Legal prism · 2026-08-22

Legal prism — 2026-08-22

Archive
Updated: 2026-08-22 14:36
The day's news through a legal prism — grounded in our database of EU legislation.
Original — verbatim from the source Analysis — our legal insight (not a source)

Today's news through the legal prism (3)

Selected for a legal angle. For each: original → fact-check and legal basis → substantive analysis.
Filter by area of law:
Original — Dealroom
Dealroom.co | Uber fined €825M in the Netherlands over automated driver suspensions Copy link
Dutch regulators fined Uber €825 million, about $966 million, for allegedly deactivating driver accounts through automated systems without properly informing drivers or giving them a meaningful way to challenge the decisions; Uber says it…
Analysis
Article 22(3) requires, at a minimum, human intervention, the right to express one’s point of view, and the right to contest the decision.
The penalty is €825 million, approximately $966 million, and is the second-largest GDPR penalty identified in the evidence.

Core issue

Although the fine is framed as a privacy penalty, the legal position concerns access to work controlled by account-management software. Because deactivation removes a driver’s ability to work, the AP treated suspension decisions as producing significant consequences under the GDPR.

  • The precise legal question is whether Uber subjected drivers to solely automated decisions producing significant effects without the safeguards required by Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR).
  • Article 22(1) gives a data subject the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects.
  • Articles 13, 14 and 15 require information about automated decision-making, including meaningful information about the logic involved, as well as the significance and envisaged consequences.
  • The GDPR is a regulation and therefore applies directly in every Member State without national transposition.

Legal assessment

The AP’s theory is consistent with the evidence because Uber’s systems flagged suspected fraud and temporarily suspended driver accounts. The alleged triggers included taking detours to inflate fares and accepting trips without intending to complete them. The AP also stated that software sometimes permanently removed drivers for low customer ratings, which Uber disputes.

  • For drivers, the operative right under Article 22(1) is not merely procedural fairness but protection against a fully automated decision affecting access to work.
  • For Uber, Article 22(3) means that a suspension system must include human intervention, an opportunity to provide an explanation, and a route to contest the decision.
  • Article 15(1)(h) gives drivers access to information about the existence, logic, significance and envisaged consequences of automated decision-making.
  • Article 12(2) requires the controller to facilitate the exercise of data subject rights under Articles 15 to 22.
  • Article 35(3)(a) requires a data protection impact assessment for systematic and extensive automated evaluation used for decisions producing legal or similarly significant effects.
  • Article 35(7) requires that assessment to describe the processing, assess necessity and proportionality, assess risks, and identify safeguards.

The AP had lead supervisory authority because Uber’s European headquarters are in Amsterdam. That made the Dutch authority the lead authority for Uber across the EU. The incidents concerned Europe between 2020 and 2022 and originated from a complaint by drivers in France. Only Ireland’s €1.2 billion fine against Meta in 2023 is identified as larger. The €825 million penalty is close to three times Uber’s earlier €290 million Dutch fine concerning transfers of driver data to the United States. Uber says its current policies include human review and a mechanism to contest suspensions.

Consequences

The practical consequence for Uber is not limited to paying €825 million if the decision stands. It must defend whether its past and current deactivation systems provide the information and challenge mechanisms required by Articles 13, 14, 15 and 22.

  • Drivers affected between 2020 and 2022 have a concrete regulatory finding supporting claims that automated suspension impaired their access to work.
  • Platform companies using automated fraud or performance systems face a compliance issue where account access determines earning capacity.
  • Low-rating deactivations are especially significant because Uber says 126 drivers across Europe lost their accounts for low customer ratings in 2021.
  • The AP’s approach makes human review and contestability central safeguards where software determines suspension or deactivation.
  • Appeals may reduce or overturn headline GDPR fines, because Reuters noted that multi-year appeals often do so for large technology companies.

The immediate procedural next step is Uber’s appeal, which the company said it will bring.

