Privacy

Privacy complaint takes aim at Musk’s X over EU ads targeted on sensitive data

Comment

X icon on a smartphone screen
Image Credits: Matt Cardy / Contributor (opens in a new window) / Getty Images

Elon Musk’s X, the social media platform formerly known as Twitter, is facing a new privacy complaint in Europe related to its ad targeting tools. The complaint, which is being lodged with the Dutch data protection authority by privacy rights not-for-profit noyb, accuses X of failing to enforce its own its advertising guidelines.

While X’s T&Cs prohibit people’s political affiliations and/or religious beliefs being used to target them with ads, an advertiser on its platform — actually the European Commission itself, no less (awks!) — was able to use exactly this kind of sensitive personal data to target users with ads.

The bloc’s staffers used X’s tools in this way in order to promote a controversial legislative proposal to scan people’s messages for child sexual abuse material (CSAM).

As we reported last month, noyb already filed a complaint against the Commission for apparently breaching pan-EU rules it helped to draw up. It’s now followed up by filing a complaint against X too. “After we filed our first complaint in this matter, the EU Commission has already confirmed to stop advertising on X. However, to put an end to this in general, we need enforcement against X as a platform used by many others,” said Felix Mikolasch, data protection lawyer at noyb, in a statement.

As well as the EU’s General Data Protection Regulation (GDPR) setting strict limits on how sensitive personal data such as political affiliation and religious beliefs may be processed — requiring those wanting to do this obtain the explicit consent of the people in question — the bloc’s recently enacted Digital Services Act (DSA) stipulates that use of personal data for ad targeting requires consent. Yet the users of X whose data was processed were not explicitly asked to agree to this use of their info.

“[X] used this specially protected data to determine whether people should or should not see an ad campaign by the EU Commission’s Directorate General for Migration and Home Affairs, which tried to rally support for the proposed ‘chat control’ [CSAM scanning] in the Netherlands,” noyb wrote in a press release. “In November, this unlawful use of micro-targeting already prompted noyb to file a complaint against the EU Commission itself. Now, noyb follows up with a complaint against X. By enabling this practice in the first place, the company violated both the GDPR and the DSA.”

In a particularly ironic twist, the Commission is actually in charge of overseeing DSA compliance on so-called very large online platforms (VLOPs) like, er, X.

Indeed, in recent months, since the DSA came into force on VLOPs, the EU’s executive has been pressing X over compliance — specifically over concerns about the spread of illegal content and disinformation on the platform related to the Israel-Hamas war.  But — funnily enough — the Commission doesn’t appear to have asked X to demonstrate its ad targeting business is complying with the regulation. (Still, given some of its own staffers were apparently busy breaking these rules it’s perhaps not too surprising?)

noyb confirmed to us it hasn’t filed a DSA complaint against X with the Commission; it’s limited its action to lodging a grievance with the Dutch DPA. It said the reason it’s picked a Netherlands-based privacy authority for sending the complaint is because the controversial ads were targeted at X users in the country; and the complainant noyb is supporting to make the complaint is Dutch. However X is regionally headquartered in Ireland, so it’s likely the Netherlands authority would engage with the Irish Data Protection Commission (DPC) on any GDPR investigation of unlawful data processing for ad targeting.

But why isn’t noyb filing a DSA complaint about X with the European Commission? A spokesman for the not-for-profit told us it’s not taken that step as the two data protection complaints it’s now made — i.e., one against the Commission filed to the EDPS (European Data Protection Supervisor, which oversees EU institutions’ compliance with the rules); and one against X sent now to a national DPA — could lead to cooperation between these data supervisors “on an almost identical case”.

“It remains to be seen if the Commission may take action against X itself under the DSA,” noyb further added.

While penalties for violations of the GDPR can scale up to 4% of global annual turnover, the DSA’s regime allows for even larger sanctions — of up to 6%. So if enforcement action is taken under both regimes Musk’s company could face a double whammy of regulatory sanctions. (GDPR-DSA sandwich anyone?)

