Uber B.V. – €4,240,000 Fine (Italy, 2022)

€4,240,000Garante per la protezione dei dati personali24 March 2022Italy
final
ePrivacy
Fine

Uber was fined €4.24 million for mishandling a data breach that affected millions of users. The Italian Data Protection Authority found that Uber did not properly inform users about the breach or obtain their consent for data processing. This case serves as a warning for companies to be transparent and responsible with user data.

What happened

Uber B.V. and Uber Technologies Inc. were fined for failing to notify the authorities and users about a major data breach from 2017.

Who was affected

Around 1.4 million users in Italy had their personal data processed without proper consent due to the breach.

What the authority found

The Italian Data Protection Authority ruled that Uber violated the Italian Privacy Code by not providing adequate privacy notices and failing to secure user consent.

Why this matters

This case shows that companies can face significant penalties for not protecting user data and being transparent about breaches. Businesses should ensure they have clear privacy policies and consent mechanisms in place.

National Law Articles

AI-identified

Art. 4 (1)(f), 13, 23, 28, 37, 38, 161, 162 (2bis), 163, 164bis (2) Codice Privacy

Entities Involved

Uber B.V.
Uber Technologies Inc.
Source verified 2 April 2026
articles corrected
national law identified
entity split needed
scope corrected
Full Legal Summary
Detailed

The Italian DPA launched an investigation into Uber B.V., with registered office in Amsterdam, and Uber Technologies Inc., with registered office in San Francisco, after the US parent company made public a data breach in 2017. The DPA found that the Dutch company Uber BV and the US company Uber Technologies were joint controllers, each responsible for violating the Italian Privacy Code (the Italian implementation of EU Directive 95/46/EC) against data subjects in Italy. During their inspections carried out at Uber Italy srl, the DPA found several violations, including inadequate privacy notice, personal data processed without consent and failure to notify the DPA about the data breach. The security incident, which occurred before the GDPR came into effect, involved the data of around 57 million data subjects worldwide, and had been sanctioned by the Dutch and British DPA on the basis of their respective national regulations. The personal data processed by Uber concerned personal and contact data (name, surname, telephone number, and e-mail), access credentials to the app, location data (those that appeared at the time of registration), and relations with other data subjects (sharing trips, introducing friends, profiling information). The controllers had also, without having obtained valid consent, processed the data of approximately 1,379,000 data subjects by profiling them on the basis of the so-called 'fraud risk', assigning them a qualitative rating (e.g., 'low') and a numerical parameter (from 1 to 100). Finally, the controllers had not complied with the obligation to notify the DPA of the processing of personal data for geolocation purposes, as required by the legislation in force before the GDPR came into effect. The DPA found violations related in particular to the inadequate privacy notice provided to data subjects (insofar as it lacks an indication of joint ownership of the processing) and 'formulated in a generic and approximate manner' with 'unclear a

Violations (2)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Uber B.V. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

24 March 2022

Authority

Garante per la protezione dei dati personali

Fine Amount

€4,240,000

GDPRhub ID

gdprhub-4946

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Uber B.V. - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: