Ride-hailing tech company Uber has been hit by a massive €290 million (£245m) fine from the Dutch Data Protection Authority (DPA).
The watchdog claims the tech firm sent personal data of European taxi drivers to the United States and failed to appropriately safeguard that transferred data—a violation of the EU’s GDPR.
According to the regulator, Uber collected sensitive information of drivers from Europe such as payment details, identity documents, taxi licenses, and location data, and held the data on its US servers.
Uber transferred the data to its headquarters in the US for over two years without using appropriate transfer tools for protecting privacy, meaning the drivers’ data was “insufficiently protected,” the regulator claimed.
The ride-hailing firm ended the violation last year, the watchdog noted.
In a statement sent to the BBC, an Uber spokesperson said that the decision is “completely unjustified.”
“Uber’s cross-border data transfer process was compliant with GDPR during a 3-year period of immense uncertainty between the EU and US,” the spokesperson said.
“This flawed decision and extraordinary fine are completely unjustified,” they added.
During a period between 2020 and 2023, the EU and the US lacked a data privacy framework agreement, meaning that, in many cases, organisations would have to take additional safeguards if they were to transfer EU data to the US.
Recommended reading
- Uber Data Breach | What You Need to Know
- Why is a Former Uber Security Officer Being Charged for Fraud?
- UK Supreme Court Rules Uber Drivers are Workers
Aleid Wolfsen, who’s Dutch DPA chairman, remarked on the regulator’s decision: “In Europe, the GDPR protects the fundamental rights of people, by requiring businesses and governments to handle personal data with due care.”
“But sadly, this is not self-evident outside Europe. Think of governments that can tap data on a large scale. That is why businesses are usually obliged to take additional measures if they store personal data of Europeans outside the European Union.
“Uber did not meet the requirements of the GDPR to ensure the level of protection to the data with regard to transfers to the US. That is very serious.”
The investigation into Uber started after over 170 French drivers complained to French human rights interest group the Ligue des droits de l’Homme.
The complaint was then forwarded to the Dutch DPA as Uber’s European headquarters is in the Netherlands.





