Uber fined after ‘serious breach’ allowing hackers to download worldwide 54 million customer data.

 In IT & Internet

Uber fined after ‘serious breach’ allowing hackers to download worldwide 54 million customer data.

Full names, email addresses and phone numbers were obtained during the October and November 2016 cyberattacks but Uber did not inform customers or drivers for more than a year. Instead, it paid the attackers $100,000 (£78,000/€88,00) to destroy the information that had been downloaded.

After an investigation by the supervisory authorities of Belgium, Germany, France, Italy, Spain, UK and the Netherlands, of which the Dutch Supervisory Authority was in charge, Uber has been fined £385,000 in the UK and €600,000 in the Netherlands because of “a series of avoidable data security flaws” allowing hackers to download personal information of 2.7 million customers in the UK and 174,000 in the Netherlands, worldwide the total amounted to 54 million customers.

The Information Commissioner’s Office (ICO) and the Dutch Supervisory Authority found Uber guilty of a “serious breach” of UK data protection law and found that Uber had shown a “complete disregard” for the customers and drivers whose information was stolen.

The security breach potentially exposed users of Uber’s app to an increased risk of fraud, both the ICO and Dutch Supervisory Authority said in their rulings of 26 November 2018.

Uber’s failure to report the leak was not only a serious failure of data security on Uber’s part, but a complete disregard for the customers and drivers whose personal information was stolen, according to the supervisory authorities in both countries.
At the time, no steps were taken to inform anyone affected by the breach, or to offer help and support.
That left the customers and drivers vulnerable. Paying the attackers and then keeping quiet about it afterwards was not, in the ICO’s view, an appropriate response to a cyberattack.

Under the laws the Netherlands and the laws of some otherEuropean countries as these were in place at the time, Uber would also have had the duty to report these data breaches and face the consequences. However, now that the General Data Protection Regulation (GDPR) came into force on 25 May this year, the breach was subject to a significantly higher penalty.

Companies found guilty of a breach under the GDPR are liable to fines of up to €20 million or 4 per cent of their global turnover, which could amount to billions of euros for the largest technology companies. The actual fines imposed on Uber are peanuts in this respect, especially in the light of Uber having paid $ 148 million dollars in de US to settle claims for damages with US customers.

For lawyers it was interesting to see that Uber US and Uber Netherlands were considered to be joint controllers which made them both separately liable for claims of the data subjects, in this case customers of Uber.

Recent Posts
  • 17 March 2020

    Hanneke Slager
    Following the recent developments in connection with the Coronavirus (COVID-19), we hereby inform you of the measures that we have taken to ensure the continuity and quality of the services we provide to you.
    Read More
  • 16 March 2020

    Fine for Dutch tennis association for unlawfully selling personal data

    Bob Cordemeyer
    The Dutch DPA imposed a fine of 525,000 euros for the unlawful sale of personal data by the Dutch national tennis association the KNLTB. In 2018, the KNLTB unlawfully provided personal data of a few hundred thousands of its members to two sponsors against payment.
    Read More
  • 16 December 2019

    On 1 January 2020 the Balanced Labour Market Act (Wet Arbeidsmarkt in Balans (WAB)) takes effect.

    Marion Hagenaars
    This Act is meant to improve the balance between fixed and flexible employment agreements. Once again, employment law is changed in important parts. Apart from that, the Dutch Supreme Court has ruled on the issue of ‘dormant employment’.
    Read More

Leave a Comment