惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
Y
Y Combinator Blog
博客园 - Franky
D
Docker
B
Blog RSS Feed
M
MIT News - Artificial intelligence
雷峰网
雷峰网
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
GbyAI
GbyAI
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MyScale Blog
MyScale Blog
B
Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
Vercel News
Vercel News
The Cloudflare Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Dutch DPA Fines Uber Over Automated Decisions Affecting D...
2026-09-10 · via Privacy & Cybersecurity Law Blog

On August 21, 2026, the Dutch Data Protection Authority (the “Dutch DPA”) announced that it had fined Uber €824,990,000 for infringing the EU General Data Protection Regulation’s (“GDPR”) prohibition on certain solely automated decisions with respect to drivers. According to the Dutch DPA, Uber used software between 2018 and 2022 to monitor drivers’ behavior and customer ratings, and automatically deactivate driver accounts where fraud was suspected or ratings were considered too low. The Dutch DPA concluded that these decisions were made without meaningful human involvement, even though they could have significant consequences for drivers, including loss of income.

The Dutch DPA concluded that Uber violated the GDPR’s restrictions on solely automated decision-making producing legal effects or similarly significant effects. In the Dutch DPA’s view, temporarily or permanently deactivating a driver’s account based exclusively on automated processing fell within that prohibition. The Dutch DPA also found that Uber did not provide drivers with sufficient information about the use of automated decision-making in these circumstances. According to the Dutch DPA, Uber has since changed its practices.

The matter arose from complaints submitted by 171 drivers in France and was handled by the Dutch DPA as Uber’s lead supervisory authority under the GDPR’s one-stop-shop mechanism. The Dutch DPA said it worked closely with the French data protection authority, and aligned its regulatory action with other European data protection authorities. Uber has appealed the decision and stated that it strongly disagrees with both the findings and the amount of the fine.

Read the Dutch DPA’s announcement in English.