Dutch Regulator Fines Uber €290 Million for GDPR Violations
Uber has been fined €290 million by the Dutch Data Protection Authority (DPA) for breaching the European Union’s General Data Protection Regulation (GDPR). The fine concerns Uber’s transfer of sensitive driver data from Europe to U.S. servers without adequate privacy safeguards.
The Allegations
The DPA found that Uber transferred European drivers’ personal data—including account details, taxi licenses, and even criminal and medical records—to the U.S. for over two years, without proper legal protections in place. This followed Uber’s discontinuation of Standard Contractual Clauses (SCCs) in 2021, leaving data vulnerable after the E.U.-U.S. Privacy Shield was invalidated in 2020. Although a replacement framework was introduced in 2023, Uber’s earlier practices were deemed insufficient. The company has since complied with the regulator’s demands.
Uber’s Reaction
Uber strongly disagrees with the fine, calling it “unjustified.” It insists its data transfers were GDPR-compliant at the time and plans to contest the decision.
This follows a €10 million fine in January 2024 for unclear data retention policies and restricted driver access to personal information.
A Broader Issue for U.S. Companies
Uber’s case underscores the challenges U.S. companies face under GDPR when transferring data. Other major companies, like Google, have faced similar issues due to differing privacy standards between the E.U. and the U.S. Aleid Wolfsen, chairman of the Dutch DPA, stressed the need for businesses to take extra precautions when moving European data abroad.
Looking Ahead
This fine is a stark reminder of the growing regulatory focus on data privacy. As the E.U. enforces strict GDPR standards, companies must ensure compliance or face steep penalties.
As individuals, we should also be mindful of how our data is handled by the services we use. Ensuring that companies are transparent and accountable with our personal information is essential in today’s digital age, where privacy risks are ever-present. Being aware and proactive about data security is not just a corporate responsibility—it’s something we all need to prioritize.




