The Dutch Data Protection Authority has fined Uber €290 million, saying the company seriously violated European data-protection rules by transferring drivers’ information to servers in the United States.

The regulator said Uber collected sensitive material from European drivers, including taxi licenses, photos, payment details, location information, identity documents and, in some cases, criminal and medical data. According to the authority, those data were sent to Uber’s US headquarters for more than two years without sufficient transfer safeguards under the EU’s General Data Protection Regulation.

The size of the fine reflects both the scale of the data involved and the regulator’s view that the breach was serious. The DPA said Uber had not met GDPR requirements to ensure adequate protection for personal data transferred out of the European Union. For a company that processes data across multiple jurisdictions, that is a significant finding.

Uber rejected the decision, calling it “extraordinary” and “completely unjustified.” The company said its transfer process had been compliant during what it described as a period of uncertainty between the EU and the US and said it planned to appeal. That response sets up a legal fight that could continue for some time.

The case began after more than 170 French drivers complained to a human rights group, which then raised the issue with French authorities. Because Uber’s European headquarters are in the Netherlands, the Dutch watchdog was the lead regulator. That detail matters because EU privacy enforcement often runs through the country where a company’s main office is located.

The DPA’s chairman, Aleid Wolfsen, framed the issue as a basic matter of protection for fundamental rights. The point, in his view, is that data belonging to Europeans should not be treated casually when stored outside the bloc. The regulator’s language suggested it believed Uber failed not just on a technical rule but on the underlying purpose of the GDPR.

This is also not Uber’s first run-in with the Dutch authority. The DPA previously fined the company €600,000 in 2018 and €10 million last year, making this the third such penalty.

The ruling adds to a wider European pattern of scrutiny for global technology companies that rely on cross-border data flows. For Uber, the immediate consequence is financial. The larger consequence is reputational: regulators are signaling that the handling of driver data will be treated as a core compliance issue, not a minor administrative matter.