EU Data Protection Authorities Establish Task Force to Collaborate on Uber Data Breach
Time 1 Minute Read

On November 29, 2017, the EU’s Article 29 Working Party (”Working Party”) announced the establishment of a task force to coordinate the plethora of national investigations throughout the EU into Uber’s 2016 data breach that affected approximately 57 million users worldwide. The task force is being led by the data protection authority (”DPA”) in the Netherlands, where Uber has its EU headquarters, and includes representatives from the DPAs in France, Italy, Germany, Belgium, Spain and the United Kingdom.

The Working Party’s actions serve as a precursor for the one-stop-shop regulatory mechanism to be introduced by the EU General Data Protection Regulation when it comes into force in May 2018. Under the one-stop-shop, the DPA in the jurisdiction of an organization’s main establishment in the EU will lead investigations into alleged violations of law, with involvement from DPAs in EU Member States that also are affected by the violations. Under the present law, however, each national DPA handles enforcement and sanctioning according to the law in their own member state, which will be true in the case of Uber as well.

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 4 Minute Read

On January 20, 2026, the European Commission proposed a comprehensive new cybersecurity package aimed at strengthening the EU’s cybersecurity resilience and enhancing its capacity to manage evolving threats.

Time 5 Minute Read

On November 19, 2025, the European Commission unveiled the much-anticipated digital omnibus legislative package (the “Digital Omnibus”), setting the stage for a new era of digital governance and regulatory simplification across the European Union. According to the Commission, this initiative is designed to enable European businesses to devote more energy to innovation and growth, rather than navigating complex compliance landscapes.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page