Dutch Data Regulator Imposes 290 Million Euro Fine on Uber

Published:

spot_img

Uber Fined 290 Million Euros by Dutch DPA for Data Protection Violations

The Dutch Data Protection Authority (DPA) has dealt a heavy blow to ride-hailing giant Uber, imposing a staggering fine of 290 million euros for its failure to adequately protect the personal data of European taxi drivers. This marks the third time the Dutch DPA has taken action against Uber, with previous fines of 10 million euros in 2023 and 600,000 euros in 2018.

The DPA found that Uber had collected and transferred sensitive information of European drivers to its headquarters in the United States without using the necessary data transfer tools to ensure compliance with the EU’s General Data Protection Regulation (GDPR). This included account details, taxi licenses, location data, photos, payment details, identity documents, and even criminal and medical records.

Dutch DPA chairman Aleid Wolfsen emphasized the importance of protecting personal data, stating, “In Europe, the GDPR protects the fundamental rights of people, by requiring businesses and governments to handle personal data with due care.” He highlighted the seriousness of Uber’s failure to meet GDPR requirements for data protection during transfers to the US.

The investigation into Uber’s data practices was initiated following complaints from over 170 French drivers, leading to a coordinated effort between the French and Dutch DPAs. The fine, amounting to 4% of Uber’s worldwide annual turnover in 2023, is the largest penalty imposed by the Dutch DPA on the company.

Uber has expressed its intention to challenge the fine, continuing a pattern of contesting previous penalties. The case is now awaiting further developments as Uber faces the consequences of its data protection violations.

spot_img

Related articles

Recent articles

Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues

Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This vulnerability could be exploited through a...

Data Breach at France’s Tax Authority Affects Approximately 680,000 Individuals

France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The breach was revealed after a threat actor...

Citrix security advisory AV26-645 warns of active exploitation of CVE-2026-8451 and CVE-2026-8452

Citrix Security Advisory AV26-645: Critical Vulnerabilities in NetScaler Products On June 30, 2026, Citrix issued a security advisory detailing critical vulnerabilities affecting several versions of...

Colombia’s Ministry of Justice Hit by Ransomware Attack Disrupting Services

In a significant cybersecurity incident, Colombia's Ministry of Justice has fallen victim to a ransomware attack that has disrupted critical public services, particularly those...