https://www.ftc.gov/business-guidance/blog/2022/05/twitter-pay-150-million-penalty-allegedly-breaking-its-privacy-promises-again Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know Dot gov The .gov means it's official. Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site. Https The site is secure. The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely. Translation Menu * Espanol Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library Menu close Main Menu Mega * Show/hide Enforcement menu items Enforcement We enforce federal competition and consumer protection laws that prevent anticompetitive, deceptive, and unfair business practices. View Enforcement Search or browse the Legal Library Find legal resources and guidance to understand your business responsibilities and comply with the law. Browse legal resources Search small [ ]Search Sections + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog Take action + Report an antitrust violation + File adjudicative documents + Find banned debt collectors + View competition guidance Competition Matters Blog Competition Matters HSR threshold adjustments and reportability for 2022 the Premerger Notification Office Staff February 11, 2022 View all Competition Matters Blog posts * Show/hide Policy menu items Policy We work to advance government policies that protect consumers and promote competition. View Policy Search or browse the Legal Library Find legal resources and guidance to understand your business responsibilities and comply with the law. Browse legal resources Search small [ ]Search Sections + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International Take action + Find policy statements + Submit a public comment Feature [ftc_hq6_400x350] Vision and Priorities Memo from Chair Lina M. Khan to commission staff and commissioners regarding the vision and priorities for the FTC. Learn more Tech@FTC Blog Tech@FTC On FTC's Twitter Case: Enhancing Security Without Compromising Privacy DPIP and CTO Staff May 25, 2022 View all Tech@FTC Blog posts * Show/hide Advice and Guidance menu items Advice and Guidance Learn more about your rights as a consumer and how to spot and avoid scams. Find the resources you need to understand how consumer protection law impacts your business. Take action + Report fraud + Report identity theft + Register for Do Not Call + Sign up for consumer alerts + Get Business Blog updates + Get your free credit report + Find refund cases + Order bulk publications Consumer Advice + Shopping and Donating + Credit, Loans, and Debt + Jobs and Making Money + Unwanted Calls, Emails, and Texts + Identity Theft and Online Security + Scams Business Guidance + Advertising and Marketing + Credit and Finance + Privacy and Security + By Industry + For Small Businesses + Browse Business Guidance Resources + Business Blog Servicemembers: Your tool for financial readiness Visit militaryconsumer.gov Get consumer protection basics, plain and simple Visit consumer.gov Learn how the FTC protects free enterprise and consumers Visit Competition Counts Looking for competition guidance? Competition Guidance * Show/hide News and Events menu items News and Events Latest News Press Release FTC Extends its Crackdown on Subscription Scam That Fleeced Consumers and Harassed Them Over the Phone May 25, 2022 View News and Events Upcoming Event May25 Webinar: Spot and avoid scams, identity theft, and impersonators Wednesday, May 25, 2022 | 2:00PM - 3:00PM View more Events Sections + News + Events + Features + Topics + Data and Visualizations + Stay Connected Sign up for the latest news Follow us on social media Feature Computer-generated illustration of gray and red coronavirus cell on solid black background Coronavirus Scams Spot the latest COVID scams, get compliance guidance, and stay up to date on FTC actions during the pandemic. Latest Data Visualization COVID-19 Visualization Map Daily COVID-19 Complaint Data Use our visualizations to explore scam and fraud trends in your state based on reports from consumers like you. * Show/hide About the FTC menu items About the FTC Our mission is protecting consumers and competition by preventing anticompetitive, deceptive, and unfair business practices through law enforcement, advocacy, and education without unduly burdening legitimate business activity. Learn more about the FTC Sections + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Careers at the FTC + Contact Featured Lina M. Khan Meet the Chair Lina Khan was sworn in as Chair of the Federal Trade Commission on June 15, 2021. Chair Lina Khan * Search Show/hide Search menu items Enter Search Term(s): [ ][Search] Looking for legal documents or records? Search the Legal Library instead. Translation Menu * Espanol Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library * Enforcement Show/hide Enforcement menu items + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog * Policy Show/hide Policy menu items + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International * Advice and Guidance Show/hide Advice and Guidance menu items + Consumer Advice + Military Consumer + Consumer.gov + Business Guidance + Competition Guidance + Bulk Publications * News and Events Show/hide News and Events menu items + News + Events + Features + Topics + Data and Visualizations + Stay Connected * About the FTC Show/hide About the FTC menu items + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Careers at the FTC + Contact Enter Search Term(s): [ ][Search] Looking for legal documents or records? Search the Legal Library instead. Breadcrumb 1. Home 2. Business Guidance 3. Business Blog Business Blog Twitter to pay $150 million penalty for allegedly breaking its privacy promises - again By Lesley Fair May 25, 2022 It's FTC 101. Companies can't tell consumers they will use their personal information for one purpose and then use it for another. But according to the FTC, that's the kind of digital bait-and-switch Twitter pulled on unsuspecting consumers. Twitter asked users for personal information for the express purpose of securing their accounts, but then also used it to serve targeted ads for Twitter's financial benefit. It wasn't Twitter's first alleged violation of the FTC Act, but this one will cost the company $150 million in civil penalties. The story starts with the FTC's 2010 complaint against Twitter. In that case, Twitter told users that users could control who had access to their tweets and that their private messages could be viewed only by recipients. But according to the FTC, Twitter didn't have reasonable safeguards to ensure users' choices were honored. The 2010 complaint cited multiple instances in which Twitter's actions - and inactions - led to unauthorized access of users' personal information. To settle that case, the company agreed to an order that became final in 2011 that would impose substantial financial penalties if it further misrepresented "the extent to which [Twitter] maintains and protects the security, privacy, confidentiality, or integrity of any nonpublic consumer information." The just-announced $150 million civil penalty stems from a new complaint filed by the Department of Justice on behalf of the FTC, alleging that Twitter violated the order in the earlier case by collecting customers' personal information for the stated purpose of security and then exploiting it commercially. You'll want to read the complaint for the details, but here's how the FTC says Twitter deceived its customers. Image Twitter complaint excerpts 2022 From May 2013 through September 2019, Twitter prompted users to provide their telephone numbers or email addresses for security purposes, such as to enable multi-factor authentication. (Multi-factor authentication is an additional layer of security that requires separate forms of identification to access an account - for example, a password and a code sent to a user's verified email address.) Twitter also told people it would use their personal data to help with account recovery (for example, if users forgot their passwords) or to re-enable full access if Twitter detected suspicious activity on a person's account. The FTC says Twitter induced people to provide their phone numbers and email addresses by claiming that the company's purpose was, for example, to "Safeguard your account." Twitter further encouraged users to provide that information because "An extra layer of security helps make sure that you, and only you, can access your Twitter account." But according to the FTC, much more was going on behind the scenes. In fact, in addition to using people's phone numbers and email addresses for the protective purposes the company claimed, Twitter also used the information to serve people targeted ads - ads that enriched Twitter by the multi-millions. Just how persuasive was Twitter's security pitch? During the time period covered by the complaint, more than 140 million users gave Twitter their email addresses or phone numbers for security purposes. Would that same number of people have given Twitter that information if they knew how else Twitter was going to use it? We don't think so. If you're struck by the irony of a company exploiting consumers' privacy concerns in a way that facilitated further invasions of co nsumers' privacy, it's an irony not lost on the FTC. In addition to imposing a $150 million civil penalty for violating the 2011 order, the new order adds more provisions to protect consumers in the future: * Twitter is prohibited from using the phone numbers and email addresses it illegally collected to serve ads. * Twitter must notify users about its improper use of phone numbers and email addresses, tell them about the FTC law enforcement action, and explain how they can turn off personalized ads and review their multi-factor authentication settings. * Twitter must provide multi-factor authentication options that don't require people to provide a phone number. * Twitter must implement an enhanced privacy program and a beefed-up information security program that includes multiple new provisions spelled out in the order, get privacy and security assessments by an independent third party approved by the FTC, and report privacy or security incidents to the FTC within 30 days. What can other companies take from the latest action against Twitter? What the text giveth, a