The Commission was contacted for an update on its own internal investigation into the controversial CSAM proposal ads targeting; and to ask whether it will be taking action against X, in its capacity as enforcer of the DSA on VLOPs, for accepting the unlawful ads. But a spokesman for the EU’s executive declined to provide an update “at the moment” — instead they reiterated the Commission’s earlier decision to advise its internal services to stop all types of paid communications on X.

Irish GDPR oversight of X

As noted above, noyb’s GDPR complaint against X, meanwhile, is likely to end up on the desk of the Irish privacy watchdog, the DPC.

Since Musk took over Twitter and set about imposing his distinctive stamp on the company (and its product), the DPC has responded by making a few public noises in the wake of certain controversial decisions by the new owner — such as Musk’s decision to let outside journalists access Twitter data; or his rolling out of a paid verification feature in the EU without prior notice; or not informing the watchdog when the DPO resigned — but the Irish regulator appears to have held back from harder interventions on the company. This is despite growing privacy concerns in areas like data deletion and the privacy and security of direct messages (DMs) under Musk’s ownership of Twitter/X.

Additionally, Musk’s X remains main established in Ireland, under the DPC’s lead oversight. It holds this status despite the US-based billionaire’s erratic leadership and unilateral decision-making — which have thrown up doubts that product decisions affecting EU users are really getting meaningful local input, as should be the case for X to claim main establishment locally. The designation is important as it allows the company continue to shrink its regulatory risk in the EU by benefiting from the streamlined oversight afforded by the GDPR’s one-stop-shop (OSS).

Again, aside from a few public expressions of concern in the early months of Musk’s takeover, the Irish regulator has not rocked the company’s boat here.

Looking further back, since the GDPR came into force, the DPC has issued just one public penalty on Twitter, as the company was still called at the time of the sanction a full three years ago. The penalty consisted of a fine of around $550k for failing to promptly report a data breach. So it’s fair to say the platform has had a pretty smooth ride under Irish privacy oversight to-date, even with Musk taking over steering the ship.

Still, it remains to be seen what the DPC might make of a complaint about X breaching ad targeting rules — assuming noyb’s latest strategic action ends up being referred to Ireland by the Dutch DPA, as seems likely under the OSS rules. The regulator has previously paid some mind to concerns about Twitter/X’s legal basis for ads when Musk was rumored to be planning to force users to choose between accepting personalized ads or paying him a subscription.

A cut-and-dried case of X failing to uphold its own advertiser T&Cs — if, indeed, that’s what noyb’s complaint boils down to — looks more straightforward than that.

EU faces privacy complaint over CSAM microtargeting ads it ran on X

EU commissioner sidesteps MEPs’ questions about CSAM proposal microtargeting

More TechCrunch

Last month, one of the Bay Area’s better-known early-stage venture capital firms, Uncork Capital, marked its 20th anniversary with a party in a renovated church in San Francisco’s SoMa neighborhood,…

A venture capital firm looks back on changing norms, from board seats to backing rival startups

The families of victims of the shooting at Robb Elementary School in Uvalde, Texas are suing Activision and Meta, as well as gun manufacturer Daniel Defense. The families bringing the…

Families of Uvalde shooting victims sue Activision and Meta

Like most Silicon Valley VCs, what Garry Tan sees is opportunities for new, huge, lucrative businesses.

Y Combinator’s Garry Tan supports some AI regulation but warns against AI monopolies

Everything in society can feel geared toward optimization – whether that’s standardized testing or artificial intelligence algorithms. We’re taught to know what outcome you want to achieve, and find the…

How Maven’s AI-run ‘serendipity network’ can make social media interesting again

Miriam Vogel, profiled as part of TechCrunch’s Women in AI series, is the CEO of the nonprofit responsible AI advocacy organization EqualAI.

Women in AI: Miriam Vogel stresses the need for responsible AI

Google has been taking heat for some of the inaccurate, funny, and downright weird answers that it’s been providing via AI Overviews in search. AI Overviews are the AI-generated search…

What are Google’s AI Overviews good for?

When it comes to the world of venture-backed startups, some issues are universal, and some are very dependent on where the startups and its backers are located. It’s something we…

The ups and downs of investing in Europe, with VCs Saul Klein and Raluca Ragab

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. OpenAI announced this week that…

Scarlett Johansson brought receipts to the OpenAI controversy

Accurate weather forecasts are critical to industries like agriculture, and they’re also important to help prevent and mitigate harm from inclement weather events or natural disasters. But getting forecasts right…

Deal Dive: Can blockchain make weather forecasts better? WeatherXM thinks so

pcTattletale’s website was briefly defaced and contained links containing files from the spyware maker’s servers, before going offline.

Spyware app pcTattletale was hacked and its website defaced

Featured Article

Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Synapse’s bankruptcy shows just how treacherous things are for the often-interdependent fintech world when one key player hits trouble. 

1 day ago
Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Sarah Myers West, profiled as part of TechCrunch’s Women in AI series, is managing director at the AI Now institute.

Women in AI: Sarah Myers West says we should ask, ‘Why build AI at all?’

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI and publishers are partners of convenience

Evan, a high school sophomore from Houston, was stuck on a calculus problem. He pulled up Answer AI on his iPhone, snapped a photo of the problem from his Advanced…

AI tutors are quietly changing how kids in the US study, and the leading apps are from China

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Well,…

Startups Weekly: Drama at Techstars. Drama in AI. Drama everywhere.

Last year’s investor dreams of a strong 2024 IPO pipeline have faded, if not fully disappeared, as we approach the halfway point of the year. 2024 delivered four venture-backed tech…

From Plaid to Figma, here are the startups that are likely — or definitely — not having IPOs this year

Federal safety regulators have discovered nine more incidents that raise questions about the safety of Waymo’s self-driving vehicles operating in Phoenix and San Francisco.  The National Highway Traffic Safety Administration…

Feds add nine more incidents to Waymo robotaxi investigation

Terra One’s pitch deck has a few wins, but also a few misses. Here’s how to fix that.

Pitch Deck Teardown: Terra One’s $7.5M Seed deck

Chinasa T. Okolo researches AI policy and governance in the Global South.

Women in AI: Chinasa T. Okolo researches AI’s impact on the Global South

TechCrunch Disrupt takes place on October 28–30 in San Francisco. While the event is a few months away, the deadline to secure your early-bird tickets and save up to $800…

Disrupt 2024 early-bird tickets fly away next Friday

Another week, and another round of crazy cash injections and valuations emerged from the AI realm. DeepL, an AI language translation startup, raised $300 million on a $2 billion valuation;…

Big tech companies are plowing money into AI startups, which could help them dodge antitrust concerns

If raised, this new fund, the firm’s third, would be its largest to date.

Harlem Capital is raising a $150 million fund

About half a million patients have been notified so far, but the number of affected individuals is likely far higher.

US pharma giant Cencora says Americans’ health information stolen in data breach

Attention, tech enthusiasts and startup supporters! The final countdown is here: Today is the last day to cast your vote for the TechCrunch Disrupt 2024 Audience Choice program. Voting closes…

Last day to vote for TC Disrupt 2024 Audience Choice program

Featured Article

Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Among other things, Whittaker is concerned about the concentration of power in the five main social media platforms.

3 days ago
Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Lucid Motors is laying off about 400 employees, or roughly 6% of its workforce, as part of a restructuring ahead of the launch of its first electric SUV later this…

Lucid Motors slashes 400 jobs ahead of crucial SUV launch

Google is investing nearly $350 million in Flipkart, becoming the latest high-profile name to back the Walmart-owned Indian e-commerce startup. The Android-maker will also provide Flipkart with cloud offerings as…

Google invests $350 million in Indian e-commerce giant Flipkart

A Jio Financial unit plans to purchase customer premises equipment and telecom gear worth $4.32 billion from Reliance Retail.

Jio Financial unit to buy $4.32B of telecom gear from Reliance Retail

Foursquare, the location-focused outfit that in 2020 merged with Factual, another location-focused outfit, is joining the parade of companies to make cuts to one of its biggest cost centers –…

Foursquare just laid off 105 employees

“Running with scissors is a cardio exercise that can increase your heart rate and require concentration and focus,” says Google’s new AI search feature. “Some say it can also improve…

Using memes, social media users have become red teams for half-baked AI features