One decision dominated August: the Dutch Data Protection Authority fined Uber nearly EUR 825 million for the fully automated blocking of drivers, one of the largest penalties ever issued under the General Data Protection Regulation (GDPR). The same weeks brought a cease-and-desist letter to the credit agency SCHUFA over data that should have been deleted, joint Lithuanian guidance on video surveillance cameras, and plain-language GDPR material from the State Data Protection Inspectorate (VDAI).
The September edition of RegRally covers the data protection and information and communication technology (ICT) developments of August that matter most to businesses processing personal data in Lithuania and across the EU.
This month at a glance
- Automated decisions: the Dutch Data Protection Authority fined Uber nearly EUR 825 million under Article 22 GDPR for deactivating drivers by automated decision-making without meaningful human intervention.
- Retention and erasure: noyb sent SCHUFA a cease-and-desist letter over an alleged shadow database, demanding genuine erasure, complete access responses and transparency, and opened an interest list for a possible class action.
- Video surveillance: Lithuania’s National Cyber Security Centre (NKSC), together with the Second Investigation Department under the Ministry of National Defence (AOTD) and the State Security Department (VSD), published recommendations on the secure use of video surveillance cameras.
- Plain-language GDPR: VDAI published material explaining data protection requirements in accessible language, useful for internal policies, staff training and privacy notices.
Quick Navigation
Uber’s EUR 825 million GDPR fine for automated decisions
Date: 21 August 2026 | Source: Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Link | Link
What happened?
On 21 August 2026, the Dutch Data Protection Authority fined Uber EUR 824,990,000, nearly EUR 825 million, for the fully automated deactivation (blocking) of drivers. It is one of the largest GDPR penalties ever issued.
The decision turns on Article 22 GDPR. Drivers were deactivated by automated decision-making with no meaningful human intervention, and without the safeguards and transparency that provision requires for decisions producing legal effects or similarly significantly affecting data subjects.
Why does it matter for businesses?
The decision is significant for organizations using AI-supported or other algorithmic decision-making tools affecting individuals, including in HR, onboarding, offboarding, fraud prevention, compliance, risk scoring and account termination. It also confirms that regulators will treat the absence of genuine human review as a substantive breach of Article 22 GDPR rather than a mere procedural defect.
Recommended actions
Businesses using automated decision-making should:
- prepare an inventory of the decisions the organization makes about individuals without human involvement, for example blocking an account, terminating a contract or refusing a client on risk grounds
- assess for each whether Article 22 GDPR allows it to be taken on a fully automated basis
- make sure the human review behind an automated decision is genuine and can be evidenced: the reviewer should see the underlying data, have authority to change the outcome and leave a record of the review
- remember that a formal sign-off alone does not meet the Article 22 GDPR standard, as this was the central failing in the Uber decision
- check that privacy notices tell individuals when a decision about them is automated and what logic is involved
- keep a working procedure through which individuals can contest an automated decision and obtain human review, and document the safeguards in writing
SCHUFA and the GDPR: retention, erasure and access requests
Date: 26 August 2026 | Source: noyb (European Center for Digital Rights)
Link
What happened?
On 26 August 2026, noyb sent a cease-and-desist letter to the German credit information agency SCHUFA over an alleged shadow database and opened an interest list for a prospective class action. noyb demands that SCHUFA stop storing data beyond its own published retention periods, provide affected individuals with their historical data in response to access requests under Article 15 GDPR, and ensure transparency about its processing practices.
SCHUFA rejected the demands, so noyb has confirmed it will file for an injunction, and an interest list has been opened for a possible damages class action.
Why does it matter for businesses?
The dispute turns on retention and genuine erasure, and on the completeness of access responses. The allegation is that records which should have been deleted are only hidden from view and still used, including to develop and test scores.
Recommended actions
Businesses holding personal data should:
- map every dataset in which the organization holds personal data, including archives, backups and historical records
- check that the retention period the organization itself publishes is actually applied, and that data is genuinely erased at the end of that period, not merely hidden from everyday view while remaining available for other uses
- make sure responses to access requests under Article 15 GDPR cover all personal data held about the individual, including archived and historical records, not only what appears in the active system
- state in the privacy notice how long each category of data is kept and on what basis
- where historical data is reused for a further purpose, for example to develop or test scoring models, confirm that the further use has its own lawful basis and is disclosed to the individuals concerned
Video surveillance cameras: security recommendations from Lithuanian authorities
Date: 26 August 2026 | Source: National Cyber Security Centre (NKSC)
Link | Link
What happened?