Legal basis (3)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 22 (statute)
Article 22 Automated individual decision-making, including profiling 1. The data subject shall have the right not to be subject to a decision based solely on automated…
Article 22 Automated individual decision-making, including profiling 1. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. 2. Paragraph 1 shall not apply if the decision: (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller; (b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or (c) is based on the data subject's explicit consent. 3. In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision. 4. Decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1), unless point (a) or (g) of Article 9(2) applies and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place. Section 5 Restrictions
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 70 (statute)
based on profiling pursuant to Article 22(2); (g) issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing…
based on profiling pursuant to Article 22(2); (g) issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph for establishing the personal data breaches and determining the undue delay referred to in Article 33(1) and (2) and for the particular circumstances in which a controller or a processor is required to notify the personal data breach; (h) issue guidelines, recommendations and best practices in accordance with point (e) of this paragraph as to the circumstances in which a personal data breach is likely to result in a high risk to the rights and freedoms of the natural persons referred to in Article 34(1).
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 15 (statute)
Article 15 Right of access by the data subject 1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data…
Article 15 Right of access by the data subject 1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Original — The Financial Express
Producers Now Liable for Plastic Waste Management Copy link
Bangladesh has introduced a new Extended Producer Responsibility framework making producers, brand owners, and importers responsible for managing plastic waste from their products and packaging, with mandatory collection and recycling…
Analysis
Under PPWR Article 44(4), producers may not make packaging or packaged products available unless they are registered in that Member State.
Once listed, a business must register within six months, pay the prescribed fee, and submit a work plan together with its application.

Core issue

Plastic businesses serving the Bangladesh market now bear a direct waste-management obligation linked to market access, not merely a sustainability expectation. Because the guideline entered into force on August 13, 2026, the immediate legal issues are identification, registration, financing, and category-specific performance. The precise question is which domestic-market actors must finance end-of-life plastic management, and which compliance thresholds determine lawful continuation. The governing instruments are the Extended Producer Responsibility Guideline for Plastic Waste Management, 2026 and Section 13 of the Environment Conservation Act, 1995. The EU comparison is legally distinct because Regulation (EU) 2025/40 applies directly in every Member State.

  • Covered actors include large, medium-sized and small enterprises, importers, manufacturers, brand owners, online platforms, supermarkets, retail chains, and recycling businesses.
  • Export-oriented industrial establishments, particularly those producing against export orders, fall outside the scope of the guideline.
  • The first mandatory target is collection of at least 15 per cent of the plastic placed on the market and recycling of at least 7.5 per cent during the first two years.

Legal assessment

The guideline makes the Department of Environment the gatekeeper, because it must identify and list obligated entities before registration duties crystallise. The DoE must decide the application within 30 working days, and registration remains valid for three years. Failure to submit the annual report prevents renewal, so reporting is directly linked to continued registration.

  • Companies must establish an EPR project fund with a Producer Responsibility Organisation.
  • They must arrange collection and recycling separately for each of the five plastic categories.
  • PROs must report to the relevant company by July, and companies must report annually to the DoE by August.
  • EPR financial transactions with PROs must be conducted through registered and approved financial institutions and supported by proper documentation.

The targets are not aggregate corporate targets, because each plastic category must meet its own collection and recycling level. The recycling rate is calculated by reference to collected plastic waste, not total plastic placed on the market. Plastic collected by local government authorities does not count toward a company’s EPR targets. That rule prevents companies from satisfying private obligations through municipal collection already carried out outside their EPR system. The enforcement structure is administrative and documentary, involving DoE inspection, audit, verification, and barcode-based checks. False or distorted reporting may result in suspension or cancellation of registration after notice and a hearing. Businesses exceeding their targets may sell surplus plastic credits to other obligated entities or internationally within two financial years, subject to prescribed conditions. The EPR fund formula uses the mandatory rate, the volume of plastic sold, and the per-unit cost, making the obligation financially measurable. The EU model confirms the same legal logic, although under a directly applicable regulation. Under PPWR Article 45(1), producers have extended producer responsibility for packaging first made available in a Member State. Under PPWR Article 46(1), producers may entrust EPR obligations to a producer responsibility organisation authorised under PPWR Article 47. Under PPWR Article 19(2), distributors must verify the producer’s EPR registration before making packaging available.

Consequences

Large enterprises face the first practical compliance burden because they enter the system during the first two years. Medium-sized enterprises enter in the third and fourth years, while small enterprises enter in the fifth year. For domestic-market businesses, the practical exposure is a combined cost, reporting, verification, and registration-renewal risk.

  • A producer placing 1,000 tonnes of plastic on the market must initially collect at least 150 tonnes.
  • If it collects 150 tonnes, the 7.5 per cent recycling target equals 11.25 tonnes, calculated by reference to collected waste.
  • In the third to fifth years, the same 1,000 tonnes would require collection of at least 300 tonnes and recycling of 45 tonnes.

