being a potential personal data breach under the GDPR and determined that the incident response plan should be initiated. TIC also confirmed that, following this (on 4 January 2019), an Incident Management (IM) ticket was opened but that, due to a failure (by Twitter Inc. staff) to follow a particular step in the incident management process as it was prescribed, the Data Protection Officer (DPO) for TIC was not added to the IM ticket, which resulted in a delay in the DPO (and, therefore TIC as controller) being notified of the issue.

TIC confirmed to the Commission that it was first made aware of the Breach by its processor, Twitter Inc., on 7 January 2019. It submitted that, in circumstances where it had notified the Breach to the Commission on 8 January 2019, it had complied with the requirement to notify under Article 33(1).

Having considered the timeline in relation to TIC’s notification of the Breach, the Commission formed the view that, notwithstanding TIC’s actual awareness of the Breach on 7 January 2019, TIC ought to have been aware of the Breach at an earlier point in time and, in this particular case, at the latest by 3 January 2019. In forming this view, the Commission took account of the fact that 3 January 2019 was the date on which Twitter Inc. first assessed the incident as being a potential personal data breach but that, for reasons of the ineffectiveness of the process in the particular circumstances that transpired and/or a failure by Twitter Inc. staff to follow its own incident management process, a delay occurred in the DPO being informed of the potential data breach, which, in turn, resulted in TIC (as controller) not being notified of the Breach until 7 January 2019.

In making this finding, the Commission also took account of an earlier delay that had arisen in the period from when the incident was first notified to Twitter Inc. by its external contractor on 29 December 2018 to when Twitter Inc. commenced its Information Security review of the issue on 2 January 2019. During the course of the Inquiry, TIC confirmed to the Commission that this delay had arisen “due to the winter holiday schedule” (in circumstances where three of the four days in question were holidays – a weekend and New Years Day) which had led to the issue not being identified and escalated as it should have been. However, the Commission did not accept this delay as being reasonable, in particular in circumstances where potential risks to the data protection and privacy rights of data subjects cannot be neglected, even for a limited period of days, simply because it is an official holiday day/period or a weekend and given that Twitter’s services do not cease to operate during such times.

As outlined in the Decision, the alternative application of Article 33(1), and that which was suggested by TIC during the Inquiry, whereby the performance by a controller of its obligation to notify is, essentially, contingent upon the compliance by its processor with its obligations under Article 33(2), would undermine the effectiveness of the Article 33 obligations on a controller. Such an approach would be at odds with the overall purpose of the GDPR and the intention of the EU legislator.

Compliance with Article 33(5)

In assessing TIC’s compliance with Article 33(5), the Commission carried out a review of the documentation provided by TIC during the course of the Inquiry, and in which it claimed that it had documented the Breach.

In doing so, the Commission found that TIC had not complied with Article 33(5). This was in circumstances where the documentation maintained by TIC – either individually or collectively – did not comprise a record, or document, of, specifically, a ‘personal data breach’ within the terms of Article 33(5), but rather was documentation of a more generalised nature, including reports and internal communications, that were generated in the course of TIC’s management of the incident.

In addition, the Commission found that the documentation maintained by TIC in relation to the Breach did not contain sufficient information so as to enable the question of TIC’s compliance with the requirements of Article 33 to be verified, as is required by Article 33(5). In particular, the Commission found that the documentation, which TIC had identified as being the primary record in which it had documented the facts, effects and remedial action taken in respect of the Breach, was deficient in circumstances where it did not contain all material facts relating to the notification of the Breach to the Commission. In particular, the documentation did not contain any reference to the issues that had led to the delay in TIC being notified of the Breach by its processor, nor did it address how TIC had assessed the risk to affected users arising from the Breach. The Commission also found that the deficiencies in the documentation furnished by TIC as a record of the Breach were further demonstrated by the fact that, during the Inquiry, the Commission had to raise multiple queries in order to gain clarity concerning the facts surrounding the notification of the Breach.