privacy policy or buried disclaimer cannot taketh away. Consumers have a right to rely on what you say at the time you ask for their information. Trying to take it back in a contradictory statement buried elsewhere on your website is unlikely to correct a misrepresentation. Keeping customers' information secure is a win-win. Consumers benefit when companies take extra steps to protect their personal data. So let's be clear: Multi-factor authentication can be an effective way to do that. Don't discourage people from agreeing to multi-factor authentication by making them give up their privacy to use it. Violating FTC orders will result in substantial penalties. The FTC takes order enforcement seriously and will use every lawful means to hold recidivists responsible for further violations. Looking for more about the Twitter case? Read the FTC's Tech Blog. Tags: * Consumer Protection * Bureau of Consumer Protection * Privacy and Security * Consumer Privacy * Data Security * Tech Subscribe Get Business Blog updates by email. Topics Advertising and Marketing (435) Advertising and Marketing Basics (180) Children (29) Children's Privacy (40) Consumer Privacy (93) Credit and Finance (192) Credit and Loans (62) Credit Reporting (54) Data Security (152) Debt (29) Debt Collection (38) Endorsements, Influencers, and Reviews (95) Environmental Marketing (30) FinTech (30) Gramm-Leach-Bliley Act (21) Health Claims (135) Health Privacy (9) Made in USA (20) Mortgages (12) Online Advertising and Marketing (153) Payments and Billing (79) Privacy and Security (277) Privacy Shield (12) Red Flags Rule (3) Self-Regulation (1) Small Business (113) Tech (55) Telemarketing (68) U.S.-EU Safe Harbor Framework (2) Selected Industries Alcohol (2) Appliances (12) Automobiles (40) Clothing and Textiles (24) Finance (34) Franchises, Business Opportunities, and Investments (56) Funerals (5) Human Resources (33) Jewelry (6) Non-Profits (15) Real Estate and Mortgages (13) Tobacco (4) Archives May 2022 (9) April 2022 (8) March 2022 (12) January 2022 (7) December 2021 (3) November 2021 (4) October 2021 (6) September 2021 (5) August 2021 (1) July 2021 (1) View More 0 Comments Leave a comment Add new comment Your name [ ] Comment [ ] [ ] [ ] [ ] [ ] * CAPTCHA This question is for testing whether or not you are a human visitor and to prevent automated spam submissions. [Save][Preview] Read Our Privacy Act Statement It is your choice whether to submit a comment. If you do, you must create a user name, or we will not post your comment. The Federal Trade Commission Act authorizes this information collection for purposes of managing online comments. Comments and user names are part of the Federal Trade Commission's (FTC) public records system, and user names also are part of the FTC's computer user records system. We may routinely use these records as described in the FTC's Privacy Act system notices. For more information on how the FTC handles information that we collect, please read our privacy policy. Comment Policy This is a moderated blog; we review all comments before they are posted. We expect participants to treat each other and the bloggers with respect. We will not post comments that do not comply with our commenting policy. We may edit comments to remove links to commercial websites or personal information before posting them. We won't post: * spam or off-topic comments * comments that contain vulgar language, personal attacks, or offensive terms that target specific groups * sales pitches or promotions * comments that contain clearly misleading or false information * comments that contain personal information, like home addresses Comments submitted to this blog become part of the public domain. To protect your privacy and the privacy of others, please do not include personal information. Also, do not use this blog to report fraud; instead, file a complaint. More from the Business Blog Business Blog New publication offers guidance on revised FTC Safeguards Rule Lesley Fair May 24, 2022 Business Blog Save the date: FTC to host "Protecting Kids from Stealth Advertising in Digital Media" Lesley Fair May 20, 2022 Business Blog FTC to Ed Tech: Protecting kids' privacy is your responsibility Lesley Fair May 19, 2022 Business Blog First FTC case under opioid statute challenges acts of company that provided marketing services to treatment centers Lesley Fair May 17, 2022 Get Business Blog updates Enter your email to subscribe to Business Center Blog [ ][Subscribe] Return to top Menu Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library Main navigation * Enforcement + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog * Policy + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International * Advice and Guidance + Consumer Advice + Military Consumer + Consumer.gov + Business Guidance + Competition Guidance + Bulk Publications * News and Events + News + Events + Features + Topics + Data and Visualizations + Stay Connected * About the FTC + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Careers at the FTC + Contact Footer * Privacy Policy * Policy and Notices * FOIA * No FEAR Act * Office of Inspector General * USA.gov