Retail chains, supermarkets, and online platforms are significant because the guideline expressly names them, but the available evidence leaves their precise financing role to be clarified. Informal waste collectors also remain practically important because payment arrangements for them still require clarification. The next procedural step is DoE identification and listing of obligated entities.

Legal basis (3)
Regulation (EU) 2025/40 of the European Parliament and of the Council on packaging and packaging waste (PPWR) Article 45 (statute)
Article 45 Extended producer responsibility 1. Producers shall have extended producer responsibility under the schemes established in accordance with Articles 8 and 8a…
Article 45 Extended producer responsibility 1. Producers shall have extended producer responsibility under the schemes established in accordance with Articles 8 and 8a of Directive 2008/98/EC and with this Section for the packaging, including packaging of packaged products, that they make available for the first time on the territory of a Member State or that they unpack without being end users.
Regulation (EU) 2025/40 of the European Parliament and of the Council on packaging and packaging waste (PPWR) Article 46 (statute)
levels of recovered and recycled materials in relation to the quantity of packaging waste generated on their territory. 5. Producer responsibility organisations shall…
levels of recovered and recycled materials in relation to the quantity of packaging waste generated on their territory. 5. Producer responsibility organisations shall ensure equal treatment of producers regardless of their origin or size, without placing a disproportionate burden on producers of small quantities of packaging, including packaging of packaged products, including small and medium-sized enterprises.
Regulation (EU) 2025/40 of the European Parliament and of the Council on packaging and packaging waste (PPWR) Article 55 (statute)
Article 55 Information on prevention and management of packaging waste 1. In addition to the information referred to in Article 8a(2) of Directive 2008/98/EC and in…
Article 55 Information on prevention and management of packaging waste 1. In addition to the information referred to in Article 8a(2) of Directive 2008/98/EC and in Article 12 of this Regulation, producers or, where entrusted with carrying out extended producer responsibility obligations in accordance with Article 46(1) of this Regulation, producer responsibility organisations, or public authorities appointed by Member States when applying Article 8a(2) of Directive 2008/98/EC, shall make available to end users, in particular consumers, the following information regarding the prevention and management of packaging waste with respect to the packaging that the producers supply on the territory of a Member State: (a) the role of end users in contributing to waste prevention, including any best practices; (b) re-use arrangements available for packaging; (c) the role of end users in contributing to the separate collection of packaging waste materials, including handling of packaging containing hazardous products or waste; (d) the meaning of the labels and symbols affixed, printed or engraved on packaging in accordance with Article 12 of this Regulation or present in the documents accompanying the packaged product; (e) the impact of inappropriate discarding of packaging waste, for example as litter or in mixed municipal waste, on the environment and on human health or the safety of
Original — Startup Fortune
TikTok Agrees to Pay DOJ $400 Million Over Children’s Privacy Claims Copy link
TikTok and ByteDance have agreed to a $400 million settlement with the Justice Department over allegations that the platform collected data from children under 13 without legally required parental consent, raising broader concerns about…
Analysis
Under GDPR Article 8(1), child-consent processing for information society services is lawful at 16, or below 16 only with parental consent or authorisation.
TikTok's immediate practical exposure is payment of $300 million, with a further $100 million triggered after the earlier consent decree is vacated by a court.

Core issue

TikTok and ByteDance now face both a monetary settlement and a renewed compliance burden because the alleged conduct followed the 2019 Musical.ly order.

  • The precise U.S. issue is whether TikTok knowingly collected personal information from children under 13 without notice, parental consent, and effective deletion tools under the Children's Online Privacy Protection Act.
  • The EU comparison is whether child users' personal data and safety were protected through lawful consent, transparency, access, deletion, and supervisory enforcement under the directly applicable Regulation (EU) 2016/679 - General Data Protection Regulation.
  • Member States may lower that age, but GDPR Article 8(1) provides that the lower age may not be below 13.

Legal assessment

GDPR Article 8(2) requires the controller to make reasonable efforts to verify parental consent or authorisation, taking into account available technology.

