
Another week of eight- and nine-figure enforcement numbers out of Europe, a health-data breach that reads like a checklist of what not to do, and a US regulator pulling back on a rule it had only recently pushed forward. Here's what mattered.
Enforcement
The Dutch Data Protection Authority fined Uber nearly €825 million (€824.99M) over automated decision-making that affected its drivers↗ — one of the largest ADM-related GDPR fines issued to date. The size of the penalty is a signal in itself: regulators are willing to treat algorithmic management of workers (automated dispatch, deactivation, or performance scoring, for instance) as a core GDPR compliance area, not a niche edge case. Any platform business using algorithmic systems to manage drivers, couriers, or other gig workers should treat this as a warning shot.
France's CNIL fined Hôpital Privé de la Loire €500,000 over a 2025 breach↗ that exposed records for roughly 525,000 patients and 202,000 "trusted third parties." The regulator's findings read like a security fundamentals checklist gone wrong: missing MFA and VPN protections, weak access controls, and a failure to notify all affected individuals, in violation of GDPR Articles 32 and 34. It's a clean case study for any healthcare organization on where breach-response obligations most often break down — both on the prevention side and on the notification side.
Separately, CNIL fined French recruiting and staffing firm EXTIA €300,000 for failing to honor individuals' data subject access requests↗. (An earlier internal note this week described EXTIA as "Uber-adjacent" — that was an error; EXTIA is an unrelated staffing and consulting firm, and the fine has nothing to do with Uber.) The case is a reminder that DSAR handling remains a live enforcement trigger in France, and that CNIL is willing to pursue mid-size companies for it, not just large platforms.
Ireland's Data Protection Commission fined the Health Service Executive €645,000, plus a reprimand and compliance orders, over insecure paper-record storage at two shuttered psychiatric hospitals↗ that led to unauthorized access. It's a useful counterpoint to an otherwise digital-breach-heavy week: GDPR Articles 32-34 exposure applies just as much to physical records as to databases, and organizations sitting on archived paper files from closed facilities shouldn't treat that as a solved problem.
New and Pending Legislation
Delaware Governor Meyer signed HB 380, amending the Delaware Personal Data Privacy Act↗ ahead of its January 1, 2027 effective date. The changes lower the applicability thresholds to 10,000 consumers (or 5,000 if 20%+ of revenue comes from data sales), tighten "strictly necessary" limits on selling sensitive data, and add new vendor/contracting requirements↗. Companies that assumed they were too small to be in scope for Delaware's law are worth a fresh look — the lower thresholds pull in a meaningfully broader set of mid-size businesses.
Guidance and Rulemaking
The FTC formally withdrew its 2021 policy statement that applied the Health Breach Notification Rule to health apps and connected devices↗, calling the statement obsolete now that a 2024 rule update already covers that ground directly. It's a deregulatory signal in tone, but not a rollback of the underlying rule — health and wellness app makers are still subject to HBNR breach-notification obligations under the updated 2024 rule; the FTC is simply retiring the older interpretive statement rather than the substantive requirement.
The EU Cyber Resilience Act's incident-reporting obligations took effect September 11↗ for manufacturers of products with digital elements. Covered manufacturers now face a 24-hour early-warning notification duty for actively exploited vulnerabilities and severe incidents, followed by more detailed follow-up reporting — a new operational burden for connected-device makers that sits alongside, and interacts with, their existing GDPR breach-notification duties.
Also worth noting
The FTC extended the comment deadline to September 25↗ on its proposed enforcement policy statement targeting "personalized pricing" — using personal data to set individualized prices for different consumers. Surveillance-pricing practices remain squarely on the agency's radar.
Canada's Privacy Commissioner also filed a Federal Court application seeking to force Google to implement a limited right to de-listing↗, following a 2025 investigation. It's the first real test of whether PIPEDA supports a de-listing right — relevant for any organization leaning on a "reasonableness" argument for PIPEDA compliance.
The Takeaway
The through-line this week is that enforcement dollar amounts keep climbing — Uber's nearly €825M fine alone dwarfs most companies' annual compliance budgets — while the underlying failures regulators keep citing are often basic: missing MFA, unanswered rights requests, unsecured paper archives. Combined with Delaware's lower thresholds and the EU's new 24-hour incident-reporting clock, the practical message for compliance teams is the same one it's been for a while — the return on shoring up access controls, DSAR response processes, and breach-notification playbooks keeps going up as the fines do.