Court Rules
All enforcement actions
SettlementCritical RiskMultistate

State AGs Settle with Uber for $148M Over 2016 Data Breach Cover-Up

Uber Technologies, Inc.September 26, 2018California Attorney General

Penalty Amount

$148,000,000

Summary

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

Remedy

Uber must pay $148 million, implement and maintain robust data security practices, comply with state laws on personal information handling, accurately represent its data security and privacy practices, develop a comprehensive information security program with executive oversight, report data security incidents quarterly for two years, and maintain a Corporate Integrity Program with a hotline, quarterly board reports, privacy principles implementation, and annual code of conduct training.

Monetary PenaltyCompliance ProgramReporting Requirements

Violation Types

Entity Details

Entity

Uber Technologies, Inc.

Also known as: Uber

Industry

Technology

Official Sources

Related Enforcement Actions

NJ

Uber Technologies, Inc.

$148.0M

Uber Technologies, Inc. agreed to pay $148 million to settle a multi-state investigation into a data breach that compromised personal information of riders and drivers. The breach occurred in November 2016 but was not disclosed until November 2017. Uber must adopt new policies to safeguard consumer data.

CA

Nexstar Media Group, Inc. and Tegna Inc.

California Attorney General Rob Bonta, joined by attorneys general from seven other states, filed a lawsuit to block the $6.2 billion merger between Nexstar Media Group and Tegna Inc. The lawsuit alleges the merger violates Section 7 of the Clayton Act by reducing competition in local TV markets, leading to higher prices, less local news, and job losses.

CA

U.S. Department of Education

California Attorney General Rob Bonta filed a lawsuit against the U.S. Department of Education to block the expansion of IPEDS data collection requiring colleges to submit race-linked student data. The lawsuit argues the demand is arbitrary, capricious, and burdensome, and could enable costly partisan investigations. A multistate coalition co-led the challenge.

CA

Live Nation

California Attorney General Rob Bonta and a coalition of state attorneys general announced they will continue their antitrust lawsuit against Live Nation/Ticketmaster after the U.S. Department of Justice settled the case. The states aim to hold Live Nation accountable for anticompetitive conduct that harms consumers, artists, and venues in the live music industry.

CA

Ford Motor Company

$376K

The California Privacy Protection Agency (CalPrivacy) settled with Ford Motor Company requiring the company to pay a $375,703 fine and change its practices. Ford violated the CCPA by requiring consumers to complete an email verification step before they could opt-out of the sale and sharing of their personal information collected through digital properties and connected vehicle services. In addition to the fine, Ford must provide easy methods to submit opt-out requests with minimal steps, audit its tracking technologies, and ensure compliance with opt-out preference signals including Global Privacy Control.

CA

GoFundMe

California Attorney General Rob Bonta, co-leading a bipartisan coalition of 21 attorneys general and charitable regulators, sent a letter to GoFundMe demanding the platform remove all plagiarized donation web pages for over 1.4 million charities, disclose information about donations, and ensure pages do not outrank official charity sites in search results. The action follows reports that GoFundMe used charities' information without consent and engaged in deceptive solicitations, violating state charitable solicitation and consumer protection laws.