By · Last updated 2026-06-05

Späť na blogGDPR a Dodržiavanie

Holandske AP: Pokuta 290 miliionov EUR pre Uber a prenosy udajov

Holandske AP vydalo najvacsiu pokutu EU za individual'ny prenos udajov -- 290 miliionov EUR proti Uberu v roku 2024. Tu je to, co suladnost cezhranicnych prenosov vyzaduje.

June 5, 20267 min čítania
Dutch APNetherlands GDPRUber GDPR finecross-border data transferEU data transfer

Holandske AP a pokuta pre Uber

V auguste 2024 holandske AP pokutovalo Uber sumou 290 miliionov EUR. Uber prenasaol udaje europskych vodicov na americke servery bez pravneho zakladu. Tieto udaje zahrnali taxis licencie, trestne kontroly, zdravotne zaznamy a cestovacie protokoly.

Uber prenasaol udaje po tom, co Schrems II zrusil stit EU-US Privacy Shield v juli 2020. Tieto prenosy udrziaval v chode dva roky. Bez standardnych zmluvnych doloziek. Bez akehokolvek nastroja podla clanku 46.

Tato pokuta je najvacsia v EU za narusenie prenosu udajov. Radı sa na tretie miesto spomedzi vsetkych pokut GDPR. Zlyhania prenosov teraz nesuju obrovske naklady. Nielen narusenia.

Pozrite naseho pruvodcu suladnostou GDPR pre rychly prehlad.

Priority oblasti presadzovania AP

Holandske AP prijalo viac ako 21 400 staznosti v roku 2023. Zameriava sa na tri oblasti.

Priorita 1 -- Monitorovanie pracovnikov (43% pripadov): Mnoho holandskych spolocnosti celi pokutam AP za sledovanie zamestnancov. Skryte kamery, hromadne kontroly e-mailov a sledovanie GPS bez oznamenia spustuju akciu. Holandske pracovne pravo prida dalsie pravidla nad ramec GDPR.

Priorita 2 -- Cezhranicne prenosy (31% pripadov): Po pokute pre Uber a spolocnom setreni s irskeho DPC o Cloudflare (2023) AP zosilnilo dohled nad prenosmi. Technologicky sektor v Amsterdame celi vysokemu riziku. Cloudove spolocnosti, fintech a rychlo rastuce startupy su vsetky v rozsahu.

Priorita 3 -- Marketing a profilovanie (26% pripadov): Toto zahrnuje suhlas s cookies, cielenie reklamy a priamy marketing. AP zaujima prisny pohladom na "opravneny zaujem". Vyzaduje pisomne testy s jasnymi dokazmi.

Pravidla prenosov po Uberi

Posudenia vplyvu prenosov (TIA): EDBP vyzaduje TIA pre kazdy prenos do tretej krajiny. TIA musi ukazat, ze ciel poskytuje rovnocennu ochranu s pravom EU. AP hovori, ze TIA musi odpovedat na styri otazky:

  • Ake su zakony pristupu v cielovej krajine?
  • Ako daleko mozu zasahnut spravodajske agentury?
  • Aky je zaznam vladnych ziadosti importerovi udajov?
  • Ake pravne opravne prostriedky mozu dotknuty pouzivat?

Standardne zmluvne dolozy -- nestacia samotne: SCC samotne nevyhovuju clanku 46. Ak TIA ukaze riziko vladneho pristupu, su povinne dalsie zaruky.

Dalsie technicke opatrenia, ktore AP prijima:

  • Sifrovanie, kde importer nema pristup k desifrovacim klucom
  • Odstranenie priamych ID pred prenosom tak, aby importer nemohol prepojit udaje s osobou
  • Redukcia udajov pred prenosom, orezanie poli, ktore importer nepotrebuje

Offline desktopova aplikacia spusta vsetku pracu na vasom zariadeni. Neposiela ziadne udaje von. To odstranuije problem s prenosom pre tuto cinnost. Pozrite nas prehlad bezpecnosti a suladnosti.

Udaje zamestnancov a holandske pracovne pravo

Zameravanie AP na 43% monitorovanie pracovnikov ukazuje, ako sa GDPR a holandske pracovne pravo prekryvaju.

Tri pravidla platia pre organizacie so sidlom v Holandsku:

Schvalenie radou zamestnancov: Spolocnost s radou zamestnancov musi ziskat jej suhlas pred zavedenim akehokolvek nastroja monitorovania. To pokryva nastroje AI, kontroly e-mailov a dochadzkove systemy.

Ucelova vhodnost: Monitorovanie musi zodpovedal svojmu stated ciel. Skryte monitorovanie nie je povolene. Otvorene monitorovanie musi byt najmenej rusivou moznostou.

Obmedzenie ucelu: Udaje HR zbierane pre jeden ciel nemozu byt pouzite pre iny. Je povinny novy pravny zaklad.

Tieto pravidla vyzaduju tri zaznamy: schvalenie rady, kontrolu ucelu a kontroly. Nas kontrolny zoznam suladnosti pokryva vsetky tri.

Detekcia PII v Holandsku

Nastroje PII v Holandsku musia zvladat miestne formaty ID. Standardne globalne nastroje ich casto prestupuju:

  • BSN (Burger Service Nummer): 9-miestny holandsky narodny ID -- vyzaduje validaciu kontrolneho suctu
  • IBAN (predpona NL): Holandsky IBAN s vlastnou validacnou logikou
  • PSC (postcode): Format je 4 cislice + medzera + 2 pismena
  • DigiD: Vladny kod digitalnej identity
  • Cisla zdravotnej starostlivosti: Formaty BGZ a EP pre zaznamy pacientov

Genericke nastroje mozi zachytit IBAN, ale prestupnut BSN kontrolny sucet alebo format PSC. Testujte detekciu BSN pred spracovanim udajov o narodnej identite. Nepredpokladajte pokrytie.

Kroky pre organizacie v Holandsku

1. Audit prenosov: Uvedte vsetky toky udajov do tretich krajin. Skontrolujte zavedene SCC. Spustite TIA pre klucove toky. Zaznamenavajte dalsie technicke opatrenia tam, kde TIA ukazuje riziko.

2. Kontrola monitorovania pracovnikov: Uvedte vsetky nastroje monitorovania, vratane AI. Skontrolujte zaznamy o schvaleni radou zamestnancov. Potvrdte, ze kontroly ucelu existuju v pisomnej forme.

3. Kontrola pokrytia PII: Testujte detekciu BSN, PSC a IBAN vo vasich nastrojoch PII. Testujte presnost na dokumentoch v holandskom jazyku.

4. Vystavenie technologickeho sektora: Startupy by mali zaznamenavat volby, ktore znizuju riziko prenosu -- cloud v regionu EU a moznosti lokalneho spracovania. Poskytovatelia cloudu s nastavenim EU-US by mali zdokumentovat svoje nastroje prenosu a pristup TIA.


anonym.legal pouziva datorove centrui Hetzner so sidlom v EU s dizajnom nulovej znalosti. Server nikdy nevidi vas text v plain-texte. Uplne narusenie servera produkuje iba AES-256-GCM sifrovany text. Potrebujete spracovanie len na lokalnom zariadeni? Desktopova aplikacia bezi uplne na vasem zariadeni bez externych pripojeni.

Zdroje

Pripravení chrániť vaše údaje?

Začnite anonymizovať PII s 285+ typmi entít v 48 jazykoch.

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.