Listen to great music on ZED 101.9FM

Listen Now

Uber Fined €290 Million for GDPR Violations Over Data Transfers to U.S. Servers

Uber has been slapped with a €290 million (£246 million; $324 million) fine by the Dutch Data Protection Authority (DPA) for illegally transferring the personal data of European drivers to U.S. servers. The DPA announced on Monday that these transfers constituted a “serious violation” of the EU’s General Data Protection Regulation (GDPR), as Uber failed to adequately protect sensitive driver information.

The watchdog revealed that over a two-year period, Uber transferred data including ID documents, taxi licenses, and location information to its U.S. headquarters. The DPA emphasized that such transfers breached GDPR requirements, which mandate that companies ensure a high level of protection for personal data when it is transferred outside the European Union.

Uber has expressed its intention to appeal the fine, describing it as “unjustified.” A spokesperson for the company stated, “Uber’s cross-border data transfer process was compliant with GDPR during a three-year period of immense uncertainty between the EU and U.S. This flawed decision and extraordinary fine are completely unjustified.”

While EU law permits data transfers to the U.S., significant ambiguity exists around the conditions under which these transfers can occur without additional authorization. DPA Chairman Aleid Wolfsen criticized Uber for failing to meet GDPR standards, stating, “The company did not ensure the level of protection required for data transfers to the U.S. This is very serious.”

The DPA’s investigation, which began after more than 170 French drivers filed complaints through a French human rights group, uncovered that Uber collected and transferred sensitive information such as taxi licenses, location data, photos, payment details, identity documents, and in some cases, even criminal and medical records of drivers.

Under GDPR, companies operating in multiple EU countries are required to work with the data protection authority in the country where their main office is located. Uber’s European headquarters are based in the Netherlands, making the DPA the relevant authority for this case.

“In Europe, the GDPR protects the fundamental rights of people by requiring businesses and governments to handle personal data with due care,” Wolfsen explained. He further noted that companies often need to take extra precautions if they store European personal data outside the EU. This fine marks the third time the DPA has penalized Uber, following fines of €600,000 (£508,000) in 2018 and €10 million (£8.5 million) last year. The EU has been increasingly vigilant in enforcing data protection laws, imposing substantial fines on major tech firms for violations. For example, last year, Irish regulators fined TikTok €345 million (£296 million) for breaching children’s privacy under GDPR rules.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *