Categories: Car Rental & Rail

Uber Failed to Protect Consumer Data, Fined $490,000

The U.K.’s Information Commissioner’s Office (ICO) is fining airlines/forget-uber-some-people-are-biking-to-airports.html” target=”_self” rel=”nofollow”>Uber for not properly protecting customers’ personal information.

The $490,000 fine is for “avoidable data security flaws” that allowed the personal details of approximately 2.7 million customers in the U.K. be accessed and downloaded by airlines/did-delta-s-cyber-attack-expose-customer-information.html” target=”_self” rel=”nofollow”>cyber attackers. This included full names, email addresses and phone numbers, according to the report.

MORE Car Rental & Rail

Drivers were also affected by the data breach. Details of journeys made and how much they were paid were among the information taken during the 2016 attack.

Adding to the problem, customers and drivers were not told about the incident for more than one year. The report also notes that, rather than informing those affected about the breach, Uber paid the hackers $100,000 to destroy the information.

“This was not only a serious failure of data security on Uber’s part but a complete disregard for the customers and drivers whose personal information was stolen. At the time, no steps were taken to inform anyone affected by the breach, or to offer help and support. That left them vulnerable,” said ICO director of investigations Steve Eckersley.

From a legal standpoint, the incident breaches principle seven of the U.K.’s Data Protection Act 1998, and the action only came to light in November of 2017 when Uber reported it to the media.

“Paying the attackers and then keeping quiet about it afterward was not, in our view, an appropriate response to the cyber attack,” added Eckersley. “Although there was no legal duty to report data breaches under the old legislation, Uber’s poor data protection practices and subsequent decisions and conduct were likely to have compounded the distress of those affected.”

A separate fine was also issued today by the Autoriteit Persoonsgegevens for a similar incident that took place in the Netherlands.

This post was published by our news partner: TravelPulse.com | Article Source |
TJS News

TravelPulse.com, part of the travAlliancemedia network of products, is the leading resource for the latest travel news, offers, and videos. Since 2002, TravelPulse.com has been delivering industry news, dynamic video content and important supplier and destination information that have allowed hundreds of thousands of travel agents to succeed. Now, with dedicated consumer content, TravelPulse is once again revolutionizing the way that travel content is consumed.

Recent Posts

Rising Number of Senior Passengers Could Affect the 90-Second Emergency Evacuation Standard

A new study revealed that the increase in senior air passengers could affect the safety…

2 hours ago

Jet Skis Join Chicago’s St. Patrick’s Day Fun

People in Chicago take St. Patricks Day serious and their famous river dyeing event is…

3 days ago

Spring Travel Without the Crowds: Under-the-Radar Getaways to Book Now

As spring break crowds head to the usual hotspots, it’s a great time to consider…

1 week ago

Navidades en el Río Rin con Viking River Cruises

Acompañenme y descubramos los mercados navideños a bordo del Viking Kara.

2 weeks ago

Snow, Stories & Sailing North

Episode 9 of The Jet Set delivers a fun mix of winter travel inspiration, entertainment…

2 weeks ago