Article 22(3) requires, at a minimum, human intervention, the right to express one’s point of view, and the right to contest the decision.
The penalty is €825 million, approximately $966 million, and is the second-largest GDPR penalty identified in the evidence.
Although the fine is framed as a privacy penalty, the legal position concerns access to work controlled by account-management software. Because deactivation removes a driver’s ability to work, the AP treated suspension decisions as producing significant consequences under the GDPR.
The AP’s theory is consistent with the evidence because Uber’s systems flagged suspected fraud and temporarily suspended driver accounts. The alleged triggers included taking detours to inflate fares and accepting trips without intending to complete them. The AP also stated that software sometimes permanently removed drivers for low customer ratings, which Uber disputes.
The AP had lead supervisory authority because Uber’s European headquarters are in Amsterdam. That made the Dutch authority the lead authority for Uber across the EU. The incidents concerned Europe between 2020 and 2022 and originated from a complaint by drivers in France. Only Ireland’s €1.2 billion fine against Meta in 2023 is identified as larger. The €825 million penalty is close to three times Uber’s earlier €290 million Dutch fine concerning transfers of driver data to the United States. Uber says its current policies include human review and a mechanism to contest suspensions.
The practical consequence for Uber is not limited to paying €825 million if the decision stands. It must defend whether its past and current deactivation systems provide the information and challenge mechanisms required by Articles 13, 14, 15 and 22.
The immediate procedural next step is Uber’s appeal, which the company said it will bring.
Under PPWR Article 44(4), producers may not make packaging or packaged products available unless they are registered in that Member State.
Once listed, a business must register within six months, pay the prescribed fee, and submit a work plan together with its application.
Plastic businesses serving the Bangladesh market now bear a direct waste-management obligation linked to market access, not merely a sustainability expectation. Because the guideline entered into force on August 13, 2026, the immediate legal issues are identification, registration, financing, and category-specific performance. The precise question is which domestic-market actors must finance end-of-life plastic management, and which compliance thresholds determine lawful continuation. The governing instruments are the Extended Producer Responsibility Guideline for Plastic Waste Management, 2026 and Section 13 of the Environment Conservation Act, 1995. The EU comparison is legally distinct because Regulation (EU) 2025/40 applies directly in every Member State.
The guideline makes the Department of Environment the gatekeeper, because it must identify and list obligated entities before registration duties crystallise. The DoE must decide the application within 30 working days, and registration remains valid for three years. Failure to submit the annual report prevents renewal, so reporting is directly linked to continued registration.
The targets are not aggregate corporate targets, because each plastic category must meet its own collection and recycling level. The recycling rate is calculated by reference to collected plastic waste, not total plastic placed on the market. Plastic collected by local government authorities does not count toward a company’s EPR targets. That rule prevents companies from satisfying private obligations through municipal collection already carried out outside their EPR system. The enforcement structure is administrative and documentary, involving DoE inspection, audit, verification, and barcode-based checks. False or distorted reporting may result in suspension or cancellation of registration after notice and a hearing. Businesses exceeding their targets may sell surplus plastic credits to other obligated entities or internationally within two financial years, subject to prescribed conditions. The EPR fund formula uses the mandatory rate, the volume of plastic sold, and the per-unit cost, making the obligation financially measurable. The EU model confirms the same legal logic, although under a directly applicable regulation. Under PPWR Article 45(1), producers have extended producer responsibility for packaging first made available in a Member State. Under PPWR Article 46(1), producers may entrust EPR obligations to a producer responsibility organisation authorised under PPWR Article 47. Under PPWR Article 19(2), distributors must verify the producer’s EPR registration before making packaging available.
Large enterprises face the first practical compliance burden because they enter the system during the first two years. Medium-sized enterprises enter in the third and fourth years, while small enterprises enter in the fifth year. For domestic-market businesses, the practical exposure is a combined cost, reporting, verification, and registration-renewal risk.
Retail chains, supermarkets, and online platforms are significant because the guideline expressly names them, but the available evidence leaves their precise financing role to be clarified. Informal waste collectors also remain practically important because payment arrangements for them still require clarification. The next procedural step is DoE identification and listing of obligated entities.
Under GDPR Article 8(1), child-consent processing for information society services is lawful at 16, or below 16 only with parental consent or authorisation.
TikTok's immediate practical exposure is payment of $300 million, with a further $100 million triggered after the earlier consent decree is vacated by a court.
TikTok and ByteDance now face both a monetary settlement and a renewed compliance burden because the alleged conduct followed the 2019 Musical.ly order.
GDPR Article 8(2) requires the controller to make reasonable efforts to verify parental consent or authorisation, taking into account available technology.
That is significant because a birthday screen is not equivalent to verified parental consent if children can use full accounts and leave personal data behind. The complaint also alleged that TikTok retained personal information and made deletion too difficult for parents. That allegation maps directly onto parental consent, erasure access, and transparent rights mechanisms.
The 2019 Musical.ly settlement was $5.7 million and required COPPA compliance going forward. The new settlement is approximately 70 times that earlier penalty. Compared with other child-privacy matters, it exceeds Google and YouTube's $170 million settlement and Epic Games' $275 million penalty. The EU material points in the same direction, because preliminary findings dated July 24, 2026 stated that TikTok violated the Digital Services Act by exposing children's accounts to adults. The evidence does not identify a DSA article, so the firm legal analysis here rests on the stated finding and on the GDPR provisions provided. Because the GDPR is a Regulation, Regulation (EU) 2016/679 applies directly in every Member State. Under GDPR Article 57(f), supervisory authorities handle complaints, investigate them as appropriate, and inform complainants of progress and outcome within a reasonable period.
Oracle's role in U.S. user data and safeguards around data, the app, and the recommendation system makes operational controls central to compliance. Trust and Safety layoffs may become relevant only to the extent they affect the product's ability to prevent underage access, delete data, or process parental requests. The known future step is the court action vacating the earlier Musical.ly decree before the remaining $100 million becomes due.