Dutch Data Protection Authority Imposes €100 Million Fine on Taxi App

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: June 2026
  • Category: Enforcement, Data Security

The Dutch data protection authority, Autoriteit Persoonsgegevens, has imposed a fine of €100 million on the taxi app Yango. The reason was the unauthorized transfer of personal data belonging to European users to Russia. Although the company used Standard Contractual Clauses (SCCs), the authority deemed them ineffective because the actual roles of the involved companies were not accurately reflected, and technical safeguards—such as the storage of encryption keys in Russia—did not provide sufficient protection.

Implications for practice:

The decision makes it clear that standard contractual clauses alone do not guarantee legally compliant transfers to third countries. Companies should ensure that SCCs accurately reflect the actual roles of the parties involved and that supplementary technical safeguards are also designed to be practically effective. Particularly in the case of data transfers to countries with extensive government access rights, the design of such measures is likely to come under increased scrutiny by supervisory authorities in the future.


Should you have any questions or require further information, please do not hesitate to contact us any time.

transportation network, modern smartphone with app for online taxi ordering service on screen, car with taxi sign at roof on street at night
© Cybrain / stock.adobe.com | #100517191

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed