Earlier quoted context omitted.
Not to defend the incompetent jerks who run Twitter or anything, but only a complete idiot would have ever trusted them with private or damaging information (including metadata such as locations). Twitter never made any reliable, verifiable guarantees about security or internal controls.
It's not a matter of Twitter giving guarantees about optional data. This is PII, which has to be protected legally. Internal controls at a company of the size of Twitter is no longer optional. You don't have to intend malice to be guilty of negligence. Equifax never gave guarantees of security and data safety either, but it's understood that they should be responsible.
https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-...
To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't post anything important on social media. Just pictures of family vacations and such.