LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
security

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWeek.

zeroday.news ·

Uber has reportedly been fined approximately 825 million euros (nearly $1 billion USD) by the Dutch Data Protection Authority (DPA). The significant penalty is said to be a result of Uber's alleged violations of the European Union's General Data Protection Regulation (GDPR), specifically concerning the automated suspension of driver accounts.

The core of the reported issue centers on Uber's automated processes for managing driver accounts, particularly those leading to suspensions. Under GDPR, automated decision-making that produces legal effects concerning an individual, or similarly significant effects, is subject to strict rules. This includes the right for individuals not to be subject to a decision based solely on automated processing, including profiling, if it produces such effects, unless specific conditions are met. These conditions often involve explicit consent, necessity for a contract, or authorization by law, and typically require safeguards such as the right to human intervention, to express one's point of view, and to contest the decision.

The reported fine suggests that the Dutch DPA found Uber's automated account suspension mechanisms did not adequately comply with these GDPR provisions. This could imply a lack of transparency regarding the logic involved in the automated decisions, insufficient opportunities for drivers to challenge or appeal suspensions with human oversight, or a failure to provide clear information about the processing of their personal data that led to these actions. Automated systems, while efficient, must be designed to uphold individual rights, especially when they impact livelihoods.

For companies operating within the EU or processing the data of EU citizens, adherence to GDPR Article 22, which addresses automated individual decision-making, is critical. This article aims to protect individuals from potentially unfair or discriminatory outcomes that can arise from algorithms operating without human review. Organizations are typically advised to conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities, which would certainly include automated decisions affecting employment or contractual relationships.

Mitigation strategies for this class of issue generally involve implementing robust human review processes for automated decisions that have significant impacts on individuals. This includes establishing clear procedures for individuals to request human intervention, understand the basis of the decision, and challenge it. Transparency in data processing, clear privacy notices, and ensuring data accuracy are also fundamental. Furthermore, organizations must demonstrate accountability by maintaining records of processing activities and demonstrating compliance with GDPR principles.

This substantial fine underscores the serious implications of non-compliance with GDPR, particularly concerning automated decision-making that affects individuals' rights and freedoms. It serves as a reminder to global technology companies that their automated systems, while designed for efficiency and scale, must be built and operated with strict adherence to data protection regulations. The incident highlights the ongoing regulatory scrutiny of algorithmic fairness and transparency in an increasingly automated world, emphasizing the need for robust governance around artificial intelligence and machine learning systems that interact with personal data.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]

breach

South Korean startup platform breach exposes key management failures

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]

security

Hired for One Job, Judged on Another: The CISO’s Real Problem

The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. The post Hired for One Job, Judged on Another: The CISO’s Real Problem appeared first on SecurityWeek.

security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

patch

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]

security

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.