+++ NETHERLANDS: FINE OF APPROX. EUR 825 MILLION AGAINST UBER FOR AUTOMATED DECISION-MAKING +++
The Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), has fined Uber Technologies Inc. approximately EUR 825 million. Uber used software to monitor drivers’ conduct and customer ratings. If the system detected suspected fraud or a driver fell below predefined rating thresholds, the driver’s account was automatically suspended temporarily; persistently low ratings resulted in permanent deactivation, in each case without further human review. Those affected consequently lost their income through the platform. The AP found that this infringed the prohibition on solely automated decision-making under Article 22 GDPR. Uber had also failed to provide drivers with sufficient information about the automated processes. Uber has since discontinued the practices and has challenged the fine. The fine represents approximately 1.85% of Uber’s reported worldwide annual turnover for 2025 of around EUR 44.5 billion; the maximum under the GDPR is 4%.
To the AP press release (dated 21 August 2026)
+++ ITALY: EUR 1.7 MILLION FINE FOLLOWING SOCIAL ENGINEERING ATTACKS +++
The Italian data protection authority, the Garante per la Protezione dei Dati Personali (GPDP), has fined Wind Tre S.p.A. approximately EUR 1.7 million. Attackers had telephoned employees at two retail outlets, posing as support technicians, and used social engineering to gain access to company systems. Personal data relating to more than 365,000 customers were exfiltrated; for 41,359 individuals, the data also included payment method information. The GPDP identified shortcomings in the management of access credentials and digital certificates, as well as inadequate security testing. More thorough checks would have identified the relevant vulnerabilities. The authority found infringements of the principles of integrity and confidentiality and of the GDPR security requirements, and ordered additional safeguards.
To the GPDP announcement (dated 16 July 2026, in Italian)
To the GPDP decision (dated 14 May 2026, in Italian)
+++ ITALY: EUR 460,000 FINE FOR EXCESSIVE RETENTION OF EMPLOYEE EMAILS AND LOG DATA +++
The GPDP has also fined Piaggio & C. S.p.A. EUR 460,000. Two former employees had complained that the company accessed messages in their individually assigned business email accounts during their employment and later used emails in disciplinary proceedings. The GPDP’s investigation found that the contents of business email accounts and technical log data had been retained for extended periods. This had enabled detailed monitoring of the employees’ activities. The authority identified infringements of the principles of lawfulness, transparency, purpose limitation and storage limitation, as well as the rules governing employee data processing. The company had also failed to respond to the data subjects’ access requests within the applicable time limit.
To the GPDP decision (dated 18 June 2026, in Italian)