Dutch Data Protection Authority Imposes €100 Million Fine on Taxi App
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: June 2026
- Category: Enforcement, Data Security
The Dutch data protection authority, Autoriteit Persoonsgegevens, has imposed a fine of €100 million on the taxi app Yango. The reason was the unauthorized transfer of personal data belonging to European users to Russia. Although the company used Standard Contractual Clauses (SCCs), the authority deemed them ineffective because the actual roles of the involved companies were not accurately reflected, and technical safeguards—such as the storage of encryption keys in Russia—did not provide sufficient protection.
Implications for practice:
The decision makes it clear that standard contractual clauses alone do not guarantee legally compliant transfers to third countries. Companies should ensure that SCCs accurately reflect the actual roles of the parties involved and that supplementary technical safeguards are also designed to be practically effective. Particularly in the case of data transfers to countries with extensive government access rights, the design of such measures is likely to come under increased scrutiny by supervisory authorities in the future.
Should you have any questions or require further information, please do not hesitate to contact us any time.