Multiple lawsuits are underway alleging that X (formerly Twitter) improperly shared user data, failed to secure personal information, and violated data protection regulations across different jurisdictions. The cases range from a U.S. federal class action involving 200 million users exposed through a 2022 security vulnerability to separate proceedings in the Netherlands representing millions of European users. The outcomes differ significantly by region—while a U.S. federal judge ruled in mid-2026 that users can proceed with a class-action lawsuit over the data breach, courts in Amsterdam rejected class-action status for similar claims filed by Dutch advocacy groups, narrowing the path to compensation for affected users in those regions.
Three major litigation efforts illustrate the scope of alleged misconduct. The most visible U.S. case centers on a 2022 API vulnerability that allowed anyone possessing a user’s email address or phone number to look up their Twitter ID, potentially compromising personal information for millions. Two separate Dutch proceedings claim that X collected and shared user data through mobile app SDKs (specifically MoPub) without proper consent and maintained inadequate security measures in violation of GDPR and the Digital Services Act. While these cases share similar allegations—unauthorized data access, insufficient transparency, and failure to comply with European data protection law—their legal trajectories have diverged, with Dutch courts blocking collective action status while the U.S. case moves forward.
Table of Contents
- What Are the Main Allegations in X Data Sharing Lawsuits?
- How Many People Are Affected by X Data Sharing Cases?
- What Is the Current Legal Status of X Data Litigation?
- Who Is Eligible to Claim in X Data Sharing Lawsuits?
- What Are the Common Challenges and Limitations in X Data Litigation?
- Regulatory Fines and Government Enforcement Against X
- Tracking Case Updates and Settlement Notices
- Frequently Asked Questions
What Are the Main Allegations in X Data Sharing Lawsuits?
The lawsuits allege several overlapping categories of misconduct. In the Dutch cases, plaintiffs argue that X violated GDPR requirements by collecting and sharing user data through third-party ad networks (MoPub SDK) without explicit, informed consent. The claim includes allegations that X used this data for microtargeting and behavioral profiling while failing to adequately disclose these practices to users. Additionally, the Dutch cases cite inadequate security measures and X’s failure to moderate hate speech on the platform, with one case (SOMI Collective Action) filed in August 2024 on behalf of approximately 7.8 million Dutch users. The U.S. data breach class action focuses on a specific security failure: a 2022 API vulnerability in X’s system that allowed third parties to determine a user’s X ID by supplying only their email address or phone number. This technical flaw exposed personal information for roughly 200 million users, though not all personal data categories may have been accessed uniformly.
The vulnerability was discovered and exploited during a period when twitter was undergoing significant operational changes following Elon Musk’s acquisition, raising questions about whether the company maintained adequate security oversight during that transition. A critical distinction between the cases centers on data *sharing* versus data *breach*. The Dutch cases allege intentional, systematic sharing of user data with advertising partners for profit, even if users did not consent. The U.S. case focuses on an unintended security lapse that allowed unauthorized access. Both claim harm to users, but the legal framing differs: one argues X profited from revealing data, the other argues X was negligent in protecting it. This distinction matters for damages calculations and the evidence required to prove violations.
How Many People Are Affected by X Data Sharing Cases?
The reported scope of affected users reaches into the hundreds of millions, but actual claim participation is far lower. The U.S. data breach class action alleges exposure to 200 million users, though the breach may not have uniformly affected all user categories or compromised all personal information types equally. The SOMI Collective Action in the Netherlands, filed in August 2024, represents approximately 7.8 million Dutch X users, while the separate MoPub data sharing case involves claims on behalf of roughly 11 million Dutch users. However, actual enrollment in the Dutch cases has been minimal: the MoPub case received only about 11,000 registrations out of 11 million potential claimants—a 0.1% participation rate. This dramatic gap between alleged victims and actual claimants illustrates a critical limitation in European collective action models. Unlike the U.S. system, where class members are often automatically included unless they opt out, the Dutch approach requires affirmative registration or participation.
This means that even if a court had approved class-action status (which it did not), the majority of affected users would never receive notice or claim compensation unless they actively sought information. Furthermore, the Dutch court rejected class-action status for both cases in early 2026, converting them to foundational actions where damages, if awarded, may not automatically extend to all potential beneficiaries. Geographic differences also matter significantly. U.S. users potentially affected by the 2022 API breach have a clearer path to collective action, though they must still meet class certification requirements and navigate federal litigation timelines. European users—particularly those in the Netherlands—face both smaller individual claim values under GDPR’s data protection framework and structural barriers to collective recovery. A user in the U.S. and a user in the Netherlands affected by the same conduct may face completely different litigation prospects and recovery mechanisms.
