The Dutch Data Protection Authority (Dutch DPA) has fined Uber €290 million for violating the General Data Protection Regulation’s (GDPR) rules on international transfers of personal data. The fining decision was published on 26 August 2024 (in Dutch). This is by far the biggest fine the Dutch DPA has ever imposed, and one of the biggest data protection fines in Europe.
Background
The Dutch DPA holds that Uber transferred personal data of European taxi drivers to the United States without a transfer mechanism between 2021 and 2023. The Dutch DPA’s investigation was triggered by a complaint submitted to the French CNIL. The Dutch DPA is the lead supervisory authority because Uber's European headquarters are in the Netherlands.
The GDPR requires that a so-called transfer mechanism is used when transferring personal data to a country outside the EU. There are various transfer mechanisms, such as an adequacy decision from the European Commission, standard contractual clauses (SCCs), binding corporate rules (BCRs), and derogations under Article 49 GDPR.
Adequacy decisions are often used for data transfers to the US, but two US adequacy decisions have previously been invalidated by the European Court of Justice (in particular on account of US intelligence services having access to European data; see the Schrems judgments from 2015 and 2020). Uber is currently certified under the Data Privacy Framework (DPF) for which a third US adequacy decision was enacted last year. However, between 2020 and 2023 no US adequacy decision was in place. During this period, SCCs were the most commonly used mechanism for data transfers to the US. According to the European Commission, however, the existing SCCs cannot be used for data transfers to a party outside the EU that is subject to the GDPR’s scope of application, because the SCCs would then duplicate and deviate from obligations under the GDPR (see question 24).
The relevant Uber entities in this matter – Uber B.V. (in the Netherlands) and Uber Technologies Inc. (in the US) – qualify as joint controllers and are both within the scope of application of the GDPR. In 2021, Uber removed the SCCs from the Data Sharing Agreement between these two entities. With regard to the period between 2021 and 2023, Uber takes the position that data transfers were necessary to perform contracts with the drivers, but the Dutch DPA holds that this derogation under Article 49 GDPR could not be applied because the conditions of the data transfers being “occasional” and “necessary” have not been met.
Key Takeaways:
- International data transfers remain a legal minefield. It is only a matter of time until the European Court of Justice will also rule on the third US adequacy decision. Last year, the Irish DPC imposed the biggest ever GDPR fine (€1.2 billion) on Meta for data transfers to the US based on SCCs. Now, the Dutch DPA seems to blame Uber in particular for the absence of SCCs. In brief: the GDPR is already 6 years old, but the regime for international data transfers remains in constant motion. While the use of an adequacy decision or SCCs may be a considered a robust approach at one point, it may result in a violation of the GDPR at a later time due to external developments. In projects involving data transfers, it is important not only to apply the appropriate transfer mechanism, but also to ensure that the approach is future-proof. This requires among others a careful review of contracts, both with third parties like customers / suppliers / partners and intra-group contracts between various entities within a group of companies.
- What to do in anticipation of the additional set of SCCs for data transfers to parties subject to the GDPR’s scope of application? While emphasizing that the existing SCCs cannot be used for data transfers to parties outside the EU that are subject to the GDPR, the European Commission indicated to be in the process of developing an additional set of SCCs for this particular scenario (see question 24). However, to date this additional set of SCCs has not yet been published, and until then, organisations should prevent being blamed for taking the same approach as Uber. The DPF may offer a solution for data transfers to the US, provided that the recipient in the US is certified under the DPF. However, it is not unthinkable that the third adequacy decision for the US will again be invalidated. Moreover, at the global level not that many countries are covered by adequacy decisions. As an alternative to an adequacy decision (at least in anticipation of the additional set of SCCs), and in particular in light of this fine by the Dutch DPA, the existing SCCs seem a safer approach than the derogations under Article 49 GDPR. In fact, by applying the existing SCCs Uber might even have escaped – even though against the instructions of the European Commission – the Dutch DPA’s fine.
- No “data transfer” if data are collected directly from the data subject. There is no definition of the term “data transfer” in the GDPR. The EDPB interpreted this term by taking the position that there is no data transfer when a party outside the EU collects data directly from a person in the EU. Uber indeed argues that drivers make their data available directly to Uber Technologies Inc. The Dutch DPA denies this defence, holding (to summarize) that Uber B.V. is responsible and in control of the data transfer to the US. In other words: Uber B.V. is designated as the data exporter. The Dutch DPA sheds little light on the question under which circumstances direct collection from the EU could have taken place. Uber has announced that it will raise objections against the fine, and further interpretation of this doctrine would indeed be useful.
- Derogations under Article 49 GDPR can only be applied in limited cases. The Dutch DPA is aligned with the EDPB in confirming that the derogations under Article 49 GDPR can only be applied in limited cases. Although the derogations potentially offer a welcome alternative (or even a last resort), for now they seem useless in practice unless the data transfers are small-scale. This is mainly due to the criterion that data transfers have to be “occasional” or “non-repetitive”. It is unclear where the line is drawn, and concrete interpretation would again be helpful.
- BCRs are the most robust solution for intra-group data transfers. Amidst these stormy developments, organisations using BCRs are in much smoother waters. This makes BCRs an interesting solution for intra-group data transfers within international organisations. Given the recent guidance from the EDPB on BCRs, now is a good time to request approval for new BCRs. We assist various clients in the approval and update of BCRs.
Our team routinely advises on international data transfers. We monitor developments and have wide experience with the various transfer mechanisms. For more information, please contact Sam Meijer or a colleague from the team.