Process under Article 60 and Article 65 GDPR

On 22 May 2020, the Commission issued a draft of its Decision (‘the Draft Decision’) to the other concerned supervisory authorities (‘CSAs’) for their opinion in accordance with the process under Article 60 GDPR. The Draft Decision set out the Commission’s proposed finding of infringements under Articles 33(1) and 33(5) and its proposal to impose an administrative fine. Under Article 60(4), CSAs have a period of four weeks within which to express a relevant and reasoned objection to a draft decision.

A number of CSAs expressed objections in relation to aspects of the Draft Decision, including objections on the basis that the Commission should, as part of its Inquiry, have considered other provisions of the GDPR; objections relating to non-substantive matters, such as the designation of the role of the respondent under investigation (TIC) and the competence of the Commission, as Lead Supervisory Authority, to deal with the matter; and objections in relation to the administrative fine which the Commission proposed.

Having considered the objections raised, and having endeavoured to reach consensus with the CSAs, the Commission was unable to follow the objections in an amended Draft Decision. On this basis, the Commission referred the matter to the European Data Protection Board (‘EDPB’) for determination pursuant to the Article 65 dispute resolution mechanism. The EDPB commenced the Article 65 procedure on 8 September 2020. Having adopted its binding decision under Article 65(1)(a) (‘the EDPB Decision’) on 9 November 2020, the EDPB notified same to the Commission on 17 November 2020. Thereafter, pursuant to Article 65(6), the Commission was required to adopt its final decision on the basis of the EDPB Decision “without undue delay and at the latest by one month after the Board has notified its decision.”

Article 65(1)(a) provides that the EDPB’s binding decision under Article 65 “…shall concern all the matters which are the subject of the relevant and reasoned objection, in particular whether there is an infringement of [the GDPR]”. In this regard, in terms of the EDPB’s assessment of the objections raised by the CSAs in this case, the EDPB Decision found that certain of the objections raised were not ‘relevant and reasoned’ within the meaning of Article 4(24) on the basis that they did not provide a clear demonstration as to the significance of the risks posed by the Draft Decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the European Union (as is required by Article 4(24)).

With regard to a number of other objections raised, and which had been made on the basis that the Commission should have considered further infringements under other provisions of the GDPR (specifically, Articles 5(1)(f), 5(2), 24 and 32), whilst the EDPB found that these objections were relevant and reasoned under Article 4(24), it determined that it could not, on the basis of the factual elements in the Draft Decision or in the objections themselves, establish the existence of such further (or alternative) infringements.

Finally, and with regard to the objections raised by CSAs in respect of the administrative fine imposed, the EDPB found that certain of these objections were relevant and reasoned under Article 4(24). As such, the EDPB issued a binding direction to the Commission to reassess the elements that it had relied upon to calculate the amount of the fine (under Article 83(2) GDPR) and to amend its Draft Decision by increasing the level of the fine. (For further detail on the EDPB Decision, please refer to the EDPB website where the EDPB Decision is published).

Decision under Section 111 of 2018 Act

The Commission adopted its final Decision (‘the Decision’) on the basis of the EDPB Decision, pursuant to Article 60(7) in conjunction with Article 65(6), on 9 December 2020. In finding that TIC had infringed both Article 33(1) and Article 33(5), the Commission imposed an administrative fine of $500,000 (estimated for this purpose at €450,000) which reflected an increase in the level of the proposed administrative fine set out in the Draft Decision, in accordance with the direction of the EDPB. In determining this fine, the Commission ensured, as it is required to do under Article 83(1) GDPR, that the fine imposed was effective, proportionate and dissuasive. In this regard, in deciding to impose a fine and in determining the amount of same, the Commission considered the full range of factors under Article 83(2) GDPR in the context of the circumstances of this particular case. In doing so, the Commission had particular regard to the nature, gravity and duration of the infringements concerned, taking account of the nature, scope and purpose of the processing and the number of data subjects affected. The Commission also had regard to the negligent character of the infringements. In setting the fine, the Commission also took account of certain other factors, including the steps that had been taken by Twitter Inc. to rectify the bug.

In reaching its decision in this case, the Commission also highlighted that controller compliance with the obligations under Article 33(1) and Article 33(5) is of central importance to the overall functioning of the supervision and enforcement regime performed by data protection authorities.

For more information, you can download a copy of the full decision at this link: Twitter International Company (‘TIC’) - December 2020  (PDF, 2,014 KB).