Court Rules
All enforcement actions
SettlementCritical RiskMultistate

State AGs Settle with Uber for $148M Over 2016 Data Breach Cover-Up

Uber Technologies, Inc.September 26, 2018California Attorney General

Penalty Amount

$148,000,000

Summary

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

Remedy

Uber must pay $148 million, implement and maintain robust data security practices, comply with state laws on personal information handling, accurately represent its data security and privacy practices, develop a comprehensive information security program with executive oversight, report data security incidents quarterly for two years, and maintain a Corporate Integrity Program with a hotline, quarterly board reports, privacy principles implementation, and annual code of conduct training.

Monetary PenaltyCompliance ProgramReporting Requirements

Contract Impact

In-house legal teams should review all vendor, customer, and data processing agreements for clauses related to data security standards, breach notification timelines and procedures, and incident response obligations. Specific attention should be paid to requirements for prompt reporting of security incidents to the company and affected individuals, encryption and access controls, and regular security audits. Given the cover-up allegations, contracts should also include clear prohibitions against delaying or withholding breach notifications and mandates for cooperation with regulators. Changes may be needed to strengthen vendor management clauses, require adherence to specific frameworks like NIST or ISO 27001, and impose liability for failures to report.

Contract Search Terms

data breach notification clausesecurity incident response planpenetration testing requirementsencryption standardsbug bounty programprivacy by designdata retention schedulethird-party vendor security addendum

Violation Types

Entity Details

Entity

Uber Technologies, Inc.

Also known as: Uber

Industry

Technology

Official Sources

Related Enforcement Actions

NJ

Uber Technologies, Inc.

$148.0M

Uber Technologies, Inc. agreed to pay $148 million to settle a multi-state investigation into a data breach that compromised personal information of riders and drivers. The breach occurred in November 2016 but was not disclosed until November 2017. Uber must adopt new policies to safeguard consumer data.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.

CA

California Privacy Protection Agency

The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.