Court Rules
All enforcement actions
SettlementCritical RiskMultistate

State AGs Settle with Uber for $148M Over 2016 Data Breach Cover-Up

Uber Technologies, Inc.September 26, 2018California Attorney General

Penalty Amount

$148,000,000

Summary

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

Remedy

Uber must pay $148 million, implement and maintain robust data security practices, comply with state laws on personal information handling, accurately represent its data security and privacy practices, develop a comprehensive information security program with executive oversight, report data security incidents quarterly for two years, and maintain a Corporate Integrity Program with a hotline, quarterly board reports, privacy principles implementation, and annual code of conduct training.

Monetary PenaltyCompliance ProgramReporting Requirements

Contract Impact

In-house legal teams should review all vendor, customer, and data processing agreements for clauses related to data security standards, breach notification timelines and procedures, and incident response obligations. Specific attention should be paid to requirements for prompt reporting of security incidents to the company and affected individuals, encryption and access controls, and regular security audits. Given the cover-up allegations, contracts should also include clear prohibitions against delaying or withholding breach notifications and mandates for cooperation with regulators. Changes may be needed to strengthen vendor management clauses, require adherence to specific frameworks like NIST or ISO 27001, and impose liability for failures to report.

Contract Search Terms

data breach notification clausesecurity incident response planpenetration testing requirementsencryption standardsbug bounty programprivacy by designdata retention schedulethird-party vendor security addendum

Violation Types

Entity Details

Entity

Uber Technologies, Inc.

Also known as: Uber

Industry

Technology

Official Sources

Related Enforcement Actions

NJ

Uber Technologies, Inc.

$148.0M

Uber Technologies, Inc. agreed to pay $148 million to settle a multi-state investigation into a data breach that compromised personal information of riders and drivers. The breach occurred in November 2016 but was not disclosed until November 2017. Uber must adopt new policies to safeguard consumer data.

CA

California State Legislature

The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.