On 26 August 2026, NKSC, AOTD and VSD jointly published recommendations on the secure use of video surveillance cameras, framing the issue as running from privacy to national security. The authorities stress that even a single unprotected camera can serve both as a source of valuable information and as an access point into the whole network of a home, company or organization.
Cameras deployed for security and monitoring are themselves attractive targets. Attackers who gain access can collect sensitive information for criminal purposes or in the interests of foreign states. The authorities point to the Dutch intelligence services’ July 2026 disclosure of systematic Russian digital espionage operations exploiting internet-connected cameras in the West and in Ukraine, where intercepted video feeds were used to identify military vehicle routes, weapons delivery routes and troop positions.
Why does it matter for businesses?
Poorly configured or unpatched devices create both a personal data exposure and a national security exposure. For businesses, camera security raises both GDPR and ICT security issues. The guidance also highlights the growing focus of public authorities on supply-chain security risks associated with connected devices and surveillance technologies.
Recommended actions
The baseline recommendations issued by the authorities are in substance the following:
- change the factory administrator password on every device to a strong and unique password that is not reused across units, and change it periodically
- update camera software and firmware regularly, and do not use devices the manufacturer no longer supports, replacing them with newer equipment from reliable manufacturers
- make sure there are no abandoned or unmonitored cameras still connected to the network
- where there is no genuine need, do not allow the camera to be reached directly from the internet. For remote access use only the manufacturer’s recommended solution or a VPN, and keep surveillance equipment in a separate network segment
- do not install or upgrade to surveillance equipment from untrusted manufacturers, in particular devices produced in China, Russia or Iran
- use features such as partial blurring where the image may otherwise reveal sensitive information, for example GPS location, and limit the camera’s field of view so that it does not capture excessive detail, such as an exact address, or confidential detail, such as computer screens or documents
- monitor whether cameras that do not belong to the organization have appeared on its property or are pointed at it
- include camera systems in the assessment of security of processing under Article 32 GDPR and, where the organization is subject to ICT rules such as the NIS2 Directive or the Digital Operational Resilience Act (DORA), also in its ICT risk management and incident reporting arrangements
VDAI explains data protection in plain language
Date: 28 August 2026 | Source: State Data Protection Inspectorate (VDAI)
Link
What happened?
On 28 August 2026, VDAI published material explaining data protection requirements in plain and accessible language, as part of its ongoing effort to make GDPR obligations comprehensible to controllers and data subjects.
Why does it matter for businesses?
The material shows how the Inspectorate itself explains key GDPR principles, and is useful when reviewing internal policies, staff training materials and privacy notices.
Recommended actions
Businesses processing personal data should:
- review the Inspectorate’s material and circulate it internally to the staff who handle personal data
- use it as a reference when reviewing internal policies, staff training materials and privacy notices
What should businesses take from this month’s developments?
The Uber decision is relevant to any business that uses automated decisions about individuals. If an account can be blocked, a contract terminated or a client refused without a person genuinely reviewing the decision, human review has to be real, evidenced and capable of changing the outcome.
Retention promises have to be kept in practice. The SCHUFA dispute turns on exactly that pattern: data kept beyond published retention periods, hidden from everyday view but still in use, and access responses that stop at the active system.
Camera systems can raise both data protection and ICT security issues. They belong in the Article 32 GDPR assessment of security of processing, and, for organizations under the NIS2 Directive or DORA, in ICT risk management and incident reporting arrangements.
How ECOVIS ProventusLaw can help
ECOVIS ProventusLaw advises businesses on telecommunications, IT and data protection matters, including GDPR compliance, automated decision-making, retention and erasure practices, privacy notices and the ICT requirements applying to connected devices.
For financial institutions, our team also covers data protection in fintech companies. As your legal advisors, we will be happy to assist with all questions related to these developments, including legal advice as well as the revision and preparation of your internal documents.
LT
RU
CN
DE