Twitter in the United States has been fined $150 million (£119 million) after law enforcement authorities accused it of improperly utilizing user data to sell tailored adverts. According to court records, the Federal Trade Commission (FTC) and the Department of Justice claim that Twitter broke an agreement with regulators.
Twitter had vowed to not give personal information like phone numbers and email addresses to advertisers. Federal investigators say the social media company broke those rules.
Twitter was fined £400,000 in December 2020 for breaking Europe’s GDPR data privacy rules.
The FTC is an independent agency of the US government whose mission is the enforcement of antitrust laws and the promotion of consumer protection.
It accuses Twitter of breaching a 2011 FTC order that explicitly prohibited the company from misrepresenting its privacy and security practices.
Twitter generates most of its revenue from advertising on its platform, which allows users ranging from consumers to celebrities to corporations to post 280-character messages or tweets.
According to a complaint filed by the Department of Justice on behalf of the FTC, Twitter 2013 began asking users to provide either a phone number or email address to improve account security.
“As the complaint notes, Twitter obtained data from users on the pretext of harnessing it for security purposes, but then ended up also using the data to target users with ads,” said Lina Khan, who chairs the FTC.
“This practice affected more than 140 million Twitter users while boosting Twitter’s primary source of revenue.”
Ian Reynolds, managing director of computer security firm Secure Team, told the BBC: “Once again, Twitter is violating the trust that their users have in their platform by using their private information to their advantage and increasing their revenue.”
He added, “Twitter led their customers into a false sense of security by acquiring their data through claiming it was for security purposes and protecting their account, but ultimately ended up using the data to target their users with ads.
“This reality shows the power that companies still have over your data and that there is a long way to go before users can be comfortable knowing that they have full control over their digital footprint.”
To authenticate an account, Twitter requires people to provide a telephone number and email address.
But, according to the FTC, until at least September 2019, Twitter was also using that information to boost its advertising business.
It is accused of allowing advertisers access to users’ security information.
In addition to the fine, Twitter must also:
- stop using the phone numbers and email addresses it illegally collected
- notify users about its improper use of security information
- tell users about the FTC law enforcement action
- explain how to turn off personalized adverts and review multi-factor authentication settings
- provide multi-factor authentication options that do not need a phone number
- implement an enhanced privacy and security program which includes reporting incidents to the FTC within 30 days
“The Department of Justice is committed to protecting the privacy of consumers’ sensitive data,” said Vanita Gupta, the US associate attorney general.
“The $150m penalty reflects the seriousness of the allegations against Twitter, and the substantial new compliance measures to be imposed as a result of the proposed settlement will help prevent further misleading tactics that threaten users’ privacy.”