  • GDPR Article 4(11) defines consent as freely given, specific, informed, unambiguous, and indicated by a statement or clear affirmative action.
  • GDPR Article 6(1)(a) permits processing where the data subject has given consent for one or more specific purposes.
  • GDPR Article 6(1)(f) weakens reliance on legitimate interests where the data subject is a child, because children's interests and freedoms may override them. The evidence indicates that children could bypass the age gate, create regular accounts, and use features outside the under-13 version.

That is significant because a birthday screen is not equivalent to verified parental consent if children can use full accounts and leave personal data behind. The complaint also alleged that TikTok retained personal information and made deletion too difficult for parents. That allegation maps directly onto parental consent, erasure access, and transparent rights mechanisms.

  • GDPR Article 12(1) requires child-directed information to be concise, transparent, intelligible, easily accessible, and in clear, plain language.
  • GDPR Article 13(2)(b) requires notice of rights of access, rectification, erasure, restriction, objection, and portability when personal data are obtained.
  • GDPR Article 15(1) gives the data subject access to confirmation of processing, purposes, data categories, recipients, storage period, and erasure rights.
  • GDPR Article 5(1)(a) requires lawful, fair, and transparent processing; GDPR Article 5(1)(c) requires data minimisation. The settlement structure is also legally significant because $300 million is due immediately and $100 million follows after a court vacates the earlier Musical.ly consent decree.

The 2019 Musical.ly settlement was $5.7 million and required COPPA compliance going forward. The new settlement is approximately 70 times that earlier penalty. Compared with other child-privacy matters, it exceeds Google and YouTube's $170 million settlement and Epic Games' $275 million penalty. The EU material points in the same direction, because preliminary findings dated July 24, 2026 stated that TikTok violated the Digital Services Act by exposing children's accounts to adults. The evidence does not identify a DSA article, so the firm legal analysis here rests on the stated finding and on the GDPR provisions provided. Because the GDPR is a Regulation, Regulation (EU) 2016/679 applies directly in every Member State. Under GDPR Article 57(f), supervisory authorities handle complaints, investigate them as appropriate, and inform complainants of progress and outcome within a reasonable period.

Consequences

  • Parents' practical position is stronger where deletion tools are ineffective, because the evidence indicates that COPPA requires a means for parents to delete children's data.
  • App operators serving minors face product-level compliance demands regarding age gates, parental consent, data retention, access, and erasure.
  • EU operators must treat child notices and consent flows as operational requirements under GDPR Articles 8, 12, 13, and 15, not as policy-page wording. For the new U.S. joint venture, the settlement creates continuity risk: new ownership does not extinguish alleged pre-existing child-privacy liabilities.

Oracle's role in U.S. user data and safeguards around data, the app, and the recommendation system makes operational controls central to compliance. Trust and Safety layoffs may become relevant only to the extent they affect the product's ability to prevent underage access, delete data, or process parental requests. The known future step is the court action vacating the earlier Musical.ly decree before the remaining $100 million becomes due.

Legal basis (3)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 57 (statute)
promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall…
promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention; (c) advise, in accordance with Member State law, the national parliament, the government, and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons' rights and freedoms with regard to processing; (d) promote the awareness of controllers and processors of their obligations under this Regulation; (e) upon request, provide information to any data subject concerning the exercise of their rights under this Regulation and, if appropriate, cooperate with the supervisory authorities in other Member States to that end; (f) handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary; (g) cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of this Regulation; (h)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 6 (statute)
or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued. 4. Where the processing for a purpose other than…
or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued. 4. Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject's consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia: (a) any link between the purposes for which the personal data have been collected and the purposes of the intended further processing; (b) the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller; (c) the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10; (d) the possible consequences of the intended further processing for data subjects; (e) the existence of appropriate safeguards, which may include encryption or pseudonymisation.
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 8 (statute)
Article 8 Conditions applicable to child's consent in relation to information society services 1. Where point (a) of Article 6(1) applies, in relation to the offer of…
Article 8 Conditions applicable to child's consent in relation to information society services 1. Where point (a) of Article 6(1) applies, in relation to the offer of information society services directly to a child, the processing of the personal data of a child shall be lawful where the child is at least 16 years old. Where the child is below the age of 16 years, such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States may provide by law for a lower age for those purposes provided that such lower age is not below 13 years. 2. The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology. 3. Paragraph 1 shall not affect the general contract law of Member States such as the rules on the validity, formation or effect of a contract in relation to a child.