To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

Dutch Regulator Fines Uber €825M For Breaking EU Data Privacy Rules

August 25, 2026

Read also: TikTok to pay $400 million over COPPA violation; Vodafone FS fined over unjustified credit loans; and more.

Views: 616 Read Time: 3 min.

Dutch Regulator Fines Uber €825M For Breaking EU Data Privacy Rules

Dutch regulator fines Uber €825M for breaking EU data privacy rules

Dutch data protection authorities have fined Uber €825 million for breaking European data privacy rules.

The Dutch Data Protection Authority said Uber used automated software to suspend driver accounts, sometimes permanently, without a human checking whether the decisions were correct. The authority said the practice violated the EU’s General Data Protection Regulation (GDPR), which limits fully automated decisions.

The violations took place between 2018 and 2022. The authority also said Uber did not properly tell drivers that automated systems were being used to make decisions about their accounts.

This is the fourth time Dutch authorities have fined Uber. In 2024, the company received a €290 million ($324 million) fine over the transfer of European drivers’ personal data to the US without adequate protection.

US DOJ announces $400M TikTok settlement over child privacy

The US Department of Justice has announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over alleged violations of the Children’s Online Privacy Protection Act (COPPA).

Under the agreement, TikTok will pay $300 million immediately and another $100 million after a court vacates a previous consent decree involving TikTok’s predecessor Musical.ly. The DOJ said the settlement is one of the largest recoveries ever made in a COPPA case.

In August 2024, the DOJ and the US Federal Trade Commission filed a complain, accusing TikTok of allowing children under 13 to create accounts and collecting their personal information without proper consent. Authorities also alleged that TikTok failed to fully comply with parents’ requests to delete their children’s accounts and data.

TikTok disputed the allegations at the time, saying some claims involved past practices that were inaccurate or had already been addressed.

The settlement is not TikTok’s first major penalty over children’s privacy. In September 2023, the company was fined €345 million by Ireland’s Data Protection Commission for violating the European Union’s General Data Protection Regulation in connection with its handling of children’s personal data.

The DOJ said TikTok has since taken steps to improve protections for younger users, including stronger age controls and better tools for parents.

Vodafone FS fined after a software error led to unjustified credit loans

The Rotterdam District Court has reduced a fine against Vodafone Financial Services BV (Vodafone FS) from €375,000 to €185,000. The Netherlands Authority for the Financial Markets (AFM) initially imposed the fine on July 15, 2024, after the company granted unjustified credit to customers due to an error in its telephone ordering system. Because of a software update, the company’s required income and expenditure test was skipped for several weeks.

The test is required for consumer credit above €250 and helps lenders check whether customers can afford a loan. As a result of the error, 158 customers received credit that should not have been granted.

Vodafone FS discovered the software issue and reported it to the AFM. The company took steps to prevent such incidents from happening in the future and compensated all affected customers. The customers were allowed to keep their phones and their credits were waived.

Vodafone FS had previously received warnings from the AFM in 2018 and March 2022 for similar incidents. The AFM initially considered a basic fine of €2.5 million but reduced it to €375,000 because the impact on customers was limited and Vodafone FS cooperated fully.

On June 18, 2026, the Rotterdam District Court reduced the fine again to €185,000. The court considered the seriousness and duration of the violation, Vodafone FS’s level of responsibility, and the fact that the legal proceedings exceeded the reasonable time limit by five months.

Doxo to pay $2.1M over misleading ads and hidden fees

US-based online bill payment company Doxo will pay $2.1 million to settle allegations from the US Federal Trade Commission (FTC) that it used misleading ads to make consumers believe it was the official payment service for their bills.

The FTC said Doxo used search ads and other advertising to appear connected to utilities, car lenders and other billers. The platform’s payment pages sometimes showed company names and logos even though Doxo did not have a relationship with most of the businesses.

The FTC also accused Doxo of adding poorly disclosed delivery fees and enrolling consumers in a recurring subscription without clearly explaining its cost and terms. A federal court found that Doxo violated the Restore Online Shoppers’ Confidence Act by failing to clearly disclose subscription terms and obtain proper consent for recurring charges.

Under the proposed settlement, the $2.1 million payment will be used for consumer refunds. Doxo and its co-founders will also be barred from falsely claiming relationships with billers, hiding fees and subscription terms, misleading consumers about charges, or billing customers without informed consent.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

Online tax preparation firm to pay $275K over customer data sharing

Texas-based online tax preparation company TaxAct has agreed to pay the US state of Connecticut $275,000 to settle allegations that it improperly shared sensitive customer tax information with Meta and Google.

According to the Connecticut Attorney General, TaxAct used tracking tools from Meta and Google between January 2018 and December 2022. The tools collected information, including customers’ income, tax refunds, taxes owed, deductions, and number of dependents.

The company also shared information about charitable donations, investment income, and mortgage or student loan interest. Authorities said TaxAct did not properly tell customers that their information was being shared.

As part of the settlement, TaxAct must create stricter rules for third-party tracking tools. The company is also required to form a review committee, improve its data tracking records and regularly check its website for unauthorized tracking technology.

TaxAct must also undergo two independent audits to make sure its tracking practices follow the new rules.

What’s next:

Talk to an Expert