What Is the Current Legal Status of X Data Litigation?
The U.S. federal data breach class action advanced significantly in mid-2026 when a federal judge ruled that X users can proceed with a class-action lawsuit over the 2022 API vulnerability. This decision permits the case to move forward as a class action rather than requiring individual arbitration or separate suits, substantially improving recovery prospects for affected users. The case is now in earlier stages of discovery and certification, meaning plaintiffs’ attorneys will gather evidence from X regarding the scope of the breach, the company’s security practices, and the damages caused to users. The Dutch proceedings took a different course. On February 4, 2026, the Amsterdam District Court declined to grant class-action status to the SOMI Collective Action, rejecting the claim brought by the Dutch Foundation on behalf of 7.8 million users.
Twenty days later, on February 24, 2026, the same court ruled against class-action status in the separate MoPub data sharing case, despite claims representing approximately 11 million Dutch users. These rulings effectively ended the collective action path in the Netherlands for these particular cases, leaving individual users with the option to pursue separate claims if they choose—a far costlier and less practical remedy for most people. The implications of these Dutch court decisions are substantial. By denying class-action status, courts limited the ability of advocacy foundations to aggregate claims and pursue damages on behalf of millions of users at once. Even though roughly 11,000 users registered for the MoPub case despite the unfavorable legal framework, the vast majority of the 11 million potential claimants will have no organized mechanism to seek compensation. This contrasts sharply with the U.S. pathway, where certification as a class action means all eligible class members are included unless they affirmatively opt out.
Who Is Eligible to Claim in X Data Sharing Lawsuits?
Eligibility depends on which lawsuit and which jurisdiction a user falls under. For the U.S. federal data breach class action involving the 2022 API vulnerability, the basic criteria include having an X account at the time of or affected by the breach and residing in the United States. The class definition may include account holders whose email address or phone number was used in queries that exploited the API vulnerability, though the precise scope will be refined through the litigation process. Users will need to be able to document their status as an X user and, depending on how the class is ultimately defined, may need to show they suffered damages (though in many class actions, harm is presumed). For the Dutch cases that have been rejected for class-action status, the situation is more complicated. The SOMI Collective Action involved allegations that affected Dutch X users, but without class certification, individual users would need to bring their own claims through Dutch courts or through alternative dispute mechanisms. Similarly, the MoPub data sharing case, which represented approximately 11 million Dutch users, only succeeded in recruiting about 11,000 registered participants before the court denied collective status.
Those who registered may have different standing or claim recognition options than those who did not, but the outcome remains uncertain pending appeals or further litigation. Geographic location matters significantly. U.S. residents have a viable class-action pathway for the 200-million-user breach. Users outside the U.S. but affected by X’s data practices are not included in the U.S. federal suit and must rely on regional litigation, regulatory enforcement, or settlements with X negotiated through other channels. A German user affected by the same MoPub data sharing practices as a Dutch user faces a different litigation landscape, as Germany has its own data protection authorities and court systems. This fragmentation means that the remedy available to an affected user depends largely on where they live—a limitation of international data protection enforcement.
What Are the Common Challenges and Limitations in X Data Litigation?
One significant challenge is that proving damages in data protection cases is often difficult. In the MoPub case, plaintiffs claimed X should owe €250 to €2,500 per person for improper data sharing and targeted advertising. However, calculating actual damages—how much is a user’s data worth, how much did X profit from sharing it, how much did the user lose—remains contentious. Courts vary in how they approach this calculation, and absent direct financial harm (like fraudulent charges), the damages may be theoretical rather than based on out-of-pocket losses. This can reduce settlement or judgment values significantly compared to initial claims. The Dutch court rejections illustrate another structural limitation: not all jurisdictions treat collective action the same way. The Netherlands’ requirement for explicit registration and its skepticism toward foundation-led collective actions means that millions of affected users may have valid claims under GDPR but no practical way to pursue them.
In contrast, the U.S. system’s class-action opt-out model casts a wider net, but U.S. class members often receive modest individual payouts because the total damages pool is shared across hundreds of millions of people. For the 200-million-user X breach, even a successful class action may result in individual settlements measured in tens or low hundreds of dollars rather than thousands. A warning regarding settlement timing: if X reaches a settlement in the U.S. class action, class members will typically have a limited window to submit a claim (usually 60-180 days) to receive a share of the settlement fund. Missing this deadline can forfeit the right to compensation. Users should monitor the case docket and subscribe to settlements.com or similar claim notice databases to avoid missing critical deadlines.
Regulatory Fines and Government Enforcement Against X
Beyond private litigation, government regulators have taken action against X over data practices. On December 5, 2025, the European Commission imposed a €120 million fine on X IC, X, x.AI, and Elon Musk for restricting data access to third-party researchers in violation of Digital Services Act obligations. This regulatory fine is separate from user litigation but reflects the same underlying concerns about X’s data practices and transparency. The European Commission’s enforcement arm determined that X’s restrictions on researcher access to platform data impeded the ability to audit and investigate X’s compliance with digital regulations—a systemic problem that affects users indirectly. Additionally, in July 2026, Elon Musk agreed to pay $1.5 million in civil penalties to the SEC for failing to properly disclose his stock acquisition of Twitter (now X) in compliance with securities laws.
While this SEC settlement addresses disclosure and securities violations rather than data protection directly, it reflects broader concerns about transparency and governance at X. The settlement indicates that federal regulators in the U.S. have found violations of law by X and its executives, which may be relevant background for courts and juries evaluating private data litigation. These regulatory actions do not automatically compensate individual users harmed by data sharing or breaches—fines go to government treasuries. However, they establish that X has violated multiple frameworks (GDPR, DSA, securities law) and may strengthen arguments in private litigation that X’s misconduct was knowing or reckless rather than merely negligent.
Tracking Case Updates and Settlement Notices
Users potentially affected by X data litigation can monitor case progress through several channels. The federal U.S. class action will generate court filings available on the federal district court’s PACER system (Public Access to Court Electronic Records), though accessing PACER requires a basic account. Settlement notices are typically posted on dedicated settlement websites created by claims administrators; users can search settlements.com or classactionrebates.com for notices specific to X data cases, though these databases lag behind case development by weeks or months.
For real-time updates on the U.S. data breach case, consulting the website of the plaintiffs’ law firm handling the action or checking for press releases from data protection advocacy groups provides earlier notice of significant developments (class certification rulings, settlement announcements, court decisions). European users should monitor decisions from the Amsterdam District Court and any appeals in Dutch courts, though English-language summaries may be limited. The key dates to watch include class certification decisions, any appeals of the February 2026 Dutch court orders denying class-action status, and potential settlement negotiations—any of which could shift eligibility or compensation prospects for users.
Frequently Asked Questions
Am I automatically in the X data breach class action if I had a Twitter account in 2022?
Not necessarily. You must likely fit the class definition (affected by the specific API vulnerability, typically residing in the U.S.), but you will only receive compensation if you submit a claim once a settlement is reached. Class membership doesn’t mean automatic payment; it means you have the right to seek recovery.
Can I join the Dutch lawsuits if I am not a Dutch resident?
Unlikely. The Dutch cases were filed on behalf of Dutch users and represent claims under Dutch and EU law. Non-residents would need to pursue separate claims in their own jurisdictions or through international mechanisms, which are rarely practical.
How much money might I receive if X settles?
This is impossible to predict. Payouts depend on the settlement amount, the number of claims filed, and how the settlement is divided among claimants. In similar large data breach class actions, individual payouts have ranged from $5 to $500, depending on the case. For a 200-million-user breach, even a large settlement would be split many ways.
What happens if I don’t claim by the deadline after a settlement?
You forfeit your right to compensation. Settlement claims typically have deadlines of 60 to 180 days. Unclaimed funds may revert to X, the defendant, the court, or cy pres recipients (charities chosen by the court).
Is the European Commission €120 million fine available to me as a user?
No. Regulatory fines go to government treasuries. That money does not compensate individual users. You would need to pursue a separate civil lawsuit or settle with X to receive personal compensation.
Can I sue X myself if the class action doesn’t cover me?
You can attempt to, but X’s terms of service likely require arbitration, meaning you would go before a private arbitrator rather than a court, and at substantial personal expense. Individual litigation is rarely practical for data protection claims valued at hundreds of dollars.
You Might Also Like
- TikTok Children Privacy Lawsuit: Allegations, Eligibility Questions and Case Status
- Snapchat Youth Privacy Lawsuit: Allegations, Eligibility Questions and Case Status
- Meta Facebook Pixel Tracking Lawsuit: Allegations, Eligibility Questions and Case Status