Uber Fined €290 million by Dutch Data Protection Authorities
31st August 2024
Worldwide ridesharing and courier company Uber is being fined €290 million for storing the personal information of their drivers on US servers during 2020 – 2023, when there was no EU-US data transfer agreement.
Case Details
The Dutch Data Protection Agency (DDPA) is fining transportation company Uber for storing sensitive personal information about their drivers on US servers, including location data, taxi licences, medical information, payment information and more. This violates the EU GDPR, as no EU-US data transfer framework was in place from 2020 to 2023.
This fine is the result of a complaint from the French Human Rights League, and the fine was imposed by the Dutch regulators as Uber’s European headquarters is based in the Netherlands. Source: https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us
This isn’t the first time Uber has run afoul of European data protection laws – in January of this year, they were fined €10 million by the DDPA for failing to disclose data retention periods to its drivers. As well as not specifying in their terms and conditions how long Uber retained personal information about its drivers, Subject Access Requests were unnecessarily difficult to make within the Uber app, and personal data wasn’t stored in a way that made it easy to access.
Uber spokesperson Caspar Nixon has called the decision by the DDPA “flawed’ and Uber intends to appeal the fine.
How Did Uber Violate the GDPR?
Uber collects and stores personal information about its drivers, including sensitive data such as medical information. They stored this data from European drivers on their US servers between 2020 and 2023 without relying on an adequacy decision or using protective transfer tools. Chapter 5 of the EU GDPR specifies that data transfers outside of the European Economic Area (EEA) must be protected by an adequacy decision between the two countries, or by using appropriate safeguards such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs) or as in Article 46, have in place approved certification mechanisms. Historically companies could use the Safe Harbour and Privacy Shield certification schemes, but the Schrems judgements invalidated these frameworks and have been replaced by the Data Privacy Framework (see GHC blog on DPF). Unfortunately, Uber could not rely on any of these certification mechanisms.
Why Was There No Adequacy Decision from 2020 – 2023 Between the EU and USA?
In the Schrems II case of 2020, the European Court of Justice declared the EU-US Privacy Shield to be invalid. The previous Schrems I case did the same thing to the Safe Harbour framework, which was deemed to be invalid for a similar reason, i.e. US National Security does not protect EU citizens’ data when it is being stored on US servers. The EU-US Data Privacy Framework (DPF) was put in place in 2023 so organisations can now transfer data between the EEA and the USA without the need for SCCs or other data protection transfer tools. But for those three years, no adequacy decision was in place. This doesn’t mean that no data transfers could take place, but they had to rely on transfer tools rather than an all-encompassing adequacy decision.
The EU-US DPF is currently under challenge in the CJEU by Max Schrems, but the UK-US extension of the DPF is still (for now) valid in the UK.
What are Protective Data Transfer Tools?
Data transfer tools such as SCC, BCRs, and ad hoc contractual clauses allow for organisations within the EEA to transfer personal data to countries outside the EEA without an adequacy decision. Uber did not have any of these tools in place, making their data transfers to US servers illegal according to EU law.
What are SCCs?
Standard contractual clauses are pre-approved sets of terms and conditions that organisations must incorporate into their data transfer agreements to ensure that people’s personal data is adequately safeguarded if it is transferred to an insecure third country. On a technical note, the EU uses SCCs, in the UK our model contractual clauses are referred to as IDTAs (International Data Transfer Agreements). They are very similar but there are slight differences such as which courts have jurisdiction. These SCCs and IDTAs are designed to offer data subjects the same protections that people enjoy under the GDPR when their data is overseas.
What are BCRs?
Binding Corporate Rules are codes of practice adopted by global companies or organisations that define the protections for data transferred to different countries within the same company. An international corporation like Uber could have relied on BCRs as a mechanism to protect drivers’ data, as the data was still stored by Uber, just in a different country.
Lessons Learned from Uber’s GDPR Breach and the Future of Data Transfers
Utilising safeguards like those mentioned above offers protection to companies from fines and sanctions from data protection authorities but for some reason, Uber chose not to use them. A spokesman for the CCIA, a tech industry association that Uber is a member of, stated that the DDPA “ignores reality” with their choice to fine Uber, and goes on to say:
“The busiest internet route in the world could not simply be put on hold for three entire years while governments worked to establish a new legal framework for these data flows.” Source – https://www.politico.eu/article/uber-fined-e290-million-for-sending-drivers-data-outside-europe/
While companies have struggled with uncertainty and extra work during the period without an adequacy decision, the data transfer tools defined in the EU GDPR could have been used to avoid these issues. When in doubt about international data transfers, seek the latest advice from the ICO, your data protection officer, or contact us here at Griffin House for advice tailored to your organisation.
Uber does plan to appeal the fine from the DDPA and time will tell whether they will be successful – we will keep you updated on this case.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.