Dutch Regulator Fines Uber €290 Million for GDPR Violations

Uber has been fined €290 million by the Dutch Data Protection Authority (DPA) for breaching the European Union’s General Data Protection Regulation (GDPR). The fine concerns Uber’s transfer of sensitive driver data from Europe to U.S. servers without adequate privacy safeguards.

The Allegations

The DPA found that Uber transferred European drivers’ personal data—including account details, taxi licenses, and even criminal and medical records—to the U.S. for over two years, without proper legal protections in place. This followed Uber’s discontinuation of Standard Contractual Clauses (SCCs) in 2021, leaving data vulnerable after the E.U.-U.S. Privacy Shield was invalidated in 2020. Although a replacement framework was introduced in 2023, Uber’s earlier practices were deemed insufficient. The company has since complied with the regulator’s demands.

Uber’s Reaction

Uber strongly disagrees with the fine, calling it “unjustified.” It insists its data transfers were GDPR-compliant at the time and plans to contest the decision.

This follows a €10 million fine in January 2024 for unclear data retention policies and restricted driver access to personal information.

A Broader Issue for U.S. Companies

Uber’s case underscores the challenges U.S. companies face under GDPR when transferring data. Other major companies, like Google, have faced similar issues due to differing privacy standards between the E.U. and the U.S. Aleid Wolfsen, chairman of the Dutch DPA, stressed the need for businesses to take extra precautions when moving European data abroad.

Looking Ahead

This fine is a stark reminder of the growing regulatory focus on data privacy. As the E.U. enforces strict GDPR standards, companies must ensure compliance or face steep penalties.

As individuals, we should also be mindful of how our data is handled by the services we use. Ensuring that companies are transparent and accountable with our personal information is essential in today’s digital age, where privacy risks are ever-present. Being aware and proactive about data security is not just a corporate responsibility—it’s something we all need to prioritize.

Stay safe and vigilant

TALK TO AN EXPERT

Contact us today to guide you how to protect your organization and achieve cyber resilience.

TALK TO AN EXPERT

Contact us today to guide you how to protect your organization and achieve cyber resilience.

SIGN UP

Subscribe for the industry news, in-depth blog posts, and Odyssey-exclusive updates directly in your inbox.