Italian Garante Fines Deliveroo 2.5M Euros for Unlawful Processing of Personal Data
Time 2 Minute Read

On August 2, 2021, the Italian Data Protection Authority (Garante per la protezione dei dati personali, “Garante”) announced that it had levied a €2,500,000 fine on Deliveroo Italy s.r.l. for the unlawful processing of personal data of approximately 8,000 Deliveroo riders, and various infringements of the EU Genera Data Protection Regulation (the “GDPR”).

Following an investigation into Deliveroo’s practices, the Garante found that Deliveroo had failed to provide transparent information to its riders about the algorithm used to manage riders’ work shifts. In addition, the Garante found that Deliveroo’s app collected a disproportionate amount of riders’ personal data in violation of the principles of lawfulness, transparency, data minimization and storage limitation.

The Garante also ordered Deliveroo to correct the GDPR violations it had found in Deliveroo’s data protection practices, including violations relating to, among others:

  • Accountability, including the preparation of internal documentation on personal data processing, internal records of processing and data protection impact assessments;
  • Transparency regarding data storage limitation, the measures implemented to protect the rights, freedoms and legitimate interests of riders, and measures implemented to verify the accuracy of data used by Deliveroo’s algorithm to manage riders’ work shifts.

Deliveroo was given a period of 60 days to correct the violations, and an additional period of 90 days to correct those related to the algorithm it uses.

Read the Garante’s press release and decision (in Italian).

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page