This website uses cookies

Read our Privacy policy and Terms of use for more information.

Monday, August 24, 2026 — Cybersecurity · Data Security · Cloud Security

Today's Top Story

Dutch DPA Hits Uber With €825M Fine for Automated Driver Deactivations

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) issued an €825 million GDPR fine against Uber on August 21 — the second-largest GDPR penalty ever — for using automated systems to suspend and permanently deactivate driver accounts without meaningful human oversight.

The investigation, triggered by complaints from 171 French Uber drivers filed through the Ligue des droits de l'Homme, found that between 2018 and 2022 Uber's software monitored driver behavior and ratings, making account-termination decisions with no human review. The case was handled by the Dutch DPA under GDPR's one-stop-shop mechanism, since Uber's European headquarters are in the Netherlands.

The fine follows the annulment of Amazon's €746 million penalty by a Luxembourg court in March 2026, making this the largest active GDPR enforcement action behind Meta's €1.2 billion record. Uber has announced it will appeal, calling the fine "disproportionate."

Why it matters: This is a landmark ruling on GDPR Article 22 (automated individual decision-making). Any organization using algorithmic systems to make consequential decisions about individuals — access, employment, benefits — should take note.

Also Today

DOJ Secures $400M TikTok COPPA Settlement

The Department of Justice announced a $400 million settlement with TikTok and ByteDance on August 21, resolving litigation over Children's Online Privacy Protection Act violations. TikTok will pay $300 million immediately and $100 million upon vacating the prior Musical.ly consent decree. This is one of the largest COPPA recoveries ever obtained.

Action: Review your organization's age-verification and parental consent mechanisms — enforcement is intensifying across platforms.

NIST IoT Security Guidelines — Comment Period Closes Today

NIST's initial public draft of SP 800-213r1, updating IoT product cybersecurity guidelines for federal procurement, has its comment period ending today, August 24. The revision expands scope from "devices" to "IoT products" and integrates the finalized IR 8259r1 lifecycle framework.

Action: If your organization sells IoT products to federal agencies, submit comments today or begin aligning procurement requirements with the new framework.

Deadline Alert

TODAY — August 24, 2026: NIST SP 800-213r1 (IoT Product Cybersecurity Guidelines) public comment period closes. Submit via NIST CSRC.

One Thing to Do Today

Audit your automated decision-making systems. The Uber ruling makes clear that GDPR Article 22 has real teeth — €825 million worth. If your organization uses algorithms to make decisions that significantly affect individuals (hiring, access, account status), ensure meaningful human review is in the loop and that affected individuals are informed about the logic involved.

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to CyberEyeQ to read the rest.

Become a paying subscriber of CyberEyeQ to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you: