{"id":17299,"date":"2024-12-16T06:00:50","date_gmt":"2024-12-16T06:00:50","guid":{"rendered":"https:\/\/letslaw.es\/?p=17299"},"modified":"2024-12-10T09:11:38","modified_gmt":"2024-12-10T09:11:38","slug":"uber-fine-dutch-dpa","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/uber-fine-dutch-dpa\/","title":{"rendered":"Uber objects to Dutch DPA&#8217;s third and largest fine for transferring data to US"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The Dutch Data Protection Authority (DPA) has imposed a hefty fine on Uber due to a series of serious breaches of the <\/span><a title=\"privacy data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/legal-advice\/\"><span style=\"font-weight: 400;\">General Data Protection Regulation<\/span><\/a><span style=\"font-weight: 400;\"> (GDPR).\u00a0<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Reasons for the sanction<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The investigation conducted by the DPA revealed that the technology company had collected and transferred a wide range of <\/span><b>personal data of European drivers to its servers located in the United States<\/b><span style=\"font-weight: 400;\">, without ensuring adequate security measures to protect such information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Among the personal data collected were:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Account information:<\/b><span style=\"font-weight: 400;\"> usernames, passwords and contact details.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Cab licenses: <\/b><span style=\"font-weight: 400;\">licenses and authorizations required to operate as a driver.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Location data:<\/b><span style=\"font-weight: 400;\"> real-time information about the driver&#8217;s location.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Photographs:<\/b><span style=\"font-weight: 400;\"> images of the driver and his vehicle.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Payment data:<\/b><span style=\"font-weight: 400;\"> information related to transactions made through the platform.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Identity documents:<\/b><span style=\"font-weight: 400;\"> copies of official documents such as ID card or passport.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Sensitive data:<\/b><span style=\"font-weight: 400;\"> in some cases, sensitive information such as criminal records and medical data has been collected.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The transfer of this data to the United States took place for more than two years, without Uber implementing adequate data transfer tools, such as standard contractual clauses, which guarantee a level of protection equivalent to that set out in the GDPR. This situation was further aggravated following the invalidation of the EU-US Privacy Shield by the Court of Justice. This situation was further aggravated following the invalidation of the EU-US Privacy Shield by the Court of Justice of the European Union in 2020.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Non-Compliance and Regulation<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Uber&#8217;s conduct represents a clear violation of the GDPR, which establishes a stringent legal framework for the protection of personal data in the European Union. By transferring personal data to a third country without adequate safeguards, <\/span><b>Uber exposed drivers to a significant risk of violation of their fundamental rights<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Dutch DPA initiated this investigation following complaints filed by more than 170 French drivers, demonstrating widespread concern among those affected. Cooperation between the <\/span><a title=\"data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\"><span style=\"font-weight: 400;\">data protection<\/span><\/a><span style=\"font-weight: 400;\"> authorities of different European countries has been instrumental in coordinating this action and ensuring an effective response to Uber&#8217;s irregular practices.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The fine imposed on Uber is one of the highest ever recorded in the context of the GDPR, reflecting the seriousness of the infringements committed. This financial penalty is intended to deter other companies from committing similar practices and serve as a reminder of the importance of complying with data protection regulations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>main violations committed by Uber<\/b><span style=\"font-weight: 400;\">, according to the Dutch DPA, focus on three key points:\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">First, the company unlawfully transferred personal data of European drivers to servers located in the United States, without ensuring the security and data protection measures required by the GDPR.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Second, Uber failed to provide drivers with transparent and complete information on how their data was used, to whom it was communicated and what rights they had.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Finally, the company failed to implement the necessary security measures to protect drivers&#8217; personal data against possible breaches or unauthorized access, thus exposing those affected to significant risks.<\/span><\/li>\n<\/ol>\n<h2><span style=\"font-weight: 400;\">Other sanctions against Uber<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">It is important to note that this is not the first time Uber has been sanctioned by the Dutch DPA. Previous fines, imposed in 2018 and 2023, evidence a pattern of non-compliance by the company, calling into question its commitment to protecting its users&#8217; data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Uber has received several sanctions from the Dutch Data Protection Authority (DPA) prior to the \u20ac290 million fine imposed in 2024. These previous sanctions demonstrate a <\/span><b>pattern of non-compliance by the company<\/b><span style=\"font-weight: 400;\"> in relation to the data protection of its drivers.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>2018: 600,000\u20ac fine<\/b><span style=\"font-weight: 400;\">. The first sanction imposed by the DPA on Uber occurred in 2018. This fine was due to violations related to data processing transparency and failure to adequately inform drivers about how their personal data was used.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>2023: 10\u20ac million fine<\/b><span style=\"font-weight: 400;\">. In 2023, Uber received a second fine, this time of \u20ac10 million. This penalty was due to similar violations as in 2018, but on a larger scale.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The repetition of the penalties to Uber suggests that the company has not taken the necessary steps to correct the deficiencies identified in the previous inspections. Despite the fines and warnings, Uber has continued to fail to comply with GDPR when it comes to protecting its drivers&#8217; data.<\/span><\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/17299#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The Dutch Data Protection Authority (DPA) has imposed a hefty fine on Uber due to a series of serious breaches of the General Data Protection Regulation (GDPR).<\/p>\n","protected":false},"author":70,"featured_media":17295,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-17299","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/70"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=17299"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17299\/revisions"}],"predecessor-version":[{"id":17300,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17299\/revisions\/17300"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/17295"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=17299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=17299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=17299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}