In this article

Sign up for our newsletter

Share this article

It’s a tough time to be a Big Tech company. This week, Uber, Meta, and TikTok all suffered astounding penalties for data privacy mismanagement. I can’t focus on all of them for this newsletter intro, so let’s pick one: Uber.

The rideshare app just picked up a $966 million fine from the Dutch Data Protection Authority, the second largest GDPR penalty ever handed down, trailing only Meta's ~$1.4 billion fine from 2023.

Uber’s system flagged drivers for suspected fraud or docked them for low customer ratings and then suspended or permanently deactivated their accounts on that basis alone. An algorithm effectively cut off drivers’ income, often without a person ever reviewing the call.

It's not just Europe, either. California's privacy agency opened its first-ever sectoral audit last month, aimed squarely at gig platforms (like Uber) and the algorithms that decide workers' dispatches, ratings, and account status. As CalPrivacy's chief privacy auditor put it, “you can't contest a decision made by an algorithm without the underlying data,” so the audit really comes down to whether workers can get that data at all.

While the GDPR fine and California audit seem to put Uber and Big Tech companies in the crosshairs, the underlying issue exposes any company using automated decision-making technology. For any business using software to screen applicants, flag risky customers, make eligibility calls for benefits or insurance, or otherwise make significant decisions about people–remember to keep a human in the loop.

Best,
Arlo

Resource Listing - State of US Privacy Enforcement

Highlights From Osano

New From Osano

Blog: 7 Things Privacy Regulators Are Looking for on Your Website

Most companies that get fined weren't trying to break the law. They just never checked their own site the way a regulator would, from opt-outs that don't actually stop trackers to ad-tech contracts that don't hold up. Here's what regulators check first.

Read more

Blog: Multi-Jurisdiction Privacy Compliance: A Practical Guide for 2026

If you’re subject to one data privacy law in the US, then it’s almost a guarantee that you’re subject to others. But every law has different rules. How can you scale compliance when you’re subject to multiple jurisdictions? Read our blog to learn key best practices.

Read more

Release Notes: August

What’s new in Osano this month? Check out our release notes to find out the latest.

Read more



Top Privacy Stories of the Week

Uber Fined $966M for Letting an Automated System Deactivate Driver Accounts

The Dutch Data Protection Authority hit Uber with an $966 million fine, the second largest GDPR penalty on record, after finding the company deactivated drivers' accounts through automated systems with little to no human review.

Read more

TikTok Pays $400M to Settle DOJ's Kids' Privacy Suit

TikTok and ByteDance will pay $400 million to settle a Justice Department lawsuit alleging the platform let kids evade its own "Kids Mode,” collected their data anyway, and made it difficult for parents to request deletion. It's one of the largest recoveries ever secured under COPPA, and the company has spent the two years since the suit was filed rebuilding its age verification and parental control systems.

Read more

Meta Settles for $17 Billion

Meta settled its Oakland trial for up to $17 billion this week, with a bipartisan coalition of 29 states signing onto a deal that requires default two-hour daily time limits for teens, an overnight app block, and an independent auditor with real access to Meta's systems. Meta didn't admit wrongdoing, but the underlying case accused the company of engineering Instagram and Facebook to be addictive and collecting data from kids under 13 without consent.

Read more

Privacy Groups Ask Maryland to Investigate Seven Data Brokers

Privacy and civil rights groups filed a complaint this week asking Maryland's attorney general to investigate seven data brokers, including LexisNexis, Motorola, and Flock Safety, for allegedly selling residents' license plate and cellphone location data to police and federal immigration agencies.

Read more

Comcast Settles 2023 Breach for $117.5M

A federal judge approved a $117.5 million settlement over Comcast's 2023 data breach, one of the largest data breach settlements on record, covering 31.7 million people. The case took two years to resolve, partly because it tested whether a decades-old cable law even applies to data breaches, and partly because Comcast reportedly waited two months after patching a known vulnerability to notify customers.

Read more

Like What You See in the Privacy Insider newsletter?

There's more to explore:

📱 The Osano Subreddit

Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!

đź“– The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands

The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.

If you’re interested in working at Osano, check out our Careers page! 

Get a demo of Osano today
Share this article